Page 1 of 1

log of mail deletions

Posted: Thu Apr 09, 2015 10:20 pm
by jmackenz
Was just wondering if Plesk on Linux kept any logfile as to mailbox deletion of contents.


An imap client is missing some mail, I'm thinking he may have deleted it from his iphone, not sure if I have anything to tell me when/if this occurred.

Re: log of mail deletions

Posted: Fri Apr 10, 2015 6:10 am
by scott
If you had auditd enabled that may have logged a delete action. That would be in /var/log/audit/

Re: log of mail deletions

Posted: Fri Apr 10, 2015 6:24 am
by jmackenz
no such luck, empty folder

Re: log of mail deletions

Posted: Fri Apr 10, 2015 9:33 am
by scott
Not much else logged then, at most you'll get a successful login record from the imap server, but nothing about what the user did. Any chance the user had multiple devices connecting to the account?

Re: log of mail deletions

Posted: Fri Apr 10, 2015 11:59 am
by jmackenz
At least outlook 2010 and an iphone, maybe another device too.

Many folders, folders exist, contents gone. No archive file or deleted items to be found.

Was able to restore, but still... I'd like to know why they went to begin with.

This auditd, how does it work to give me more info in future. (googling now)

Re: log of mail deletions

Posted: Fri Apr 10, 2015 12:37 pm
by scott
So an observation Ive had here, the iphone clients (and many others) default to using POP. If that is the case (and it will be logged as a POP connection) then what could be happening is that the mail is being downloaded to the specific phone, which is going to delete the message off the server unless it is configured not to.

Re: log of mail deletions

Posted: Fri Apr 10, 2015 12:39 pm
by jmackenz
If he has another device, that may be possible, but the iphone I'm aware of is definitely set to imap.