On 25/09/19 09.47, [email protected] wrote:
> Mohon bantuandan pencerahannya untuk email SPAM yang dikirim oleh email
> account nya sendiri.
> 
> Berikut log smtp-in nya:

> Tue 2019-09-24 07:02:35: Accepting SMTP connection from
> [138.255.131.189:13717] to [117.102.89.155:25]
> 
> Tue 2019-09-24 07:02:35: --> 220 mail.mandau.id ESMTP MDaemon 14.0.0;
> Tue, 24 Sep 2019 07:02:35 +0700
> 
> Tue 2019-09-24 07:02:36: <-- EHLO [138.255.131.189]
>
> Tue 2019-09-24 07:02:36: --> 250-mail.mandau.id Hello [138.255.131.189],
> pleased to meet you
> 
> Tue 2019-09-24 07:02:36: <-- MAIL From:<[email protected]
> <mailto:[email protected]>>


Mail ini akan ditolak dengan berbagai macam cara


aktifkan HELO FQDN check

http://mdaemon.dutaint.co.id/mdaemon/19.0/index.html?security--reverse_lookup.htm

[x] Perform lookup on HELO/EHLO domain
[ ] ...send 501 and close connection on forged identification (caution)
[x] Refuse to accept mail if a lookup returns 'domain not found'
[x] ...send 501 error code (normally sends 451 error code)
[x] ...and then close the connection
[x] Exempt authenticated sessions (lookup will defer until after MAIL)


atau aktifkan Sender Authentication check

http://mdaemon.dutaint.co.id/mdaemon/19.0/index.html?security--smtp_authentication.htm

[x] Authentication is always required when mail is from local accounts
        [ ] ...unless message is to a local account
[x] Authentication is always required when mail is sent from local IPs
[x] Credentials used must match those of the return-path address
[x] Credentials used must match those of the 'From:' header address
[x] Mail from 'Postmaster', 'abuse', 'webmaster' must be authenticated
[x] Do not apply POP Before SMTP to authenticated sessions


> Tue 2019-09-24 07:02:00: Accepting SMTP connection from [85.8.0.217:33221] to 
> [117.102.89.155:25]
> 
> Tue 2019-09-24 07:02:00: --> 220 mail.mandau.id ESMTP MDaemon 14.0.0; Tue, 24 
> Sep 2019 07:02:00 +0700
> 
> Tue 2019-09-24 07:02:00: <-- EHLO h85-8-0-217.cust.a3fiber.se


Sama saja dengan diatas, bisa juga ditolak dengan pengaktifan domain
antispoofing (SPF, DKIM, DMARC).


https://www.mail-archive.com/[email protected]/msg44714.html



-- 
syafril
-------
Syafril Hermansyah
MDaemon-L Moderators, running MDaemon 19.5.0-64 bit Beta B
Harap tidak cc: atau kirim ke private mail untuk masalah MDaemon.

Never give up on anything.
If you fail, try, try and try again.
You are learning the best ways of doing things.
        --- Lailah Gifty Akita


-- 
--[mdaemon-l]----------------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server di Indonesia

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Berlangganan: Kirim mail ke [email protected]
Henti Langgan: Kirim mail ke [email protected]
Versi terakhir MD 19.0.3, SG 6.1.0


Kirim email ke