Articles in this section

Emails are automatically forwarded to an unknown address in Plesk

Plesk for Linux kb: technical

Applicable to:

  • Plesk for Linux

Symptoms

  • All mail from a Plesk email address is forwarded to an unknown email address, with these records logged to /var/log/maillog:

    dovecot service=lda, user=john.doe@example.com, ip=[]. sieve: msgid=618dad9e22271@example.com: redirect action: forwarded to unknown@example.com

  • Custom forwarding rules exist in Roundcube at Settings > Filters

Cause

The account has been compromised, and malicious rules have been created in Roundcube.

Resolution

Secure the account and remove the forwarding rules:

  1. Set a stronger password for the affected account.
  2. Log in to webmail of the affected mailbox
  3. Go to Settings > Filters and remove the malicious forwarding rule(s).

Note: To help prevent such thing to occur again, secure Plesk server.

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.