iamnoone 發表於 2007-2-14 15:07:37

重覆寄信!!

各位先進好:<br>小弟日前遇到一個問題,公司業務寄賀卡給客戶,因要寄給多人,所以用密件副本方式,即<br>以一人列收件人欄,其餘列在密件副本欄內,奇怪的是,列在收件人這個客戶卻收到了上百<br>封由本公司業務所發的信件(內容相同),查看了log,發現確有上百個寄給該客戶的記錄。<br>以下是其中一個log的記載,其餘的log內容一樣,唯一不同處在於紅色字體的數字部份會<br>不規則變動,希望各位先進能夠幫小弟解惑,感激&#33;&#33;<br>----------------------------------------------------------------------------------------------<br>Mon 2007-02-12 14:36:30: --&#62; EHLO *******.com.tw<br>Mon 2007-02-12 14:36:30: &lt;-- 250-<span style='color:red'>bay0-mc4-f22.bay0</span>.hotmail.com (3.3.1.4) Hello <br>Mon 2007-02-12 14:36:30: &lt;-- 250-SIZE 29696000<br>Mon 2007-02-12 14:36:30: &lt;-- 250-PIPELINING<br>Mon 2007-02-12 14:36:30: &lt;-- 250-8bitmime<br>Mon 2007-02-12 14:36:30: &lt;-- 250-BINARYMIME<br>Mon 2007-02-12 14:36:30: &lt;-- 250-CHUNKING<br>Mon 2007-02-12 14:36:30: &lt;-- 250-AUTH LOGIN<br>Mon 2007-02-12 14:36:30: &lt;-- 250-AUTH=LOGIN<br>Mon 2007-02-12 14:36:30: &lt;-- 250 OK<br>Mon 2007-02-12 14:36:30: --&#62; MAIL From:&lt;*****@*****.com.tw&gt; SIZE=107388<br>Mon 2007-02-12 14:36:30: &lt;-- 250 *****@******.com.tw....Sender OK<br>Mon 2007-02-12 14:36:30: --&#62; RCPT To:&lt;******@hotmail.com&gt;<br>Mon 2007-02-12 14:36:31: &lt;-- 250 ******@hotmail.com <br>Mon 2007-02-12 14:36:31: --&#62; DATA<br>Mon 2007-02-12 14:36:31: &lt;-- 354 Start mail input; end with &lt;CRLF&gt;.&lt;CRLF&gt;<br>Mon 2007-02-12 14:36:31: Sending &lt;d:\mdaemon\remoteq\pd50000057429.msg&gt; to <br>Mon 2007-02-12 14:36:40: Transfer Complete.<br>Mon 2007-02-12 14:36:41: &lt;-- 250 &lt;[email protected]&gt; Queued mail for delivery<br>Mon 2007-02-12 14:36:41: --&#62; QUIT<br>Mon 2007-02-12 14:36:41: &lt;-- 221 bay0-mc4-f22.bay0.hotmail.com Service closing transmission channel<br>Mon 2007-02-12 14:36:41: SMTP session successful (Bytes in/out: 1378/214998)<br>

