Windows Thread, Spam spam spam... in Technical; One of my colleagues is getting lots of mail like the following:
From: System Administrator
Sent: 31 March 2008 10:01
...
-
7th April 2008, 09:09 AM #1 Spam spam spam...
One of my colleagues is getting lots of mail like the following:
From: System Administrator
Sent: 31 March 2008 10:01
To: <colleague>
Subject: Undeliverable: {Spam?} Упрощенная система налогообложения в 2008 г.
Your message did not reach some or all of the intended recipients.
Subject: {Spam?} Упрощенная система налогообложения в 2008 г.
Sent: 31/03/2008 08:12
The following recipient(s) could not be reached:
foo@pgpi.ru on 31/03/2008 10:04
The e-mail account does not exist at the organization this message was sent to. Check the e-mail address, or contact the recipient directly to find out the correct address.
<mail-pgpi.pgpi.local #5.1.1>
From: System Administrator
Sent: 31 March 2008 12:01
To: <colleague>
Subject: Undeliverable: *****SPAM***** Hermes
Your message did not reach some or all of the intended recipients.
Subject: *****SPAM***** Hermes
Sent: 01/04/2008 05:19
The following recipient(s) could not be reached:
gerichdd@neoperl.com on 31/03/2008 11:58
The e-mail system was unable to deliver the message, but did not report a specific reason. Check the address and try again. If it still fails, contact your system administrator.
< mail1.nrgnetworks.com #5.0.0 smtp; 550 unknown user <gerichdd@neoperl.com>>
It obviously looks like it's being bounced back to here. Is it likely her machine is zombified, or is it just speculative spam? It's coming from all over the place.
Bottom line, how do i stop it?
She's getting about 30 per day atm.
-
-
IDG Tech News
-
7th April 2008, 09:18 AM #2 Those messages do look like bounce backs... her machine isn't being used as a relay is it?
Get the AV and AS tools out!
-
-
7th April 2008, 09:44 AM #3 Sometimes the domain or address is used, I've had over 4000 bounced back in a single day before, and it certainly wasn't a compromised machine.
-
-
7th April 2008, 09:44 AM #4 AV came back clean (McAfee 8.5). I'll try a SpyBot search today methinks.
Is there a way to check Exchange to see if her account is indeed sending out those emails initially?
-
-
7th April 2008, 09:46 AM #5 @Ryan: You can use message tracking to see what mail has been sent from her account.
-
-
7th April 2008, 11:18 AM #6 I've turned on message tracking to see if that yields anything. Thanks Ric
@DMcCoy - how did you resolve that? Or did you?
-
-
7th April 2008, 11:30 AM #7 
Originally Posted by
Ryan
@DMcCoy - how did you resolve that? Or did you?
There is nothing you can do if a spammer spoofs email to come from your domain. You just need to control the NDR messages really.
-
-
7th April 2008, 11:56 AM #8 
Originally Posted by
ZeroHour
You just need to control the NDR messages really.
Go on...
-
-
7th April 2008, 12:25 PM #9 
Originally Posted by
ZeroHour
There is nothing you can do if a spammer spoofs email to come from your domain.
You could implement SPF.
SPF: Project Overview
-
-
7th April 2008, 12:30 PM #10 @Geoff: SPF is still considered fairly toothless. Not many truely use it to weight against a server. I have used SPF in the past and even when I break the SPF (so it read "fail" in the header) the email still does not get filtered.
@Ryan: there is not much you can do to block NDR's as you still need them for real NDR. Just educate the staff saying if you receive a bounce and didnt send anything, ignore it generally.
-
-
7th April 2008, 12:44 PM #11 Hmm. It may be time to bite the bullet and give her an alternate email address then. Cheers lads.
-
-
7th April 2008, 02:03 PM #12 
Originally Posted by
ZeroHour
@Geoff: SPF is still considered fairly toothless. Not many truely use it to weight against a server. I have used SPF in the past and even when I break the SPF (so it read "fail" in the header) the email still does not get filtered.
I do, because I have an up to date Spam Assassin installation. It will factor in SPF information in it's 'spaminess' score. While I agree SPF isn't the perfect solution, it's one of the best ones on the table at the moment. So unless you can come up with a better idea, what's the problem with implementing it. Even if it doesn't get rid of all the spam, it'll cut down on a percentage.
-
-
8th April 2008, 01:47 PM #13
- Rep Power
- 14

Originally Posted by
ZeroHour
@Geoff: SPF is still considered fairly toothless. Not many truely use it to weight against a server. I have used SPF in the past and even when I break the SPF (so it read "fail" in the header) the email still does not get filtered.
I have implemented it, and I know for a fact it is used by hotmail servers. When I have tested it and it blocks email fine. Perhaps you misconfigured your spf record?
-
SHARE:
Similar Threads
-
By kmount in forum Comments and Suggestions
Replies: 2
Last Post: 30th March 2008, 05:48 PM
-
By tartarus in forum Networks
Replies: 21
Last Post: 2nd January 2008, 03:37 PM
-
By callumtuckey in forum General Chat
Replies: 7
Last Post: 4th October 2007, 12:35 PM
-
By indie in forum How do you do....it?
Replies: 14
Last Post: 13th June 2006, 07:39 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules