I noticed that Intrusion detection is sending emails when an IP gets banned from root@hostname instead of using the From email specified under Admin > System Settings > System Misc > Notifications or Admin > System Settings > Email Settings
Seems like this issue is back in the latest version.
Here’s a raw email that was blocked by our SMTP gateway due to it using a wrong from address.
Received: from pbx1.domain.local (unknown [123.456.7.89])
by p-pm-outbound04c-aws-useast1c.smtpservice.com (Postfix) with ESMTPA id 12D94405B4F
for <email-to@domain.com>; Tue, 10 May 2022 07:22:06 +0000 (UTC)
Received: by pbx1.domain.local (Postfix, from userid 0)
id 5AB06841C25; Tue, 10 May 2022 03:17:04 -0400 (EDT)
Subject: [Fail2Ban] apache-forbidden: started on pbx1.domain.local
Date: Tue, 10 May 2022 03:17:04 -0400
From: Fail2Ban <root@pbx1.domain.local>
To: email-to@domain.com
Message-Id: <20220510071704.5AB06841C25@pbx1.domain.local>
Hi,
The jail apache-forbidden has been started successfully.
Regards,
Fail2Ban