MarchFun 發表於 2007-2-14 15:15:05

這個似乎是 SMTP OUT 的內容,最好能把 SMTP IN 也提供來看看。

iamnoone 發表於 2007-2-15 09:57:59

<!--QuoteBegin-March Fun+2007/2/14 - 15:15--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>引言</b> (March Fun @ 2007/2/14 - 15:15)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->這個似乎是 SMTP OUT 的內容,最好能把 SMTP IN 也提供來看看。<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd--><br>感謝站長的回覆&#33;&#33;<br>以下是小弟找到唯一包含該異常收件人的STMP IN LOG(FROM:本公司業務)<br>因內容冗長,故有做刪減,刪減部份皆為<br><span style='color:blue'>&lt;-- RCPT TO: &lt; &gt;<br> --&#62; 250 &lt; &gt;, Recipient ok</span><br>型態。<br><br><br>STMP IN LOG:<br>-----------------------------------------------------------------------------------------------<br>Mon 2007-02-12 11:43:57: Session 367; child 2; thread 3388<br>Mon 2007-02-12 11:27:54: Accepting SMTP connection from <br>Mon 2007-02-12 11:27:54: --&#62; 220 *******.com.tw ESMTP MDaemon 9.5.4; Mon, 12 Feb 2007 11:27:54 +0800<br>Mon 2007-02-12 11:27:54: &lt;-- EHLO ********<br>Mon 2007-02-12 11:27:54: --&#62; 250-********.com.tw Hello ********, pleased to meet you<br>Mon 2007-02-12 11:27:54: --&#62; 250-ETRN<br>Mon 2007-02-12 11:27:54: --&#62; 250-AUTH=LOGIN<br>Mon 2007-02-12 11:27:54: --&#62; 250-AUTH LOGIN CRAM-MD5<br>Mon 2007-02-12 11:27:54: --&#62; 250-8BITMIME<br>Mon 2007-02-12 11:27:54: --&#62; 250 SIZE 15360000<br>Mon 2007-02-12 11:27:54: &lt;-- MAIL FROM: &lt;****@*****.com.tw&gt;<br>Mon 2007-02-12 11:27:54: --&#62; 250 &lt;*****@*****.com.tw &gt;, Sender ok<br>Mon 2007-02-12 11:27:54: &lt;-- RCPT TO: &lt;Alex_*****@global******.com&gt;<br>Mon 2007-02-12 11:27:54: --&#62; 250 &lt; Alex_*****@global******.com &gt;, Recipient ok<br>Mon 2007-02-12 11:27:54: &lt;-- RCPT TO: &lt;alice****[email protected]&gt;<br>Mon 2007-02-12 11:27:54: --&#62; 250 &lt; alice****[email protected] &gt;, Recipient ok<br>Mon 2007-02-12 11:27:54: &lt;-- RCPT TO: &lt;allan_****@global*******.com&gt;<br>Mon 2007-02-12 11:27:54: --&#62; 250 &lt; allan_****@global*******.com &gt;, Recipient ok<br>Mon 2007-02-12 11:27:54: &lt;-- RCPT TO: &lt;a****@a*****.com&gt;<br>Mon 2007-02-12 11:27:54: --&#62; 250 &lt; a****@a*****.com &gt;, Recipient ok<br>Mon 2007-02-12 11:27:54: &lt;-- RCPT TO: &lt;are****@ind****.com&gt;<br>Mon 2007-02-12 11:27:54: More than 5 RCPT commands encountered; this session tarpitted with a 10 second initial delay scaling by 1.00<br><span style='color:red'>Mon 2007-02-12 11:34:54: &lt;-- RCPT TO: &lt;*****@hotmail.com&gt;<br>Mon 2007-02-12 11:34:54: --&#62; 250 &lt;*****@hotmail.com&gt;,Recipient ok<br>有異常的收件人</span><br>Mon 2007-02-12 11:35:25: &lt;-- RSET<br>Mon 2007-02-12 11:35:25: --&#62; 250 RSET? Well, ok.<br>Mon 2007-02-12 11:35:35: &lt;-- MAIL FROM: &lt;****@*****.com.tw &gt;<br>Mon 2007-02-12 11:35:35: --&#62; 250 &lt;*****@*****.com.tw &gt;, Sender ok<br>Mon 2007-02-12 11:35:45: &lt;-- RCPT TO: &lt; Alex_*****@global******.com &gt;<br>Mon 2007-02-12 11:35:45: --&#62; 250 &lt; Alex_*****@global******.com &gt;, Recipient ok<br>Mon 2007-02-12 11:35:55: &lt;-- RCPT TO: &lt; alice****[email protected] &gt;<br>Mon 2007-02-12 11:35:55: --&#62; 250 &lt; alice****[email protected] &gt;, Recipient ok<br>Mon 2007-02-12 11:36:05: &lt;-- RCPT TO: &lt; allan_****@global*******.com &gt;<br>Mon 2007-02-12 11:36:05: --&#62; 250 &lt; allan_****@global*******.com &gt;, Recipient ok<br>Mon 2007-02-12 11:36:15: &lt;-- RCPT TO: &lt; a****@a*****.com &gt;<br>Mon 2007-02-12 11:36:15: --&#62; 250 &lt; a****@a*****.com &gt;, Recipient ok<br>Mon 2007-02-12 11:36:25: &lt;-- RCPT TO: &lt; are****@ind****.com &gt;<br>Mon 2007-02-12 11:36:25: --&#62; 250 &lt; are****@ind****.com &gt;, Recipient ok<br><span style='color:red'>Mon 2007-02-12 11:43:26: &lt;-- RCPT TO: &lt;*****@hotmail.com&gt;<br>Mon 2007-02-12 11:43:26: --&#62; 250 &lt;*****@hotmail.com &gt;, Recipient ok<br>有異常的收件人</span><br>Mon 2007-02-12 11:43:56: &lt;-- DATA<br>Mon 2007-02-12 11:43:56: Creating temp file (SMTP): c:\mdaemon\temp\md50000011015.tmp<br>Mon 2007-02-12 11:43:56: --&#62; 354 Enter mail, end with &lt;CRLF&gt;.&lt;CRLF&gt;<br>Mon 2007-02-12 11:43:56: Message size: 106833 bytes<br>Mon 2007-02-12 11:43:56: Performing DomainKeys lookup (Sender: ****@*****.com.tw)<br>Mon 2007-02-12 11:43:56: * File: c:\mdaemon\temp\md50000011015.tmp<br>Mon 2007-02-12 11:43:56: * Message-ID: n/a<br>Mon 2007-02-12 11:43:56: * Querying for policy: *******.com.tw<br>Mon 2007-02-12 11:43:56: *  Querying: _domainkey.*******.com.tw ...<br>Mon 2007-02-12 11:43:56: *  DNS: Name server reports domain name unknown<br>Mon 2007-02-12 11:43:56: * Result: pass<br>Mon 2007-02-12 11:43:56: ---- End DomainKeys results<br>Mon 2007-02-12 11:43:56: Performing DKIM lookup<br>Mon 2007-02-12 11:43:56: * File: c:\mdaemon\temp\md50000011015.tmp<br>Mon 2007-02-12 11:43:56: * Message-ID: n/a<br>Mon 2007-02-12 11:43:56: * Result: neutral<br>Mon 2007-02-12 11:43:56: ---- End DKIM results<br>Mon 2007-02-12 11:43:56: Passing message through AntiVirus (Size: 106833)...<br>Mon 2007-02-12 11:43:57: * Message is clean (no viruses found)<br>Mon 2007-02-12 11:43:57: ---- End AntiVirus results<br>Mon 2007-02-12 11:43:57: Message creation successful: d:\mdaemon\inbound\md50000200732.msg<br>Mon 2007-02-12 11:43:57: --&#62; 250 Ok, message saved &lt;Message-ID: &gt;<br>Mon 2007-02-12 11:43:57: &lt;-- QUIT<br>Mon 2007-02-12 11:43:57: --&#62; 221 See ya in cyberspace<br>Mon 2007-02-12 11:43:57: SMTP session successful (Bytes in/out: 110508/4866)

