Linux & Security Guide
Incident Response
Contain compromised SMTP credentials and investigate activity.
This guide is designed as a production checklist. Test changes on a staging server and keep a working configuration backup.
Overview
Contain compromised SMTP credentials and investigate activity. The safest approach is to make one change at a time, validate syntax, reload the service, and then review logs and delivery results.
Configuration example
# Review listening services and recent authentication failures
ss -lntup
journalctl --since "1 hour ago"
grep -i "authentication failed" /var/log/maillog | tail -100Recommended procedure
- Document the current working configuration and relevant IP, DNS and authentication values.
- Confirm that every referenced file, key, hostname and source IP exists.
- Apply the smallest possible change and run the service configuration validator.
- Reload rather than restart when the software supports safe reloads.
- Watch logs, queue growth, SMTP responses and provider-specific behavior.
Common mistakes
- Copying a configuration from a different software release without checking directive support.
- Using a source IP without matching PTR, forward DNS and HELO identity.
- Changing multiple routing and throttling rules at once, making failures difficult to isolate.
- Ignoring envelope sender behavior, bounce handling and complaint suppression.
Verification
systemctl status postfix || systemctl status pmta
ss -lntp
tail -f /var/log/maillog
# Send a controlled test and inspect the complete received headers.Production notes
Delivery settings should be based on current response data, list quality and reputation. A value that works for one server or ISP can be unsafe for another. Prefer conservative defaults and measured increases.