[Mimedefang] sendmail processes remaining after message rejected

Michael D. Sofka sofkam at rpi.edu
Fri Aug 31 09:41:43 EDT 2007

I sent a version of this to the CanIt list last night....

The load on our smtp servers has gone way up the past few days.
There are now 250--300 sendmail processes running on each machine,
here normally there are fewer than 100 processes running.

Most of the processes are from connections that were rejected,
due to RBLs, or high spam score.  But, the sendmail processes
remain in "cmd read" mode.  I've firewalled a few of the more
aggressive IPs.

There was some discussion on the Mimedefang list about
completewhois going offline, and slowing down spamassassin.
I've removed the completewhois rules from spamassassin
yesterday, but this has not helped.

Since last night I noticed that we're running out of Mimedefang
slaves.  Not surprising if old sendmail connections are hanging
around, but I wonder if this could be a cause rather than an

Has anybody else seen this?  I remember something similar with a
Brazilian ISP a few years ago. (More than a few--it predated CanIt.)

There is more email traffic this week, from returning students
and classes starting.   But, not that much more traffic.

CanIt: 3.3.8, MimeDefang 2.62, ClamAV 0.91.1. Red Hat Enterprise 4,
Sendmail 8.13.1.

Michael D. Sofka
Sr. Systems Programmer, TeX, Email, Epistemology
Rensselaer Polytechnic Institute http://rpinfo.rpi.edu/~sofkam/

