Hi, im getting this every minute in the mail server plugin's log

Nov 22 14:24:05 server postfix/smtpd[9855]: connect from unknown[92.118.38.55]
Nov 22 14:24:19 server postfix/smtpd[9855]: warning: unknown[92.118.38.55]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Nov 22 14:24:19 server postfix/smtpd[9855]: disconnect from unknown[92.118.38.55] ehlo=1 auth=0/1 rset=1 quit=1 commands=3/4
Nov 22 14:24:40 server postfix/smtpd[6004]: warning: hostname ip-38-55.ZervDNS does not resolve to address 92.118.38.55: Name or service not known

Is it dangerous? is there a way to blacklist the ip so they stop sniffing aroung? right now i see 2 IPs doing this.

Thanks πŸ™‚

    aaPanel_Jose mmm nevermind, they stoped last night, but today they are still spamming the mail server, the IP is even in the black list yet they are able to spam, and yes, fail2ban is active πŸ™

      LCDraws
      If it is a long connection, even if fail2ban has added the ip to the blacklist, the request can continue.
      Like you have already logged into the ssh terminal even if you set the firewall to block your ip connection 22 port, but you have already connected ssh can continue to use