Ive recently switched to using tcpserver to help with selective relaying
for my mail server...  Ive noticed that i am getting LOTS of entries like
the following in my message log... im not exactly sure what is going on
here.... i am chaos.sodatrian.com, and know nothing about mail.chsj23.org
other that it belongs to Cathedral High School in St. Cloud...

Did i miss something, and am i an open relay? I dont believe so... is
someone spoofing this addr, and abusing my mail server under my eyes and i
dont realize it?  or am i (chaos) trying to connect to mail.chsj23.org...

sorry for the ignorance, i dont really have a clue about tcpserver.

thx



Jun  3 17:22:52 chaos smtpd: 991603372.893650 tcpserver: status: 0/40
Jun  3 17:22:56 chaos smtpd: 991603376.508229 tcpserver: status: 1/40
Jun  3 17:22:56 chaos smtpd: 991603376.509026 tcpserver: pid 14690 from
204.221.246.57
Jun  3 17:22:56 chaos smtpd: 991603376.587363 tcpserver: ok 14690
chaos.sodatrain.com:209.251.64.127:25 mail.chsj23.org:204.221.246.57::3264
Jun  3 17:22:58 chaos smtpd: 991603378.906917 tcpserver: status: 2/40


[root at chaos log]# grep chsj23.org /var/log/messages | wc
   4115   45265  579601

This is from June 3rd, untill now.

I added this into my hosts.deny a few days ago...

ALL: mail.chsj23.org





-- 
||  ||  ||  ||  ||  ||
duncan shannon
duncan at sodatrain.com