Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Sat Jan 16, 2010 6:50 am 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
Code:
A message from <apache@mydomain.org>
to: support@mydomain.org

was considered unsolicited bulk e-mail (UBE).

Our internal reference code for your message is 29902-10/WFh9jabPpGXB

The message carried your return address, so it was either a genuine mail
from you, or a sender address was faked and your e-mail address abused
by third party, in which case we apologize for undesired notification.

We do try to minimize backscatter for more prominent cases of UBE and
for infected mail, but for less obvious cases some balance between
losing genuine mail and sending undesired backscatter is sought,
and there can be some collateral damage on either side.


Return-Path: <apache@mydomain.org>
From: fajuua@ctzuhc.com
Message-ID: <20100115171629.45DAA10449@mail.mydomain.org>
Subject: [mydomain] VJIAaXukaP

Delivery of the email was stopped!


dsn_status

Reporting-MTA: dns; mail.mydomain.org
Received-From-MTA: smtp; mail.mydomain.org ([127.0.0.1])
Arrival-Date: Fri, 15 Jan 2010 18:16:30 +0100 (CET)

Original-Recipient: rfc822;support@mydomain.org
Final-Recipient: rfc822;support@mydomain.org
Action: failed
Status: 5.7.0
Diagnostic-Code: smtp; 554 5.7.0 Reject, id=29902-10 - SPAM
Last-Attempt-Date: Fri, 15 Jan 2010 18:16:30 +0100 (CET)
Final-Log-ID: 29902-10/WFh9jabPpGXB


header

Return-Path: <apache@mydomain.org>
Received: by mail.mydomain.org (Postfix, from userid 48)
   id 45DAA10449; Fri, 15 Jan 2010 18:16:29 +0100 (CET)
To: support@mydomain.org
Subject: [mydomain] VJIAaXukaP
From: fajuua@ctzuhc.com
MIME-Version: 1.0
Content-Type: text/html;
Message-Id: <20100115171629.45DAA10449@mail.mydomain.org>
Date: Fri, 15 Jan 2010 18:16:29 +0100 (CET)


I often receive email like this, my VPS isn't an open relay and my email forms are quite secure.
May I need to worry about this? What does it means?
Have you ever received mail like this?


Top
   
 Post subject:
PostPosted: Sat Jan 16, 2010 11:37 pm 
Offline
Senior Member

Joined: Sun Aug 02, 2009 1:32 pm
Posts: 222
Website: https://www.barkerjr.net
Location: Connecticut, USA
With your obfuscation, I'm having trouble determining what that email means. Does it show your VPS's IP address in the sender's header? I receive spoofed spam bounces from time to time, but they usually don't have my server's IP.


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 7:19 am 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
BarkerJr wrote:
With your obfuscation, I'm having trouble determining what that email means. Does it show your VPS's IP address in the sender's header? I receive spoofed spam bounces from time to time, but they usually don't have my server's IP.


No obfuscation in my post,
I only changed the domain name in mydomain.org ...


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 9:12 am 
Offline
Senior Member

Joined: Sun Aug 02, 2009 1:32 pm
Posts: 222
Website: https://www.barkerjr.net
Location: Connecticut, USA
Is it possible that the email is not spam at all, and just caused by the fact that ctzuhc.com does not resolve?


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 10:09 am 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
BarkerJr wrote:
Is it possible that the email is not spam at all, and just caused by the fact that ctzuhc.com does not resolve?


I don't know, I'm asking here to understand why of this email...
thanks for your patience :)


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 12:51 pm 
Offline
Senior Member

Joined: Fri Sep 21, 2007 4:12 pm
Posts: 78
Quote:
The message carried your return address, so it was either a genuine mail from you, or a sender address was faked and your e-mail address abused by third party


It is absolutely trivial to send email "from" anyone at all. If you've double and triple checked your setup and your logs, this would be the reason.


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 3:44 pm 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
kbrantley wrote:
Quote:
The message carried your return address, so it was either a genuine mail from you, or a sender address was faked and your e-mail address abused by third party


It is absolutely trivial to send email "from" anyone at all. If you've double and triple checked your setup and your logs, this would be the reason.


I receive mail like this once a week and I don't want that my email address will be inserted in some spam list...
what do you think about that?

my mail logs is huge, is there a way to filter it to see only the email sent from my server? in that way I can see if someone non authorized is using my vps to send email...
thanks.


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 4:04 pm 
Offline
Senior Member

Joined: Fri Sep 21, 2007 4:12 pm
Posts: 78
cat /var/log/maillog | grep 'from=<my@email.com>'

... or similar. It would likely depend on your mailserver.


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 4:46 pm 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
kbrantley wrote:
cat /var/log/maillog | grep 'from=<my@email.com>'

... or similar. It would likely depend on your mailserver.


it seems that there is nothing of strange in my log, can't understand why I receive this email...
am I the only one who receive this kind of email?


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 4:57 pm 
Offline
Senior Member
User avatar

Joined: Sun Dec 27, 2009 11:12 pm
Posts: 1038
Location: Colorado, USA
sblantipodi wrote:
and I don't want that my email address will be inserted in some spam list...

It's a big bad internet out there and spammers could care less what you think about them using your email address as their spoofed from/reply to address.

Nor is there anything you can do to stop them.

You would hope that people would be smart enough to have filters on THEIR email server to drop mail that doesn't have matching sender IP vs sender domain - but don't count on it.


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 5:29 pm 
Offline
Senior Member

Joined: Fri Sep 21, 2007 4:12 pm
Posts: 78
sblantipodi wrote:
kbrantley wrote:
cat /var/log/maillog | grep 'from=<my@email.com>'

... or similar. It would likely depend on your mailserver.


it seems that there is nothing of strange in my log, can't understand why I receive this email...
am I the only one who receive this kind of email?


I've got a few over the years. People send email "from" my address and I get the backscatter. SPF can prevent a lot of this, but very few people set it up, never mind correctly.


Top
   
 Post subject:
PostPosted: Sun Jan 17, 2010 9:56 pm 
Offline
Senior Member

Joined: Sun Aug 02, 2009 1:32 pm
Posts: 222
Website: https://www.barkerjr.net
Location: Connecticut, USA
I setup SPF then bitch at admins who bounce email, I didn't send, to me.


Top
   
 Post subject:
PostPosted: Mon Jan 18, 2010 4:55 am 
Offline
Senior Member
User avatar

Joined: Sun Feb 08, 2004 7:18 pm
Posts: 562
Location: Austin
SPF isn't required to get after admins for this. They should be rejecting mail at SMTP time, not generating new bounce mails and firing them wherever the spam told them to. Admins doing that are almost as bad as the spammers.


Top
   
 Post subject:
PostPosted: Mon Jan 18, 2010 8:31 pm 
Offline
Senior Member

Joined: Sun Aug 02, 2009 1:32 pm
Posts: 222
Website: https://www.barkerjr.net
Location: Connecticut, USA
Right, but if the admin checks SPF, then at least he can be sure that he bounces it back to the right person. That is assuming that the sending domain has SPF configured.


Top
   
 Post subject:
PostPosted: Mon Jan 18, 2010 8:44 pm 
Offline
Senior Member
User avatar

Joined: Sun Feb 08, 2004 7:18 pm
Posts: 562
Location: Austin
My point is that it is a misconfigured server which generates new bounce messages.

A properly configured server rejects mail at SMTP time, and that's all it has to do. If you're generating bounce emails you've already lost.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group