Hello,
Every couple of days we get get a burst of spam to our servers which last around 4 hours, the email is different for each burst but when it starts we usually get thousands of identical emails sent to our servers but sent to hundreds of different email accounts. The strange thing about this is that all the emails seem to go to genuine email accounts that exist and even accounts that are hardly/never used for example; [email protected] but FredB never used his account because he was setup on the system but never started at the company in the end...
The most recent email is this sanesecurity.blogspot.co.uk/2015/10/shaun-buzzard-order-lp2220151013164535d.html
Because all the spam seems to go to specific accounts that exist and very rarely [email protected] [email protected] It makes me believe that some how the spammers/spam are getting a list of genuine accounts from my servers but I am not sure how they would do this other than working out from bounce mails. When setting up new servers I generally follow a guide on how to make the servers more secure, such as :blackhole: mail etc.
Does anyone have any ideas?
Thanks in advance.
Every couple of days we get get a burst of spam to our servers which last around 4 hours, the email is different for each burst but when it starts we usually get thousands of identical emails sent to our servers but sent to hundreds of different email accounts. The strange thing about this is that all the emails seem to go to genuine email accounts that exist and even accounts that are hardly/never used for example; [email protected] but FredB never used his account because he was setup on the system but never started at the company in the end...
The most recent email is this sanesecurity.blogspot.co.uk/2015/10/shaun-buzzard-order-lp2220151013164535d.html
Because all the spam seems to go to specific accounts that exist and very rarely [email protected] [email protected] It makes me believe that some how the spammers/spam are getting a list of genuine accounts from my servers but I am not sure how they would do this other than working out from bounce mails. When setting up new servers I generally follow a guide on how to make the servers more secure, such as :blackhole: mail etc.
Does anyone have any ideas?
Thanks in advance.
Last edited by a moderator: