仍在尝试设置(安装和安全)我的第一台服务器,今天我在我的 mail.warn 日志文件中发现了几行奇怪的行。
Sep 8 17:41:48 jvps postfix/smtpd[7793]: warning: hostname worker-13.sfj.censys-scanner.com does not resolve to address 192.35.168.218
Sep 8 18:44:10 jvps postfix/smtpd[9990]: warning: hostname zg-0823b-129.stretchoid.com does not resolve to address 192.241.231.159
Sep 8 23:14:54 jvps postfix/submission/smtpd[19438]: warning: hostname zg-0823a-56.stretchoid.com does not resolve to address 192.241.219.247
Sep 9 16:26:00 jvps postfix/smtpd[26250]: warning: hostname 26.189.237.221.broad.cd.sc.dynamic.163data.com.cn does not resolve to address 221.237.189.26
Sep 9 16:26:01 jvps postfix/smtpd[26250]: warning: hostname 26.189.237.221.broad.cd.sc.dynamic.163data.com.cn does not resolve to address 221.237.189.26
Sep 9 19:45:53 jvps postfix/smtpd[1008]: warning: hostname zg-0823a-256.stretchoid.com does not resolve to address 192.241.225.64
Sep 9 23:15:33 jvps postfix/submission/smtpd[8430]: warning: hostname zg-0823b-193.stretchoid.com does not resolve to address 192.241.234.225
Sep 10 10:10:33 jvps postfix/smtpd[1332]: warning: hostname hn.ly.kd.adsl does not resolve to address 61.163.192.88
Sep 10 10:10:34 jvps postfix/smtpd[1332]: warning: hostname hn.ly.kd.adsl does not resolve to address 61.163.192.88
Sep 10 15:09:48 jvps postfix/smtpd[11980]: warning: hostname worker-15.sfj.censys-scanner.com does not resolve to address 192.35.168.250
Sep 10 19:48:41 jvps postfix/smtpd[21725]: warning: hostname zg-0823b-181.stretchoid.com does not resolve to address 192.241.234.120
Sep 10 20:55:58 jvps postfix/submission/smtpd[24052]: warning: hostname zg-0823a-206.stretchoid.com does not resolve to address 192.241.224.91
有人能解释一下这是什么吗?我不知道这些主机名或 IP,我有点迷茫
答案1
这些主机连接到您的邮件服务器并通过主机名标识自己,但该主机名在 DNS 中没有与其连接的 IP 地址匹配的地址记录。其中绝大多数是垃圾邮件来源,不过您帖子中的其中一个是数据收集机器人在极少数情况下,这是某人的合法但配置错误的邮件服务器;他们通常会很快修复它,因为几乎所有人都会拒绝他们的邮件或将其标记为垃圾邮件。
它们看起来完全脱离上下文的原因在于 Debian 的众多值得怀疑的设计决策之一:他们选择按日志级别分离邮件日志。因此,与这些连接相关的其余日志位于其他文件中。Debian 创建了mail.info
和,每个文件都包含这些日志级别的日志条目。幸运的是,他们还创建了mail.warn
,它是完整的,包含所有日志条目。您可以在此日志中搜索类似的日志条目并查看周围的上下文。您还应该能够从 systemd 日志中获取完整的日志。mail.err
mail.log