Dear Pak,
Berikut saya kirimkan email balasan dari server ke user dan smtp log nya,
Tolong dibantu.
X-MDAV-Result: clean
X-MDAV-Processed: abcdomain.com, Mon, 08 Aug 2016 23:08:15 +0700
Return-Path: <>
Received: from abcdomain.com by abcdomain.com (via RAW) (MDaemon PRO v14.0.3)
    for <jul...@abcdomain.com>; Mon, 08 Aug 2016 23:08:14 +0700
Date: Mon, 08 Aug 2016 23:08:14 +0700
From: "MDaemon at abcdomain.com" <mdae...@abcdomain.com>
Reply-To: nore...@abcdomain.com
Subject: Permanent Delivery Failure
To: jul...@abcdomain.com
X-MDaemon-Deliver-To: jul...@abcdomain.com
Message-ID: <mdaemon7783201608082308.aa0814...@abcdomain.com>
Mime-Version: 1.0
X-Actual-From: mdae...@abcdomain.com
X-MDDSN-Message: Yes
X-Return-Path: <>
Content-Type: multipart/mixed; boundary="0808-2308-14-PART-BREAK"

   The following data may contain sections which represent BASE64 encoded
   file attachments.  These sections will be unreadable without MIME aware
   tools.  Seek your system administrator if you need help extracting any
   files which may be embedded within this message.

--0808-2308-14-PART-BREAK
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 7bit

--------------------------------------------------------------------------
MDaemon Delivery Status Notification - http://www.altn.com/dsn/
--------------------------------------------------------------------------

The attached message had PERMANENT fatal delivery errors.

After one or more unsuccessful delivery attempts the attached message has
been removed from the MDaemon mail queue on this server.  The number and
frequency of delivery attempts are determined by local configuration.

--------------------------------------------------------------------------
YOUR MESSAGE WAS NOT DELIVERED TO ONE OR MORE RECIPIENTS
--------------------------------------------------------------------------

Failed address: 147133...@qq.com

--- Session Transcript ---
 Mon 2016-08-08 23:08:07: Session 206969; child 0007
 Mon 2016-08-08 23:08:07: Parsing message <xxxxxxxxxxxxxxxxxx\pd50002638663.msg>
 Mon 2016-08-08 23:08:07: *  From: serv...@baidu.com
 Mon 2016-08-08 23:08:07: *  To: 147133...@qq.com
 Mon 2016-08-08 23:08:07: *  Subject: ?????????????????
 Mon 2016-08-08 23:08:07: *  Size (bytes): 2167
 Mon 2016-08-08 23:08:07: *  Message-ID:
 Mon 2016-08-08 23:08:07: Attempting SMTP connection to [qq.com]
 Mon 2016-08-08 23:08:07: Resolving MX records for [qq.com] (DNS Server: 
192.168.87.2)...
 Mon 2016-08-08 23:08:07: *  P=010 S=000 D=qq.com TTL=(92) MX=[mx3.qq.com]
 Mon 2016-08-08 23:08:07: *  P=020 S=001 D=qq.com TTL=(92) MX=[mx2.qq.com]
 Mon 2016-08-08 23:08:07: *  P=030 S=002 D=qq.com TTL=(92) MX=[mx1.qq.com]
 Mon 2016-08-08 23:08:07: Attempting SMTP connection to [mx3.qq.com:25]
 Mon 2016-08-08 23:08:07: Resolving A record for [mx3.qq.com] (DNS Server: 
192.168.87.2)...
 Mon 2016-08-08 23:08:11: *  D=mx3.qq.com TTL=(10) A=[103.7.30.40]
 Mon 2016-08-08 23:08:11: Attempting SMTP connection to [103.7.30.40:25]
 Mon 2016-08-08 23:08:11: Waiting for socket connection...
 Mon 2016-08-08 23:08:11: *  Connection established (192.168.1.244:61318 -> 
103.7.30.40:25)
 Mon 2016-08-08 23:08:11: Waiting for protocol to start...
 Mon 2016-08-08 23:08:11: <-- 220 newmx59.qq.com MX QQ Mail Server
 Mon 2016-08-08 23:08:11: --> EHLO abcdomain.com
 Mon 2016-08-08 23:08:11: <-- 250-newmx59.qq.com
 Mon 2016-08-08 23:08:11: <-- 250-SIZE 73400320
 Mon 2016-08-08 23:08:11: <-- 250-STARTTLS
 Mon 2016-08-08 23:08:11: <-- 250 OK
 Mon 2016-08-08 23:08:11: --> STARTTLS
 Mon 2016-08-08 23:08:11: <-- 220 Ready to start TLS
 Mon 2016-08-08 23:08:11: SSL negotiation successful (TLS 1.0, 2048 bit key 
exchange, 128 bit RC4 encryption)
 Mon 2016-08-08 23:08:11: --> EHLO abcdomain.com
 Mon 2016-08-08 23:08:11: <-- 250-newmx59.qq.com
 Mon 2016-08-08 23:08:11: <-- 250-SIZE 73400320
 Mon 2016-08-08 23:08:11: <-- 250 OK
 Mon 2016-08-08 23:08:11: --> MAIL From:<jul...@abcdomain.com> SIZE=2167
 Mon 2016-08-08 23:08:11: <-- 250 Ok
 Mon 2016-08-08 23:08:11: --> RCPT To:<147133...@qq.com>
 Mon 2016-08-08 23:08:11: <-- 250 Ok
 Mon 2016-08-08 23:08:11: --> DATA
 Mon 2016-08-08 23:08:12: <-- 354 End data with <CR><LF>.<CR><LF>
 Mon 2016-08-08 23:08:12: Sending <xxxxxxxxxxxxxxxxxx\pd50002638663.msg> to 
[103.7.30.40]
 Mon 2016-08-08 23:08:12: Transfer Complete
 Mon 2016-08-08 23:08:14: <-- 550 Mail content denied. 
http://service.mail.qq.com/cgi-bin/help?subtype=1&&id=20022&&no=1000726
 Mon 2016-08-08 23:08:14: --> QUIT
--- End Transcript ---
: Message contains [1] file attachments


The information contained in this e-mail, including any attachment, is 
confidential and/or legally privileged. If you are not the intended recipient, 
please notify the sender and delete this e-mail and its attachment from your 
system. Any unauthorized dissemination, distribution, copying, or other use of 
this e-mail or its attachment is strictly prohibited.
Please consider the environment before printing this e-mail.

