Results 1 to 3 of 3

Thread: spam, forged sender, bounce backs

  1. #1
    Member Drake's Avatar
    Join Date
    Nov 2001
    Location
    New Jersey
    Posts
    80
    cPanel/WHM Access Level

    DataCenter Provider

    Question spam, forged sender, bounce backs

    Hi all,

    This age old problem is getting on our nerves again. Especially within the last few days (August 20+) As sysadmins, we are receiving non-deliverable e-mail bounce backs. It is obviously spammers (not relaying through our boxes), but just using a bogus sender name. Some of the recipient targeted servers actually send back a full snapshot of the bounced e-mail, which is good, so we can analyse the headers to be sure its not one of our own customers spamming. What we're seeing is that the sender is claiming to be from one or more of our hosted domain names, but not an IP number or ours. These originating IP numbers have been in Thailand, taiwan, and various eastern block Europe countries. Only a few are from IP's within the USA. In a perfect world, you would lookup the IP number and send a complaint to the Sysadmin of the offending network. OK, but this gets nowhere, even with Bell Atlantic DSL, and other USA companies. The best response I got from them was an automated e-mail trying to sell me their spam blocking service. What a joke. And forget about complaining to a sysadmin in Bulgaria. This seemes to come in waves, and then quiet down for a while. Anyone got any ideas why this is?
    www.DuraServer.net
    Web Hosting ~ Networtking
    Shared & Dedicated Servers
    Connectivity, On-Site-Service

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Apr 2002
    Posts
    686
    cPanel/WHM Access Level

    DataCenter Provider

    Default

    Im wondering if you found a soultion for this.

    Im having the same sort of problem on one domain and its loading up exim way to much...

  3. #3
    Registered User Poonga's Avatar
    Join Date
    Sep 2004
    Posts
    2

    Default bogons, blacklists, and the like

    Have you looked into bogon listings? They can be added to your iptables to block bogus ip net ranges, also, adding rbl listings to your sa or exim can filter out quite a few spammers. Using a global type of filter like that to block subject headers can cause real bounce backs to be foobared so you gotta be careful with those. Do a forum search in here, I'm sure you'll find a couple of threads mentioning this.

    Edit: There's a great filter for fake message bouncing over at http://www.timj.co.uk/linux/sa.php thanks to Tim Jackson.
    Last edited by Poonga; 09-20-2004 at 04:06 PM.

Similar Threads

  1. Limiting bounce backs( Big problem)
    By mohitmoudgil in forum Archived Feature Requests
    Replies: 6
    Last Post: 04-30-2012, 04:43 PM
  2. mailbox full bounce to sender due to forwarder
    By jganders in forum E-mail Discussions
    Replies: 2
    Last Post: 07-06-2009, 04:33 PM
  3. email bounce backs
    By deanc in forum E-mail Discussions
    Replies: 4
    Last Post: 11-23-2008, 09:32 PM
  4. Question about returning (bounce) a message back to sender...
    By guldvog in forum E-mail Discussions
    Replies: 8
    Last Post: 10-21-2007, 02:40 AM
  5. Bounce messages not delivered to sender
    By jackflash in forum cPanel & WHM Discussions
    Replies: 8
    Last Post: 05-24-2005, 03:23 PM