MarchFun 發表於 2007-2-15 11:49:41

<!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>引言</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->Mon 2007-02-12 11:27:54: More than 5 RCPT commands encountered; this session tarpitted with a 10 second initial delay scaling by 1.00<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd--><br><br>其中這一句沒看過,有可能跟這個有關。你設定了什麼與這類相關的東西嗎?

iamnoone 發表於 2007-2-15 13:55:26

<!--QuoteBegin-March Fun+2007/2/15 - 11:49--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>引言</b> (March Fun @ 2007/2/15 - 11:49)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--><br>其中這一句沒看過,有可能跟這個有關。你設定了什麼與這類相關的東西嗎?<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd--><br>再次感謝站長回覆&#33;&#33;<br>因來公司資歷尚淺,設定是由先前的師兄所設定的,不過小弟查了一下說明,此設定應在 Mebu內,如附件。<br><br>依小弟的拙見,該設定應是防止有人利用我們的伺服器來做大量廣告信而設的機制,<br>是否是因這個設定而造成前述的情形,不得而知。<br><br>不過小弟在此補充幾點:<br>1.因客戶數眾多,所以業務分了三批來寄發,皆以前述的密件副本方式,而有異樣僅有一人,此客戶在第一批。<br>2.經站長指點,查看SMTP IN LOG , 共有三個log,內容與上面所post的一樣,有「More than 5 RCPT commands encountered; this session tarpitted with a 10 second initial delay scaling by 1.00]的訊息。<br>3.從SMTP OUT的記錄來看,所寄發給有異樣客戶的次數大於要寄的總客戶數(即寄了200多次給該客戶,而總共要寄的客戶卻只有50幾位)<br>4.用戶端與主機已做過掃毒,並無異狀。<br><br>小弟不知提供這幾點補充是否有幫助?

MarchFun 發表於 2007-2-15 15:03:08

應該是跟這個有關,因為你這裏設定當一封信寄給 5 個人以上時就啟動陷阱 (tarpit) 機制。所以可能因為這樣造成那封信因為中斷而一再的重寄。<br><br>最下面一行你注意一下,意思是驗證過的來源不必受此約束。你最好把公司內的 IP 全部加入信任的 IP 或列入區域網路的設定中,可以免除這項機制的檢查。

iamnoone 發表於 2007-2-15 16:45:19

<!--QuoteBegin-March Fun+2007/2/15 - 15:03--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>引言</b> (March Fun @ 2007/2/15 - 15:03)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->公司內的 IP 全部加入信任的 IP 或列入區域網路的設定中,可以免除這項機制的檢查。<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd--><br>對於站長的關注,小弟由衷感激&#33;&#33;<br>小弟想再請教幾個問題:<br>1.我看了一下的設定,my local IP 的值為192.168.*.*,這是否意為內部裡的PC(均為192.168.1.xxx)是屬於<span style='color:red'>驗證過的來源</span>?<br>2.因公司業務是使用NB,常需在外地跑,所以在其MS Outlook的smtp server是設真實IP(61.218.xxx.xxx,網卡IP還是192.168.1.xxx),所以在log page 的host是顯示 61.218.xxx.xxx,那我再把61.218.xxx.xxx這個真實IP加到my local IP,這樣就ok了嗎?
頁: [1]
檢視完整版本: 重覆寄信!!