Uit het log wordt ik ook niet veel wijzer. Hierin is GedeeldeData de naam van mijn nas, "xxx.i234.me" is mijn DDNS naam (Waar mijn eigen domeinnaam en het MX-record naar toe verwijzen) en "217.121.xxx.xxx" is mijn IP adres. De xxx heb ik zelf toegevoegd.
Jun 26 23:12:34 GedeeldeData postfix/smtpd[22167]: connect from unknown[192.69.1.114]
Jun 26 23:12:34 GedeeldeData postfix/smtpd[22170]: connect from unknown[192.69.1.114]
Jun 26 23:12:34 GedeeldeData postfix/smtpd[22167]: SSL_accept error from unknown[192.69.1.114]: lost connection
Jun 26 23:12:34 GedeeldeData postfix/smtpd[22167]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:12:34 GedeeldeData postfix/smtpd[22167]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:12:34 GedeeldeData postfix/smtpd[22170]: Anonymous TLS connection established from unknown[192.69.1.114]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22170]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22170]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22177]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22177]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22187]: connect from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22187]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22187]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22187]: connect from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22187]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:12:35 GedeeldeData postfix/smtpd[22187]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22187]: connect from unknown[192.69.1.114]
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22187]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22187]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22187]: connect from unknown[192.69.1.114]
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22187]: lost connection after HELO from unknown[192.69.1.114]
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22187]: disconnect from unknown[192.69.1.114] helo=1 mail=0/1 rset=0/1 commands=1/3
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22177]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:12:36 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:12:37 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:12:37 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@emailsecuritygrader.com> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:38 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@emailsecuritygrader.com> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:38 GedeeldeData postfix/smtpd: SYSTEM: Last message 'NOQUEUE: reject: RCP' repeated 1 times, suppressed by syslog-ng on GedeeldeData
Jun 26 23:12:38 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:38 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:38 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@localhost> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:39 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<postmaster@xxx.i234.me> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:39 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:39 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient%emailsecuritygrader.com@[217.121.xxx.xxx]>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient%emailsecuritygrader.com@[217.121.xxx.xxx]> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:39 GedeeldeData postfix/trivial-rewrite[22211]: warning: valid_ipv4_hostaddr: invalid character 104(decimal): xxx.i234.me
Jun 26 23:12:39 GedeeldeData postfix/smtpd[22177]: warning: Illegal address syntax from unknown[192.69.1.114] in RCPT command: <testRecipient%emailsecuritygrader.com@[xxx.i234.me]>
Jun 26 23:12:40 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:42 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient%emailsecuritygrader.com>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient%emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:45 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:49 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com@[217.121.xxx.xxx]>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient@emailsecuritygrader.com@[217.121.xxx.xxx]> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:52 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:55 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:12:58 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient@emailsecuritygrader.com>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient@emailsecuritygrader.com> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:13:02 GedeeldeData postfix/smtpd: SYSTEM: Last message 'NOQUEUE: reject: RCP' repeated 2 times, suppressed by syslog-ng on GedeeldeData
Jun 26 23:13:02 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <emailsecuritygrader.com!testRecipient>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<emailsecuritygrader.com!testRecipient> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:13:05 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <emailsecuritygrader.com!testRecipient@[217.121.xxx.xxx]>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<emailsecuritygrader.com!testRecipient@[217.121.xxx.xxx]> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:13:08 GedeeldeData postfix/trivial-rewrite[22211]: warning: valid_ipv4_hostaddr: invalid character 104(decimal): xxx.i234.me
Jun 26 23:13:08 GedeeldeData postfix/smtpd[22177]: warning: Illegal address syntax from unknown[192.69.1.114] in RCPT command: <emailsecuritygrader.com!testRecipient@[xxx.i234.me]>
Jun 26 23:13:12 GedeeldeData postfix/smtpd[22177]: NOQUEUE: reject: RCPT from unknown[192.69.1.114]: 554 5.7.1 <testRecipient%emailsecuritygrader.com@>: Relay access denied; from=<testRelay@[217.121.xxx.xxx]> to=<testRecipient%emailsecuritygrader.com@> proto=SMTP helo=<emailsecuritygrader.com>
Jun 26 23:13:14 GedeeldeData postfix/smtpd[22177]: too many errors after RCPT from unknown[192.69.1.114]
Jun 26 23:13:14 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] helo=1 mail=20 rcpt=0/20 rset=20 commands=41/61
Jun 26 23:13:14 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:13:14 GedeeldeData postfix/smtpd[22177]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:13:14 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:13:14 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:13:14 GedeeldeData postfix/smtpd[22177]: lost connection after MAIL from unknown[192.69.1.114]
Jun 26 23:13:14 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] helo=1 mail=1 commands=2
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22177]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22177]: lost connection after EHLO from unknown[192.69.1.114]
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] ehlo=1 commands=1
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22167]: connect from unknown[192.69.1.114]
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22167]: SSL_accept error from unknown[192.69.1.114]: lost connection
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22167]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22167]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22170]: connect from unknown[192.69.1.114]
Jun 26 23:13:20 GedeeldeData postfix/smtpd[22170]: Anonymous TLS connection established from unknown[192.69.1.114]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
Jun 26 23:13:21 GedeeldeData postfix/smtpd[22170]: lost connection after EHLO from unknown[192.69.1.114]
Jun 26 23:13:21 GedeeldeData postfix/smtpd[22170]: disconnect from unknown[192.69.1.114] ehlo=1 commands=1
Jun 26 23:13:21 GedeeldeData postfix/smtpd[22177]: connect from unknown[192.69.1.114]
Jun 26 23:13:21 GedeeldeData postfix/smtpd[22177]: lost connection after CONNECT from unknown[192.69.1.114]
Jun 26 23:13:21 GedeeldeData postfix/smtpd[22177]: disconnect from unknown[192.69.1.114] commands=0/0
Jun 26 23:16:41 GedeeldeData postfix/anvil[22173]: statistics: max connection rate 9/60s for (25:192.69.1.114) at Jun 26 23:13:21
Jun 26 23:16:41 GedeeldeData postfix/anvil[22173]: statistics: max connection count 1 for (465:192.69.1.114) at Jun 26 23:12:34
Jun 26 23:16:41 GedeeldeData postfix/anvil[22173]: statistics: max cache size 3 at Jun 26 23:12:35
Vreemd genoeg kom ik mijn eigen domeinnaam of e-mail adres niet tegen in het log.
Verder is hun IP:192.69.1.114, ondanks al dit testen, niet op de blokkeringslijst gekomen. Ze hebben dus niet geprobeerd met een standaard WW in te loggen.