--0808-2308-14-PART-BREAK
Content-Type: message/rfc822; name="md50001884370.eml"
Content-Transfer-Encoding: 7bit

X-MDAV-Result: clean
X-MDAV-Processed: abcdomain.com, Mon, 08 Aug 2016 23:07:43 +0700
Received: from abcdomain.com by abcdomain.com (MDaemon PRO v14.0.3) 
    with ESMTP id md50005965506.msg for <147133...@qq.com>;
    Mon, 08 Aug 2016 23:07:41 +0700
X-Spam-Processed: abcdomain.com, Mon, 08 Aug 2016 23:07:41 +0700
    (not processed: message from valid local sender)
X-Return-Path: jul...@abcdomain.com
X-Envelope-From: jul...@abcdomain.com
X-MDaemon-Deliver-To: 147133...@qq.com
From: "yc" <serv...@baidu.com>
To: <147133...@qq.com>
Subject: =?gb2312?B?m9LsZaBv8ISc/PR24rWBU7/fhM27js7rzdGKUsNRjEzKaA==?=
Content-Type: text/html; charset="gb2312"
Content-Transfer-Encoding: base64

--0808-2308-14-PART-BREAK--

===== SMTP Log =====

Mon 2016-08-08 23:07:37: ----------
Mon 2016-08-08 23:07:39: Session 206958; child 0004
Mon 2016-08-08 23:07:39: Accepting SMTP connection from [192.168.87.2:56060] to 
[192.168.1.244:25]
Mon 2016-08-08 23:07:39: --> 220 abcdomain.com ESMTP MDaemon 14.0.3; Mon, 08 
Aug 2016 23:07:39 +0700
Mon 2016-08-08 23:07:39: <-- EHLO abcdomain.com
Mon 2016-08-08 23:07:39: --> 250-abcdomain.com Hello abcdomain.com, pleased to 
meet you
Mon 2016-08-08 23:07:39: --> 250-ETRN
Mon 2016-08-08 23:07:39: --> 250-AUTH LOGIN CRAM-MD5 PLAIN
Mon 2016-08-08 23:07:39: --> 250-8BITMIME
Mon 2016-08-08 23:07:39: --> 250-STARTTLS
Mon 2016-08-08 23:07:39: --> 250 SIZE
Mon 2016-08-08 23:07:40: <-- MAIL FROM: <jul...@abcdomain.com>
Mon 2016-08-08 23:07:40: --> 250 <jul...@abcdomain.com>, Sender ok
Mon 2016-08-08 23:07:40: <-- RCPT TO: <147133...@qq.com>
Mon 2016-08-08 23:07:40: --> 250 <147133...@qq.com>, Recipient ok
Mon 2016-08-08 23:07:40: <-- DATA
Mon 2016-08-08 23:07:40: Creating temp file (SMTP): 
d:\mdaemon\temp\md50001884365.tmp
Mon 2016-08-08 23:07:40: --> 354 Enter mail, end with <CRLF>.<CRLF>
Mon 2016-08-08 23:07:41: Message size: 1656 bytes
Mon 2016-08-08 23:07:41: Passing message through AntiVirus (Size: 1656)...
Mon 2016-08-08 23:07:41: *  Message is clean (no viruses found)
Mon 2016-08-08 23:07:41: ---- End AntiVirus results
Mon 2016-08-08 23:07:41: Message creation successful: 
d:\mdaemon\inbound\md50005965506.msg
Mon 2016-08-08 23:07:41: --> 250 Ok, message saved <Message-ID: >
Mon 2016-08-08 23:07:41: <-- QUIT
Mon 2016-08-08 23:07:41: --> 221 See ya in cyberspace
Mon 2016-08-08 23:07:41: SMTP session successful (Bytes in/out: 1766/410)
Mon 2016-08-08 23:07:41: ----------




Terima kasih,Julian

 

    On Tuesday, August 9, 2016 5:50 PM, Syafril Hermansyah 
<syaf...@dutaint.co.id> wrote:
 

 On 09/08/16 13:42, MDaemon-L@dutaint.com -- Julian Aristo via MDaemon-L
wrote:
> Ada user yang terus menerus menerima spam email. Sudah coba block IP nya
> 103.7.30.40 pakai IP screening tapi tetap spam email diterima.


> Tue 2016-08-09 07:24:22: *  From: serv...@baidu.com
>  Tue 2016-08-09 07:24:22: *  To: 472610...@qq.com


Bisa dicarikan transaksi mail dari sender diatas di smtp-in log?

-- 
syafril
-------
Syafril Hermansyah
MDaemon-L Moderators, MDaemon 16.5-64 Beta A, SP 5.0.1-64
Harap tidak cc: atau kirim ke private mail untuk masalah MDaemon.

We are products of our past, but we don't have to be prisoners of it.
    --- Rick Warren


-- 
--MDaemon-L----------------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 16.0.4, SP 5.0.1, OC 3.6.1, SG 4.0.1






--
--MDaemon-L----------------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 16.0.4, SP 5.0.1, OC 3.6.1, SG 4.0.1

Kirim email ke