Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member erinspice's Avatar
    Join Date
    Feb 2006
    Posts
    101

    Default spam/open relay question

    Hi! I received a Client TOS Notification from AOL today. It was my understanding that they sent these whenever they believe that my server is the origination point of a spam email message. Can you guys help me understand this?

    Subject: Can you tell me what's wrong, and how we can fix it?
    From: "Zachery O. Livingston" <Zachery@someunrelateddomain.com>
    Date: Wed, 08 Aug 2007 10:35:13 +0400
    To: <Undisclosed Recipients>
    Return-Path: <jr_abernathy@someunrelateddomain.com>
    Received: from rly-xa05.mx.aol.com (rly-xa05.mail.aol.com [xx.xx.xx.xx]) by air-xa02.mail.aol.com (v118.4) with ESMTP id MAILINXA21-7446b964229c; Wed, 08 Aug 2007 02:35:35 -0400
    Received: from my.hostname.com (my.hostname.com [xx.xx.xx.xx]) by rly-xa05.mx.aol.com (v118.4) with ESMTP id MAILRELAYINXA56-7446b964229c; Wed, 08 Aug 2007 02:35:14 -0400
    Received: from xx.xx.xx.xx.blahblah.com ([xx.xx.xx.xx]) by my.hostname.com with smtp (Exim 4.63) (envelope-from <jr_abernathy@cargill.com>) id 1IIf8Q-0007pP-2y for info@myclientsdomain.com; Wed, 08 Aug 2007 01:35:10 -0500
    Received: from xx.xx.xx.xx (HELO mail3.someunrelateddomain.com) by blahblah.com with esmtp (GZQPSLACJQJ GMAGB) id 9nLM0a-Iw8dFU-Rw for infon@blahblah.com; Wed, 08 Aug 2007 10:35:13 +0400
    Message-ID: <0b9901c7d986$464858e0$0dcc7e57@Zachery>
    MIME-Version: 1.0
    Content-Type: multipart/alternative; boundary="----=_NextPart_2967_0C01_01C7D9A7.CD59F8E0"
    X-Priority: 3
    X-MSMail-Priority: Normal
    X-Mailer: Microsoft Outlook Express 6.00.2800.1165
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
    X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
    X-AntiAbuse: Primary Hostname - my.hostname.com
    X-AntiAbuse: Original Domain - myclientsdomain.com
    X-AntiAbuse: Originator/Caller UID/GID - [0 0] / [47 12]
    X-AntiAbuse: Sender Address Domain - someunrelateddomain.com
    X-AOL-IP: xx.xx.xx.xx
    My server received the email in the 2nd Received line and sent it out in the 3rd one. I tested my server on 2 different open relay test sites and it came back both times that it is not an open relay. What do these headers mean? How was my server involved in this spam transmission and how can I stop it?

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Check /etc/valiases/* and see if anyone is forwarding email to AOL. If they are, they've probably reported your server as sending spam within their AOL account - bad user. If that's the case you're better off removing the forwarder and telling the user to POP their email from the server (though if they're an AOL user...)
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. Open Relay
    By plumas in forum Discusión en Español
    Replies: 2
    Last Post: 01-20-2009, 08:01 PM
  2. Open Relay
    By ukpro in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-14-2005, 07:08 PM
  3. open relay ?
    By arhs in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 01-17-2005, 02:19 PM
  4. How do you correctly close an Open Relay? Failed abuse.net mail relay test
    By Vatoloco in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-08-2004, 07:00 PM
  5. Demo Accounts & Spam Open Relay
    By qkslvr in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 07-29-2004, 11:12 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube