My server IP was blacklisted for sending out spam and I am tracking down the program sending spam.
I did netstat
, and it shows a lot of programs using port 25
e.g
tcp 0 182 10.205.3.7:38995 xxx.55.92.168:25 ESTABLISHED 31909/smtp
tcp 0 0 127.0.0.1:443 127.0.0.1:52160 TIME_WAIT -
tcp 0 0 10.205.3.7:53001 xxx.186.99.50:25 TIME_WAIT -
tcp 0 0 127.0.0.1:52171 127.0.0.1:443 TIME_WAIT -
tcp 0 0 127.0.0.1:443 127.0.0.1:52254 TIME_WAIT -
tcp 0 0 127.0.0.1:52251 127.0.0.1:443 TIME_WAIT -
tcp 0 0 127.0.0.1:443 127.0.0.1:52049 TIME_WAIT -
tcp 0 0 127.0.0.1:52091 127.0.0.1:443 TIME_WAIT -
tcp 0 0 10.205.3.7:59762 xxx.17.41.47:25 ESTABLISHED 2147/smtp
tcp 0 1 10.205.3.7:50400 xxx.88.180.116:25 SYN_SENT 2151/smtp
tcp 0 0 127.0.0.1:52083 127.0.0.1:443 TIME_WAIT -
tcp 0 0 10.205.3.7:55824 xxx.127.217.16:25 TIME_WAIT -
tcp 0 0 10.205.3.7:35888 xxx.27.42.58:25 ESTABLISHED 1913/smtp
tcp 0 0 127.0.0.1:443 127.0.0.1:52242 TIME_WAIT -
tcp 0 0 10.205.3.7:80 xxx.76.138.169:25703 TIME_WAIT -
tcp 0 0 10.205.3.7:51114 xxx.54.188.110:25 ESTABLISHED 31424/smtp
tcp 0 0 127.0.0.1:443 127.0.0.1:52059 TIME_WAIT -
tcp 0 149 10.205.3.7:34686 xxx.125.136.27:25 ESTABLISHED 703/smtp
tcp 0 0 10.205.3.7:34669 xxx.125.136.27:25 ESTABLISHED 32586/smtp
tcp 0 0 127.0.0.1:443 127.0.0.1:52238 TIME_WAIT -
tcp 0 0 127.0.0.1:443 127.0.0.1:52150 TIME_WAIT -
tcp 0 0 127.0.0.1:52038 127.0.0.1:443 TIME_WAIT -
tcp 0 0 10.205.3.7:37635 xxx.115.11.16:25 ESTABLISHED 31093/smtp
tcp 0 0 10.205.3.7:59959 xx.127.217.21:25 ESTABLISHED 690/smtp
Is postfix the only program that should be using port 25, or is the word smtp
an alias for all the processes of postfix?
------ EDIT ----
Thank you all for your help, just to clarify:
- I'm not running an open relay, I checked.
- From the
netstat
output it was not really clear which process belongs to postfix.