ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Outgoing Spam Email from EE install. HELP!

February 01, 2012 9:49am

Subscribe [1]
  • #1 / Feb 01, 2012 9:49am

    jasonathopi

    35 posts

    Long story short, my hosting provider blocked my main email address because I was sending out hundreds of spam emails an hour. They told me that most likely one of my EE installs had been hacked. After changing my email account password I’m getting TONS of kickback emails with this message

    Hi. This is the qmail-send program at oproxy3-pub.bluehost.com.
    I'm afraid I wasn't able to deliver your message to the following addresses.
    This is a permanent error; I've given up. Sorry it didn't work out.
    
    <[email protected]>:
    Connection timed out doing CNAME lookup (#4.4.3)
    I'm not going to try again; this message has been in the queue too long.
    
    --- Enclosed are the original headers of the message.
    
    From: <[email protected]>
    Subject: Someone just responded to your comment
    Date: January 25, 2012 8:20:24 AM EST
    To: .(JavaScript must be enabled to view this email address)
    Reply-To: "[email protected]" <[email protected]>
    
    (Body supressed)

    Does this mean it’s a site that has a comment form built into it? I have about 30 EE installs on my server and I’m trying to narrow it down.

    Also what steps do I need to take to fix this. So far I have:
    1. Logged into every site and taken my email address out of the “Email Configuration”
    2. Upgraded the software on sites with comment forms.
    3. Deleted old inactive EE sites from my server.

    I’m still getting the spam kickbacks. Any other ideas?

    Thanks,
    Jason

     

  • #2 / Feb 02, 2012 3:51pm

    Dan Decker

    7338 posts

    Hi jasonathopi,

    From the information you provided, it looks like notifications are trying to be sent to bad email accounts. Perhaps as a part of member registration? Have you noticed an increase in Spam registrations across any of the sites? I would at any sites that have member registration enabled and focus on any pending member accounts. The problem will be that these attempts to send are at the email server level and not at the ExpressionEngine level. The email server will make so many attempts to deliver the message before giving up. At this point, it would be best to continue working with the host, as ExpressionEngine has “handed off” the sending of the email.

    Cheers,

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases