xinetd[#]: Deactivating service smtp due to excessive incoming connections. Restarting in 30 seconds.

This happened to a Plesk 8.x Linux (RH) server, the problem was that smtp service was up and running, and the queue was very light , but smtp wouldn’t accept any connections at port 25 even from localhost.

In the /var/log/messages I saw this disturbing message:
xinetd[#]: Deactivating service smtp due to excessive incoming connections. Restarting in 30 seconds.


I did check the connections (`netstat -an |grep :25 |wc -l) and the number was nothing important..like 20 which is never so much trouble for qmail.

After checking real-time the mail log file (tail -f /usr/local/psa/var/log/maillog)

Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:4642 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1399 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1397 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1398 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1400 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:4594 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1401 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1403 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:4640 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1404 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1405 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1409 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1410 (www.domain.tld)
Nov 15 10:54:42 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1416 (www.domain.tld)
Nov 15 10:54:43 server relaylock: /var/qmail/bin/relaylock: mail from 218.59.175.220:1411 (www.domain.tld)

Ofcourse this ip was blacklisted in many different antispam lists, and the problem was that it was sending spam to domains hosted in our server and not through it.Blacklisting through the firewall the ip (and several others I’ve found sovled the problem right away.