What’s your OS version?
Show only the output of this command:
exiqgrep -i
What’s your OS version?
Show only the output of this command:
exiqgrep -i
Ubuntu 24.04.3 LTS (GNU/Linux 6.8.0-84-generic x86_64)
Last login: Tue Sep 30 16:10:02 2025 from 66.220.203.0
root@server:~# exiqgrep -i
Exim message queue display utility.
-h This help message.
-C Specify which exim.conf to use.
-E Specify exim binary to use.
Selection criteria:
-f <regexp> Match sender address sender (field is "< >" wrapped)
-r <regexp> Match recipient address
-s <regexp> Match against the size field from long output
-y <seconds> Message younger than
-o <seconds> Message older than
-z Frozen messages only (exclude non-frozen)
-x Non-frozen messages only (exclude frozen)
-G <queuename> Match in given queue only
[ NB: for regexps, provided string sits in /<string>/ ]
Display options:
-c Display match count
-l Long Format [Default]
-i Message IDs only
-b Brief Format
-R Reverse order
-a All recipients (including delivered)
root@server:
Ok, now:
exim -bp | exiqgrep -i
Last login: Tue Sep 30 16:19:08 2025 from 66.220.203.0
root@server:~# exim -bp | exiqgrep -i
Exim message queue display utility.
-h This help message.
-C Specify which exim.conf to use.
-E Specify exim binary to use.
Selection criteria:
-f <regexp> Match sender address sender (field is "< >" wrapped)
-r <regexp> Match recipient address
-s <regexp> Match against the size field from long output
-y <seconds> Message younger than
-o <seconds> Message older than
-z Frozen messages only (exclude non-frozen)
-x Non-frozen messages only (exclude frozen)
-G <queuename> Match in given queue only
[ NB: for regexps, provided string sits in /<string>/ ]
Display options:
-c Display match count
-l Long Format [Default]
-i Message IDs only
-b Brief Format
-R Reverse order
-a All recipients (including delivered)
root@server:~#
Use this:
exim -bp | exiqgrep -i -o 60 | xargs exim -Mrm
root@server:~# exim -bp | exiqgrep -i -o 60 | xargs exim -Mrm
Message 1v2KWg-00000009oUF-06uw has been removed
Message 1v2ZnW-0000000CaDW-3agr has been removed
Message 1v2iHU-0000000EAm0-2JfZ has been removed
Message 1v2qXL-0000000G1S4-2Y5V has been removed
Message 1v2sFG-0000000GQSh-2rQy has been removed
Message 1v2yfJ-00000000Nxp-2Dwi has been removed
Message 1v3EmR-00000004L55-48IA has been removed
Message 1v3L2d-00000005v79-3fAT has been removed
Message 1v3MQT-00000006CqF-1NOT has been removed
Message 1v3Oql-00000006vYN-0wtk has been removed
Message 1v3Zki-00000009isf-0JOk has been removed
Message 1v3aDc-00000009skz-1QF0 has been removed
Message 1v3czM-0000000AgB5-2EPt has been removed
root@server:~#
yes all delete TH..YOU VERY MUCH!
root@server:~# exim -bp
root@server:~#
today I get 100 emails from all users, no idea, can’t lost time, reinstall VPS and hestiaCP.
Fortunately, those IPs are already listed in multiple blocklist. But yes, they are on fire, I’ve had hundreds of attacks from that range in the last few days.
True, I cross checked just now, and they are own my own list too.
FYI: I have my own 4 & 6 blocklist as well. So apart from the other abuseip range lists, I use my own too, which I manually update, literally daily. Reverse IP as well, domain and email blacklist.
32825 including wildcard domains; 1091 email blocklist; 10980 IPV4 & 554 IPV6 blocked as of date.
![]()
it’s a virus, no idea how it’s come, no change anything 1 years. crazy
Hi guys, I just having kind of similar issue this las few days, getting this email that says I tried to send an email to this address: [email protected] but I never did that, have I been hacked?
| From | Mail Delivery System |
|---|---|
| To | [email protected] |
| undefined | ---- |
| Date | dom 22:07 |
| undefined | ---- |
This message was created automatically by mail delivery software.
A message that you sent has not yet been delivered to one or more of its
recipients after more than 48 hours on the queue on server01.luis-fonseca.net.
The message identifier is: 1vCVLn-00GGZ8-1j
The subject of the message is: =?UTF-8?B?dG5wd2xhcGZiZnZsanNv?=
The date of the message is: Sat, 25 Oct 2025 03:53:55 +0000
The address to which the message has not yet been delivered is:
[email protected]
host cuoly.com [82.192.82.228]
No action is required on your part. Delivery attempts will continue for
some time, and this warning may be repeated at intervals if the message
remains undelivered. Eventually the mail delivery software will give up,
and when that happens, the message will be returned to you.
Reporting-MTA: dns; server01.luis-fonseca.net
Action: delayed
Final-Recipient: rfc822;[email protected]
Status: 4.0.0
Remote-MTA: dns; cuoly.com
Return-path: <[email protected]>
Received: from [181.115.171.223] (helo=DESKTOP-EJKNAKK)
by server01.luis-fonseca.net with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
(Exim 4.96)
(envelope-from <[email protected]>)
id 1vCVLn-00GGZ8-1j
for [email protected];
Sat, 25 Oct 2025 03:53:58 +0000
From: [email protected]
Reply-To: [email protected]
To: [email protected]
Subject: =?UTF-8?B?dG5wd2xhcGZiZnZsanNv?=
Content-Type: multipart/alternative; boundary=“EecqQSKgHBzgz2YNnNgeFmiCv45Eg7rm”
Message-Id: <[email protected]>
Date: Sat, 25 Oct 2025 03:53:55 +0000
and on headers section I have this value:
Return-path: <>
Envelope-to: [email protected]
Delivery-date: Mon, 27 Oct 2025 04:07:00 +0000
Received: from Debian-exim by server01.luis-fonseca.net with local (Exim 4.96)
id 1vDEVY-0002mB-12
for [email protected];
Mon, 27 Oct 2025 04:07:00 +0000
Auto-Submitted: auto-replied
From: Mail Delivery System [email protected]
To: [email protected]
References: [email protected]
Content-Type: multipart/report; report-type=delivery-status; boundary=1761538020-eximdsn-1765517790
MIME-Version: 1.0
Subject: Warning: message 1vCVLn-00GGZ8-1j delayed 48 hours
Message-Id: [email protected]
Date: Mon, 27 Oct 2025 04:07:00 +0000
Do you have an auto reply on [email protected]?
Hi @Raphael , no auto replies are set.
I don’t think so.
Looks like some spammer is spoofing your email address and you’re receiving the bounce messages. It’s a pain, but I don’t think you should worry too much.
I would edit your _dmarc DNS record and replace p=quarantine with p=reject.
Hi guys, this days I keep having issues with Mail Delivery, at the point that yesterday at night on my location my thunderbird at phone told me can’t login to my mail, then I tried to login through web on roundcube and my other emails on my domain works, but this [email protected] no, I have reset password already and can login again, theere was a bunch of mail deliveries system messages there, but the interesting thing was that THERE WAS A EMAIL on SENT box that I never submitted ![]()
Headers says:
MIME-Version: 1.0
Date: Fri, 27 Mar 2026 20:08:07 -0700
From: [email protected]
To: undisclosed-recipients:;
Bcc: [email protected], [email protected],
[email protected], [email protected],
[email protected], [email protected], [email protected]
Subject: Attn: Email ID Owner
Reply-To: [email protected]
Mail-Reply-To: [email protected]
Message-ID: [email protected]
X-Sender: [email protected]
Content-Type: multipart/alternative;
boundary=“=_61bd9a528c99b2c34b8b44fed38d375b”
Checking with Gemini to check how to filter logs I found this ones:
zgrep “[email protected]” /var/log/exim4/mainlog* | grep “P=esmtpsa”
/var/log/exim4/mainlog.2.gz:2026-03-27 20:11:56 1w6DX9-00399a-1Z <= [email protected] H=(8OlVAHqbQ2) [102.217.4.180] P=esmtpsa X=TLS1.2:ECDHE_SECP256R1__RSA_SHA512__AES_128_GCM:128 CV=no A=dovecot_login:[email protected] S=768 [email protected]
/var/log/exim4/mainlog.2.gz:2026-03-27 20:44:14 1w6E2P-0039z8-1j <= [email protected] H=(WIN-BGU86CDI74S) [155.117.189.117] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=837 id=8LJ6H7AWUSU4.VYS0RWM07RY12@win-bgu86cdi74s
/var/log/exim4/mainlog.2.gz:2026-03-27 20:50:33 1w6E8W-003ACZ-2C <= [email protected] H=(freshtools.is) [185.66.142.48] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_login:[email protected] S=635 [email protected]
/var/log/exim4/mainlog.2.gz:2026-03-27 20:54:57 1w6ECm-003ADc-1q <= [email protected] H=(DESKTOP-QFL84PA.arnhem.chello.nl) [128.90.135.55] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=1134
/var/log/exim4/mainlog.2.gz:2026-03-27 20:55:21 1w6EDB-003AJl-06 <= [email protected] H=(WIN-BGU86CDI74S) [143.0.119.136] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=835 id=02CZU9DWUSU4.NZXTRD1PQBQ32@win-bgu86cdi74s
/var/log/exim4/mainlog.2.gz:2026-03-27 21:11:46 1w6ET3-003AiA-1g <= [email protected] H=([91.219.238.105]) [91.219.238.105] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=1128
/var/log/exim4/mainlog.2.gz:2026-03-27 21:11:46 1w6ET4-003AiB-1l <= [email protected] H=([91.219.238.105]) [91.219.238.105] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=1128
/var/log/exim4/mainlog.2.gz:2026-03-27 21:11:54 1w6ETC-003AiJ-02 <= [email protected] H=ns3160686.ip-51-91-240.eu (localhost.localdomain) [51.91.240.93] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_login:[email protected] S=1064 id=TB75fMpIxrCZG0wYBrqfM2LDki4qGZNW2HFJW3dbZfg@localhost.localdomain
/var/log/exim4/mainlog.2.gz:2026-03-27 21:16:54 1w6EY1-003Atb-1u <= [email protected] H=([127.0.1.1]) [187.64.19.125] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=936
/var/log/exim4/mainlog.2.gz:2026-03-27 21:41:40 1w6Ew0-003BXW-0k <= [email protected] H=([192.168.1.30]) [23.154.80.77] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=682
/var/log/exim4/mainlog.2.gz:2026-03-27 22:20:18 1w6FXM-003CZF-2B <= [email protected] H=([192.168.11.105]) [196.117.243.113] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=761
/var/log/exim4/mainlog.2.gz:2026-03-27 22:57:56 1w6G7n-003DQp-1c <= [email protected] H=(DESKTOP-QFL84PA.arnhem.chello.nl) [128.90.145.247] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=1183
/var/log/exim4/mainlog.2.gz:2026-03-27 23:26:45 1w6GZf-003E7h-0P <= [email protected] H=([10.64.21.61]) [41.216.176.1] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=860
/var/log/exim4/mainlog.2.gz:2026-03-27 23:51:14 1w6GxM-003EqY-1y <= [email protected] H=(DESKTOP-QFL84PA.arnhem.chello.nl) [128.90.145.75] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no SNI=mail.luis-fonseca.net A=dovecot_plain:[email protected] S=1193
/var/log/exim4/mainlog.3.gz:2026-03-26 00:19:20 1w5YRR-001wsO-0m <= [email protected] H=dynamic-176-002-105-196.176.2.pool.telefonica.de (170.168.247.169) [176.2.105.196] P=esmtpsa X=TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_128_GCM:128 CV=no A=dovecot_login:[email protected] S=4174 [email protected]
/var/log/exim4/mainlog.3.gz:2026-03-26 12:13:56 1w5jb1-002HOu-2k <= [email protected] H=(Q3OS5) [45.235.9.12] P=esmtpsa X=TLS1.2:ECDHE_SECP256R1__RSA_SHA512__AES_128_GCM:128 CV=no A=dovecot_plain:[email protected] S=988
/var/log/exim4/mainlog.4.gz:2026-03-25 09:38:39 1w5KhA-001YY3-1m <= [email protected] H=(UJZECE2W) [171.255.57.162] P=esmtpsa X=TLS1.2:ECDHE_SECP256R1__RSA_SHA512__AES_128_GCM:128 CV=no A=dovecot_plain:[email protected] S=978
/var/log/exim4/mainlog.6.gz:2026-03-23 18:49:32 1w4kLC-000SHj-0H <= [email protected] H=(UJZECE2W) [171.232.102.33] P=esmtpsa X=TLS1.2:ECDHE_SECP256R1__RSA_SHA512__AES_128_GCM:128 CV=no A=dovecot_plain:[email protected] S=976
/var/log/exim4/mainlog.8.gz:2026-03-21 10:40:17 1w3tke-004HDv-08 <= [email protected] H=32.18.23.93.rev.sfr.net (UJZECE2W) [93.23.18.32] P=esmtpsa X=TLS1.2:ECDHE_SECP256R1__RSA_SHA512__AES_128_GCM:128 CV=no A=dovecot_plain:[email protected] S=1033
/var/log/exim4/mainlog.9.gz:2026-03-20 11:06:07 1w3Xg2-003ckV-2c <= [email protected] H=(UJZECE2W) [120.56.12.72] P=esmtpsa X=TLS1.2:ECDHE_SECP256R1__RSA_SHA512__AES_128_GCM:128 CV=no A=dovecot_plain:[email protected] S=1009
I also run this:
zgrep “Login: user=[email protected]” /var/log/dovecot.log*
/var/log/dovecot.log.1:Mar 27 07:29:10 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=72.207.33.64, lip=191.101.1.90, mpid=672280, session=<ZIH8dPxNquVIzyFA>
/var/log/dovecot.log.1:Mar 27 07:59:40 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=35.151.30.125, lip=191.101.1.90, mpid=675088, TLS, session=<uIEa4vxNOjwjlx59>
/var/log/dovecot.log.1:Mar 27 08:25:09 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=175.42.64.81, lip=191.101.1.90, mpid=678124, session=<QZs3Pf1N6aKvKkBR>
/var/log/dovecot.log.1:Mar 27 09:00:56 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=185.94.164.27, lip=191.101.1.90, mpid=681491, TLS, session=<iDMtvf1NFLq5XqQb>
/var/log/dovecot.log.1:Mar 27 11:58:20 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=201.191.50.141, lip=191.101.1.90, mpid=698634, TLS, session=<m72jNwBO3I/JvzKN>
/var/log/dovecot.log.1:Mar 27 11:58:37 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=201.191.50.141, lip=191.101.1.90, mpid=698642, TLS, session=<D8SlOABOIqfJvzKN>
/var/log/dovecot.log.1:Mar 27 12:28:04 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=73.209.155.226, lip=191.101.1.90, mpid=702136, TLS, session=<3g/8oQBOaKhJ0Zvi>
/var/log/dovecot.log.1:Mar 27 13:23:57 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=194.110.207.211, lip=191.101.1.90, mpid=707568, TLS, session=<0UzPaQFOifTCbs/T>
/var/log/dovecot.log.1:Mar 27 14:04:44 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=144.172.115.208, lip=191.101.1.90, mpid=711285, TLS, session=<Ftum+wFOXLGQrHPQ>
/var/log/dovecot.log.1:Mar 27 14:18:16 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=148.135.120.177, lip=191.101.1.90, mpid=712984, TLS, session=<CPMXLAJOSMmUh3ix>
/var/log/dovecot.log.1:Mar 27 16:25:32 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=81.219.156.136, lip=191.101.1.90, mpid=725787, TLS, session=<+p848wNOEvFR25yI>
/var/log/dovecot.log.1:Mar 27 16:25:36 imap-login: Info: Login: user=<[email protected]>, method=PLAIN, rip=38.240.56.179, lip=191.101.1.90, mpid=725795, TLS, session=<SuB48wNOyMMm8Diz>
Not sure if this helps, or more logs are needed to check ? I just copy part of them , I have notice couple of the IP listed on some of the logs are currently banned on Fail2ban
Hi,
It’s clear to me that your email account has been compromised. There have been multiple successful logins from different IP addresses across various countries, and emails are being sent from it.
4 Hungary
3 Brazil
2 Viet Nam
2 United States of America
2 Netherlands (Kingdom of the)
2 France
2 Belgium
1 Portugal
1 Morocco
1 Kenya
1 India
1 Germany
1 Canada
1 Austria
You have already changed the password (I hope to a new one). If other user or email accounts are using the same compromised password, you should change them as well.
I would also check whether Exim has queued mails from that user.
I’ve checked your IP address, and at this time it is not listed on any of the blocklists I use. It also does not appear in the blocklists checked via MXToolbox, nor is it listed by Spamhaus.
After you changed the password, did you see more logins to that account?
Hi my friend @sahsanu , so I have used this command and I have deleted 2 emails on queue, I have also changed all email passwords and actually I will change them once again, let me check new logs to see logins, I guess only this email was compromised, but I guess not the server?