Hello
I was noticed by my ISP which told me that my mail server is sending spam mails. After further investigation I saw the problem at the logs.
My question is how it could have happened and how I can fix it.
What I can tell is that I have disabled the usage of iptables by Docker to test something with my IDS and I forgot to activate it again. Now I activated it again, but I still get mail logs, but at least I get the IP correctly logged.
Please see my log:
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: PASS OLD [ASSUMED_INTRUDER_IP]:51373
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51372 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25226]: disconnect from unknown[ASSUMED_INTRUDER_IP] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23848]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25231]: disconnect from unknown[ASSUMED_INTRUDER_IP] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[26877]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtp[518]: D356A1CEA83: to=<REDACTED>, relay=dpworld-com.mail.protection.outlook.com[104.47.1.36]:25, delay=182786, delays=182555/230/0.81/0.51, dsn=4.7.500, status=deferred (host dpworld-com.mail.protection.outlook.com[104.47.1.36] said: 451 4.7.500 Server busy. Please try again later from [89.58.28.90]. (S77719) [VE1EUR01FT055.eop-EUR01.prod.protection.outlook.com 2023-07-24T12:36:53.730Z 08DB8BF9D8C80D96] (in reply to end of DATA command))
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: B85841CEFF1: from=<it@mail.libertyrising.de>, size=858063, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51374 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25226]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtp[463]: 7E2871C84CE: to=<REDACTED>, relay=internity-pl.mail.protection.outlook.com[104.47.17.74]:25, delay=192025, delays=191800/224/0.6/0.26, dsn=4.7.500, status=deferred (host internity-pl.mail.protection.outlook.com[104.47.17.74] said: 451 4.7.500 Server busy. Please try again later from [89.58.28.90]. (S77719) [DB8EUR05FT012.eop-eur05.prod.protection.outlook.com 2023-07-24T12:36:53.728Z 08DB8BC357C36BCC] (in reply to end of DATA command))
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 521471C91B2: from=<it@mail.libertyrising.de>, size=858003, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25151]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: AE2031D0745: from=<it@mail.libertyrising.de>, size=858022, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23420]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51375 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25219]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[26877]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[24995]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[24017]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23848]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 0CDD91CC1AA: from=<it@mail.libertyrising.de>, size=858050, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25222]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: B49261D2CFB: from=<it@mail.libertyrising.de>, size=858034, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51376 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[24995]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: E52F31D05E0: from=<it@mail.libertyrising.de>, size=858009, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23420]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 862731C81D9: from=<it@mail.libertyrising.de>, size=857973, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: PASS OLD [ASSUMED_INTRUDER_IP]:51376
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25231]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 4D6971D31EB: from=<it@mail.libertyrising.de>, size=857973, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51377 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: D8A011C8876: from=<it@mail.libertyrising.de>, size=858057, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25219]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: PASS OLD [ASSUMED_INTRUDER_IP]:51377
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25222]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25234]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51378 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25151]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 8BC9D1D201F: from=<it@mail.libertyrising.de>, size=858006, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25226]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25231]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23848]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25222]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25219]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: PASS OLD [ASSUMED_INTRUDER_IP]:51378
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23854]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: F2DB51CB975: from=<it@mail.libertyrising.de>, size=858009, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51379 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23726]: warning: Unable to look up MX host for robimyopinie.eu: Host not found, try again
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23726]: NOQUEUE: reject: RCPT from unknown[ASSUMED_INTRUDER_IP]: 554 5.7.1 <REDACTED>: Relay access denied; from=<it@mail.libertyrising.de> to=<REDACTED> proto=ESMTP helo=<mail.libertyrising.de>
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 531701DA017: from=<it@mail.libertyrising.de>, size=858057, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25234]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: PASS OLD [ASSUMED_INTRUDER_IP]:51379
