Suddenly, starting yesterday, in the logwatch report, I am seeing loads and loads of failed attempts to log in on port 25. Port 25 is, of course, open to receive mail, but nobody should be using it to log in. And as far as I was aware, they haven’t been until yesterday.
This appears to be a new issue. Has sonething changed?
And the next day’s logwatch report had none. Even more puzzling.
There’s nothing worrying here - it’s just standard scanning from being on the internet.
Most spam now comes via compromised email accounts, so if you look across enough servers you’ll find this very common.
It’s not the incoming spam that concerns me. We seem to have mostly got spam tamed.
It’s that authenticated connections are being tried. Why was the server even allowing clients to try to authenticate on 25?
And why only the day before yesterday?