I have very recently started to get emails like the one below every day, about 10 times a day.
My questions are...
1) Are these bounce messages the result of someone spoofing my email address remotely, or has my server likely been compromised by a spammer?
2) Is there any chance that this activity is going to get my domain on some sort of worldwide blacklist?
3) Is there anything I can do to stop this nonsense?
Typical bounce message in my inbox follows. I've replaced my actual domain name with 'mydomain.com' in every instance. Please note that our friend "Rosalie Richmond" <ojlakd@mydomain.com> does not exist – she appears to be a spoofed email address.
Code:Return-path: <> Envelope-to: mycatchallmailbox@mydomain.com Delivery-date: Sat, 15 Apr 2006 06:01:27 -0700 Received: from myusername by server.mydomain.com with local-bsmtp (Exim 4.52) id 1FUkOy-0003Oe-Ci for mycatchallmailbox@mydomain.com; Sat, 15 Apr 2006 06:01:27 -0700 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on server.mydomain.com X-Spam-Level: X-Spam-Status: No, score=-0.2 required=7.0 tests=BAYES_00,FORGED_RCVD_HELO, HTML_50_60,HTML_IMAGE_ONLY_20,HTML_MESSAGE,NO_REAL_NAME autolearn=no version=3.1.1 Received: from [63.118.88.99] (helo=MAILBOX.tca.us) by server.mydomain.com with esmtp (Exim 4.52) id 1FUkOx-0003OW-KZ for ojlakd@mydomain.com; Sat, 15 Apr 2006 06:01:24 -0700 From: postmaster@tca-us.com To: ojlakd@mydomain.com Date: Sat, 15 Apr 2006 09:04:02 -0400 MIME-Version: 1.0 Content-Type: multipart/report; report-type=delivery-status; boundary="9B095B5ADSN=_01C6605BB7F7EAAA00005851MAILBOX.tca.us" X-DSNContext: 335a7efd - 4523 - 00000001 - 80040546 Message-ID: <pEBtKarvz000021fa@MAILBOX.tca.us> Subject: Delivery Status Notification (Failure) This is a MIME-formatted message. Portions of this message may be unreadable without a MIME-capable mail program. --9B095B5ADSN=_01C6605BB7F7EAAA00005851MAILBOX.tca.us Content-Type: text/plain; charset=unicode-1-1-utf-7 This is an automatically generated Delivery Status Notification. Delivery to the following recipients failed. mjbailey@tca-us.com --9B095B5ADSN=_01C6605BB7F7EAAA00005851MAILBOX.tca.us Content-Type: message/delivery-status Reporting-MTA: dns;MAILBOX.tca.us Received-From-MTA: dns;camfw Arrival-Date: Sat, 15 Apr 2006 09:04:02 -0400 Final-Recipient: rfc822;mjbailey@tca-us.com Action: failed Status: 5.1.1 --9B095B5ADSN=_01C6605BB7F7EAAA00005851MAILBOX.tca.us Content-Type: message/rfc822 Received: from camfw ([192.168.13.1]) by MAILBOX.tca.us with Microsoft SMTPSVC(6.0.3790.1830); Sat, 15 Apr 2006 09:04:02 -0400 Received: (qmail 27081 invoked from network); Sat, 15 Apr 2006 16:01:02 +0300 Received: from unknown (HELO bitp.jipl) (81.213.239.135) by dsl.dynamic8121313810.ttnet.net.tr with SMTP; Sat, 15 Apr 2006 16:01:02 +0300 Message-ID: <000601c6608c$a65739e1$87efd551@bitp.jipl> From: "Rosalie Richmond" <ojlakd@mydomain.com> To: "Helen Wallace" <mjbailey@tca-us.com> Subject: latter Date: Sat, 15 Apr 2006 15:53:57 +0300 MIME-Version: 1.0 Content-Type: multipart/related; type="multipart/alternative"; boundary="----=_NextPart_000_0002_01C660A5.CBA471AD" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.2180 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180 Return-Path: ojlakd@mydomain.com X-OriginalArrivalTime: 15 Apr 2006 13:04:02.0828 (UTC) FILETIME=[119524C0:01C6608D] {insert junk email here}



LinkBack URL
About LinkBacks
Reply With Quote





