SPAMCOP HOME · SPAMCOP FAQ · NEWSGROUPS · FORUM FAQ · WEBMAIL · SSL WEBMAIL · SPAMCOPWIKI


 Other words, data, places -->  SpamCop Pages V  FAQs & Words V  Newsgroups V  WebMail V  News-Recent Stuff V   Poll on menu

------>------> Latest and Current Announcements <------<------

Welcome Guest ( Log In | Register )

> This is a SpamCop.net FAQ Development/Support area

Please do NOT post any requests for help in this forum. Please post all questions in the appropriate Help Forum. This forum is reserved for the development of the SpamCop FAQ (here) and is open to all who wish to contribute to building a better FAQ. Suggestions for improvements are welcome as well as pointing out areas that are unclear or you are unable to understand as we can use those comments to improve the current FAQ (here).

 
Reply to this topicStart new topic
> FAQ Entry: Why am I getting all these bounces?
Jeff G.
post Feb 4 2004, 05:53 PM
Post #1


T-shirt wearing out
Group Icon

Group: Membersph
Posts: 3730
Joined: 2-July 04
From: Northeast New Jersey (New York Metro Area), USA ... Please read my sig. :)
Member No.: 2041



As Mike Richter would write in part:
Spammers forge the email addresses into the "From" addresses of their spam
all the time. There is no known method of making them stop. Fortunately, it
is very likely to stop on its own in a short time (typically, a few days
unless you have gotten the spammer angry at you).

Even more fortunately, no responsible individual or ISP will blame you
for the spew. You may get some irate e-mails from those who are truly
clueless, but your IP address won't show up on a blocklist for such a
forgery.

You are not supposed to report bounces or the content of bounces with
the SpamCop Reporting Service, but you can use its parsing portion to help
you compose your own reports. UPDATE: "Misdirected bounces" now "may be reported" per On what type of email should I (not) use SpamCop?.

This post has been edited by Jeff G.: May 3 2005, 04:35 AM


--------------------
Best Regards, Jeff G. (full signature)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Wazoo
post May 2 2005, 11:41 PM
Post #2


What Life?
Group Icon

Group: Forum Admin
Posts: 12536
Joined: 22-January 04
From: Iowa
Member No.: 18



Stolen from the spamcop newsgroup;

Onyx wrote:
> Ok, I just recieved cca 100 messages notifying me of failed delivery of
> emails I didn't send and they keep coming, woo hoo. Apparently, spammer
> vermin used email on my domain as a return address for their spam.
>
> Two questions:
> 1. What would be the best way to deal with this?

First of all, check your mail server to make sure that it will not relay
for a spammer forging a real user on your domain. Apparently there is a
popular mail server software out there that is designed to do that and
there is no way to disable that feature except to enable SMTP-AUTH for
all e-mail. This is what I have picked up from the admin(at)dsbl.org
list's public archives.

Then assuming that your mail server is not the one that is affected by
this feature:

File abuse reports about the delayed bounces with each mail server that
is doing the delayed bounce.

Such delayed bounces are now reportable by spamcop.net:
See a recent post in spamcop.help by Larry Kilgallen for a sample text:

: As I report that spam (the message claiming I sent a message
" I did not) I include something like the following text in my
: SpamCop report:

Believe it or not, spammers lie.

Please adjust your software to not send these meaningless warnings
blindly to the "From:" address, but instead respond within the
SMTP dialog, so your comments get to the actual originator rather
than pestering an innocent bystander.


While the bounces are allowed by RFC, it is from a time when third party
open relays were also allowed.

Most mail servers do an SMTP reject, which means that any bounce message
will come from the original sending mail server, and the only ones of
those that are relaying spam are either the domain that should receive
the abuse report of one of their users, or an open relay. Open relays
should be blocked on site.


When mail servers do not do an SMTP reject, and do an accept and bounce,
then they are participating in a DDOS to victims like you.

There have also been several recent posts on news.admin.net-abuse.email
about the practice of abusive bouncing of spam.

There are some mail server operators that claim that it is not practical
to convert to SMTP rejects instead of bouncing.

These mail server operations must be bigger than AOL.COM which had
several years ago announced on the SPAM-L mailing list that they
recognized that such bounces where abusive to the rest of the internet
and were switching over to only using SMTP rejects.

It seems that for every example of someone claiming that their network
is too large to convert, an example can be found of a larger network
that did so. And I suspect that it is a much lower operational cost to
use SMTP rejects instead of doing the accept and then bouncing.

> 2. Could this possibly get my domain listed on anti-spam lists?

Only if the mail server operator is either incompetent, or is so small
that it is unlikely that they will ever receive a legitimate e-mail from
your domain.

According to posts on news.admin.net-abuse.email, even the conservative
spamhaus.org will eventually list I.P. addresses that bounce spam to
forged addresses.

It is far more likely that the I.P. addresses of the mail servers that
are bouncing the spam will get put on local and public blocking lists
than the I.P. address of your domain.

Most medium to large mail servers pay a metered rate for their
bandwidth, and accepting fake bounces or spam needlessly increases their
operating costs.

So if the only e-mail they have ever seen from an I.P. address is spam
or fake bounces, many mail server operators that are paying for
bandwidth out of their profits or pockets will block that I.P. address.

-John
wb8tyw <at> qsl.network
Personal Opinion Only

EDIT: Wazoo edited the above, based on jeff G's observation, a few newsgroup replies that pointed to the same situation, and John's later post;

QUOTE
A typo on my part, I meant to type now instead of not.  In this case
though it may not have been obvious.

-John
wb8tyw <at> qsl.network
Personal Opinion Only
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Jeff G.
post May 3 2005, 04:39 AM
Post #3


T-shirt wearing out
Group Icon

Group: Membersph
Posts: 3730
Joined: 2-July 04
From: Northeast New Jersey (New York Metro Area), USA ... Please read my sig. :)
Member No.: 2041



QUOTE(Wazoo @ May 3 2005, 12:41 AM)
Such delayed bounces are not reportable by spamcop.net
...
-John
wb8tyw <at> qsl.network
Personal Opinion Only
*
Yes, they are (now). Please see my UPDATE above in Linear Post #1.


--------------------
Best Regards, Jeff G. (full signature)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Reply to this topicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 

- Lo-Fi Version Time is now: 22nd November 2009 - 02:49 AM