收到ISP滥用通知,求教如何排查Postfix SASL认证失败问题
Let's walk through this step by step to figure out why your public IP got flagged for abuse, and how you can track down and fix the root cause.
First, let's break down the logs you shared:
postfix/smtpd[21723]: warning: unknown[X.X.X.X]: SASL LOGIN authentication failed: UGFzc3dvcmQ6 Apr 26 10:51:59 shorelinedelivery postfix/smtpd[21723]: disconnect from unknown[X.X.X.X] Apr 26 13:37:31 shorelinedelivery postfix/smtpd[25499]: connect from unknown[103.215.211.106] Apr 26 13:37:35 shorelinedelivery postf...
That SASL LOGIN authentication failed: UGFzc3dvcmQ6 line is key — UGFzc3dvcmQ6 is Base64 for "Password:", meaning someone tried brute-forcing a login to your Postfix mail server and failed. The random external IP (103.215.211.106) connecting to your server is another sign of automated login attempts. Repeated brute-force attacks, or successful logins that lead to spam being sent from your server, are almost certainly why your ISP flagged your IP.
Start by digging into your full mail logs (usually /var/log/mail.log or /var/log/maillog on Linux) to see if any unauthorized users actually managed to log in. Look for lines like this:
postfix/smtpd[XXXX]: login: user=<someuser>, method=LOGIN, rip=Y.Y.Y.Y, lip=Z.Z.Z.Z, mpid=XXXX, status=ok
If you see logins from unfamiliar IPs, your mail account passwords are compromised — someone is using your server to send spam. Immediately change all mail account passwords (use strong, unique ones) and enable two-factor authentication if your mail setup supports it.
An open relay (a server that lets anyone send mail through it without authentication) is a huge red flag for ISPs. Check your Postfix config file (/etc/postfix/main.cf) for these critical settings:
- Ensure
smtpd_sasl_auth_enable = yes(if you need client login access) - Make sure
smtpd_recipient_restrictionsincludesreject_unauth_destination— this blocks unauthenticated users from sending mail to external addresses - Check for
smtpd_client_restrictionsthat limit suspicious connections, likereject_rbl_client zen.spamhaus.org(blocks IPs known for spam)
You can quickly list these settings with:
postconf -n | grep -E "smtpd_sasl|smtpd_recipient_restrictions|smtpd_client_restrictions"
If you find your server is configured as an open relay, fix the settings and restart Postfix (systemctl restart postfix).
If you don't see successful unauthorized logins, your server might be infected with malware that's sending spam directly (bypassing Postfix authentication).
- Check running processes for suspicious mail-related activity:
ps aux | grep -E "sendmail|smtp|postfix" - Look at your Postfix mail queue for piles of unsent spam:
If you see hundreds/thousands of spam messages, clear the queue withpostqueue -ppostsuper -d ALL(double-check these aren't legitimate emails first!). - Scan your server for malware with tools like ClamAV:
clamscan -r / --exclude-dir=/proc --exclude-dir=/sys
Once you've done your initial troubleshooting, reach out to your ISP:
- Explain what you've found (brute-force attempts, compromised passwords, malware, etc.)
- Share relevant log snippets to show you're actively fixing the issue
- Ask them to remove the abuse flag from your IP
To stop this from happening again:
- Set up
fail2banto automatically block IPs that make repeated failed login attempts to Postfix (enable thepostfixandpostfix-sasljail rules) - Limit login attempt rates in Postfix with
smtpd_client_rate_limitandsmtpd_sasl_authenticated_header - Keep your server's OS and all software (Postfix, Dovecot, etc.) fully updated to patch security holes
- Avoid using weak passwords for any server or mail accounts
内容的提问来源于stack exchange,提问作者user6633639