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25226]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 82CF11C971C: from=<it@mail.libertyrising.de>, size=858019, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[24995]: NOQUEUE: reject: RCPT from unknown[ASSUMED_INTRUDER_IP]: 554 5.7.1 <REDACTED>: Relay access denied; from=<it@mail.libertyrising.de> to=<REDACTED> proto=ESMTP helo=<mail.libertyrising.de>
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtp[463]: Trusted TLS connection established to hkspedition-de0e.mail.protection.outlook.com[104.47.7.138]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[26877]: NOQUEUE: reject: RCPT from unknown[ASSUMED_INTRUDER_IP]: 554 5.7.1 <REDACTED>: Relay access denied; from=<it@mail.libertyrising.de> to=<REDACTED> proto=ESMTP helo=<mail.libertyrising.de>
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23726]: disconnect from unknown[ASSUMED_INTRUDER_IP] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23726]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[24995]: disconnect from unknown[ASSUMED_INTRUDER_IP] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: D0A791C99BE: from=<it@mail.libertyrising.de>, size=858022, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[26877]: disconnect from unknown[ASSUMED_INTRUDER_IP] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25234]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23854]: warning: TLS SNI from unknown[ASSUMED_INTRUDER_IP] is invalid: 89.58.28.90
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[24017]: NOQUEUE: reject: RCPT from unknown[ASSUMED_INTRUDER_IP]: 554 5.7.1 <REDACTED>: Relay access denied; from=<it@mail.libertyrising.de> to=<REDACTED> proto=ESMTP helo=<mail.libertyrising.de>
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: F25F91D91D0: from=<it@mail.libertyrising.de>, size=858057, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 4CBC91CBA1D: from=<it@mail.libertyrising.de>, size=858092, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[25231]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[23420]: NOQUEUE: reject: RCPT from unknown[ASSUMED_INTRUDER_IP]: 554 5.7.1 <REDACTED>: Relay access denied; from=<it@mail.libertyrising.de> to=<REDACTED> proto=ESMTP helo=<mail.libertyrising.de>
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtp[531]: Trusted TLS connection established to interaduaneira-com-br.mail.protection.outlook.com[104.47.58.110]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 04DD71C6774: from=<it@mail.libertyrising.de>, size=858019, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtpd[24017]: disconnect from unknown[ASSUMED_INTRUDER_IP] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 7CA131C8B16: from=<it@mail.libertyrising.de>, size=858022, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51380 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtp[500]: 1C3451D492E: host allfred-eu.mail.protection.outlook.com[104.47.11.202] said: 451 4.7.500 Server busy. Please try again later from [89.58.28.90]. (S77719) [AM0EUR02FT052.eop-EUR02.prod.protection.outlook.com 2023-07-24T12:36:53.978Z 08DB8BC57CF71EAE] (in reply to end of DATA command)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/smtp[570]: Trusted TLS connection established to sggw-edu-pl.mail.eo.outlook.com[104.47.51.202]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:53 1bfd159614a5 postfix/qmgr[377]: 0A54A1D1F53: from=<it@mail.libertyrising.de>, size=858047, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 whitelist_forwardinghosts: Look up ASSUMED_INTRUDER_IP on whitelist, result 200 DUNNO
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/postscreen[382]: PASS OLD [ASSUMED_INTRUDER_IP]:51380
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/smtpd[28309]: connect from unknown[ASSUMED_INTRUDER_IP]
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/qmgr[377]: D03D11DE239: from=<it@mail.libertyrising.de>, size=858047, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/smtpd[25219]: warning: Unable to look up MX host mail.ncplus.pl for Recipient address REDACTED: No address associated with hostname
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/smtpd[25219]: NOQUEUE: reject: RCPT from unknown[ASSUMED_INTRUDER_IP]: 554 5.7.1 <REDACTED>: Relay access denied; from=<it@mail.libertyrising.de> to=<REDACTED> proto=ESMTP helo=<mail.libertyrising.de>
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/qmgr[377]: 0540A1DBBDB: from=<it@mail.libertyrising.de>, size=857996, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/smtpd[25219]: disconnect from unknown[ASSUMED_INTRUDER_IP] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/postscreen[382]: CONNECT from [ASSUMED_INTRUDER_IP]:51381 to [172.22.1.253]:25
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/smtpd[23420]: disconnect from unknown[ASSUMED_INTRUDER_IP] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/qmgr[377]: 0CC511CBDD4: from=<it@mail.libertyrising.de>, size=858044, nrcpt=1 (queue active)
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/smtpd[25222]: NOQUEUE: reject: RCPT from unknown[ASSUMED_INTRUDER_IP]: 554 5.7.1 <REDACTED>: Relay access denied; from=<it@mail.libertyrising.de> to=<REDACTED> proto=ESMTP helo=<mail.libertyrising.de>
mailcowdockerized-postfix-mailcow-1 | Jul 24 14:36:54 1bfd159614a5 postfix/smtpd[23854]: Anonymous TLS connection established from unknown[ASSUMED_INTRUDER_IP]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)