The primary mode of support here is peer-to-peer, meaning users helping other users. (please remember this at all times!)
Another try:
This forum is composed of people who have used spamcop and those who are learning about anti-spam efforts.
![]() ![]() |
| geistman |
May 25 2007, 07:27 AM
Post
#1
|
|
Newbie ![]() Group: Members Posts: 1 Joined: 25-May 07 Member No.: 7790 |
For the last several days, I have been receiving hundreds of delivery failure notices (in various forms from Undelivered mail, Mailer-daemon AntiSpam BOL, Postmaster, ...) to my email account every day. I am certain that my computer is not the source of these messages; my system is spyware and virus-free. It looks like somebody's infected computer is pumping out spam messages with my email address as the return address.
I don't want my email address or domain to be considered a spam site because of this. I would like to stop this from occurring, if possible. I realize that the delivery return messages are not, themselves, spam, but is there a way I can get information from the header and then submit that message to spamcop? Or is there some other way I can control this? Thanks in advance. |
| Telarin |
May 25 2007, 07:46 AM
Post
#2
|
|
Advanced Member Group: Memberp Posts: 803 Joined: 30-November 05 Member No.: 4882 |
Actually, spamcop DOES consider these misdirected NDRs to be spam, and you can report them through spamcop. Spamcop has no interest in the email addresses listed on the message, as they are trivially forged, the only information that spamcop is concerned with are the actual IP addresses in the message header, which can not be forged.
A properly configured mail server will not produce bounces to a forged from address, however, as you have found out, there are many many mail servers on the internet that are not properly configured. You can submit these misdirected bounces to spamcop as you would any other piece of spam. -------------------- Will Russell, MCP
IT Specialist Galveston Insurance Associates |
| Farelf |
May 25 2007, 12:37 PM
Post
#3
|
|
T-shirt wearing out Group: Membersph Posts: 3871 Joined: 23-February 04 From: Western Australia Member No.: 491 |
In support of Will's advice, note the official SC FAQ On what type of email should I (not) use SpamCop?, particularly
QUOTE(Spam within other messages) Messages which may be reported: There are several types of responses to forged email that SpamCop has in the past prohibited. However, these messages have become a big enough problem that we now allow them to be reported as the spam that they technically are. Examples of messages in this category: 1. Misdirected bounces 2. Misdirected virus notifications 3. Misdirected vacation emails 4. Misdirected challenges from challenge/response spam filtering systems ...I am certain that my computer is not the source of these messages; my system is spyware and virus-free. It looks like somebody's infected computer is pumping out spam messages with my email address as the return address. The proof of that would be that it is not your IP address shown as the origin of the bounced spam. Confidence in AV and firewall protection is sometimes sadly misplaced but it certainly would not be usual practice for spam to be going out using your domain address if you were infected. If you have difficulty reading the headers on that bounced spam you could always snip a sample and post into the parser just to see what it makes of it. Just be sure to cancel, not report the results. That is not "your" spam to report, of course.-------------------- Plus ça change, plus c’est la même chose
|
| Miss Betsy |
May 25 2007, 02:18 PM
Post
#4
|
|
T-shirt wearing out Group: Membersph Posts: 3332 Joined: 2-February 04 Member No.: 174 |
And while all domain owners want to STOP the forging of their domain in the From - some even would prefer the perpetuators to be boiled in oil - There is not much you can do about stopping them. Fortunately, few people on the internet today would think it was really your domain, and no one with any authority to enact any punitive measures would do so.
If you are getting hundreds, it might be a good idea to turn off your 'catchall' Miss Betsy -------------------- an almost new internet user
if you don't think your post has been answered sufficiently, please email service[at]admin.spamcop.net |
| Telarin |
May 29 2007, 08:17 AM
Post
#5
|
|
Advanced Member Group: Memberp Posts: 803 Joined: 30-November 05 Member No.: 4882 |
And while all domain owners want to STOP the forging of their domain in the From - some even would prefer the perpetuators to be boiled in oil Very, very hot oil... -------------------- Will Russell, MCP
IT Specialist Galveston Insurance Associates |
| davidwalker |
Jun 8 2007, 04:35 AM
Post
#6
|
|
Newbie ![]() Group: Members Posts: 1 Joined: 8-June 07 Member No.: 7844 |
In support of Will's advice, note the official SC FAQ On what type of email should I (not) use SpamCop?, particularly The proof of that would be that it is not your IP address shown as the origin of the bounced spam. Confidence in AV and firewall protection is sometimes sadly misplaced but it certainly would not be usual practice for spam to be going out using your domain address if you were infected. If you have difficulty reading the headers on that bounced spam you could always snip a sample and post into the parser just to see what it makes of it. Just be sure to cancel, not report the results. That is not "your" spam to report, of course. This has happened to me on average once per month for the past 6 months and my e-mail address is being faked by a true spammer. Woke up this morning with more than 700 delivery failure,auto-responses,challenges etc. And while the actual (forged?) IP address is somewhere in Asia according to APNIC there are a number of firewalls that block my IP temporarily. I have reported the spam to the companies that are being "promoted" but only one has taken any action. I have been totally ignored by all the rest. While it is not "my" spam, is there any way I can report it??? David -------------------- Marching to the sound of a different drum
|
| Miss Betsy |
Jun 8 2007, 05:13 AM
Post
#7
|
|
T-shirt wearing out Group: Membersph Posts: 3332 Joined: 2-February 04 Member No.: 174 |
<snip>And while the actual (forged?) IP address is somewhere in Asia according to APNIC there are a number of firewalls that block my IP temporarily. What do you mean that there are 'firewalls' that block your IP? No server admin would block your IP address because of a forged From. The IP address cannot be forged by the receiving computer. It is only the From and the return path that can be forged. QUOTE I have reported the spam to the companies that are being "promoted" but only one has taken any action. I have been totally ignored by all the rest. While it is not "my" spam, is there any way I can report it??? The clue is in your comment 'only one has taken any action' - unless it is a mistake (including infected computers on smaller networks), neither sources nor spamvertized sites take action against spammers. Although spamcop was designed with the idea that server admins would take action and stop spam, most spam is now sent from places that prefer spammer money and even if spamvertized websites are taken down, spammers have hundreds of domain names to use. The way to stop spam is to block it at the server level from those places that send it. And that includes the people who accept spam and then send emails to the return path. You can report these through spamcop. If you want to want to be ignored, then you can report the spam contained in the 'bounces' manually. You can use the parser to find the correct abuse address, but be sure to cancel the report. Miss Betsy -------------------- an almost new internet user
if you don't think your post has been answered sufficiently, please email service[at]admin.spamcop.net |
| agsteele |
Jun 8 2007, 11:57 AM
Post
#8
|
|
Been There Group: Memberp Posts: 1077 Joined: 31-January 04 From: Keighley UK Member No.: 148 |
This has happened to me on average once per month for the past 6 months and my e-mail address is being faked by a true spammer. Woke up this morning with more than 700 delivery failure,auto-responses,challenges etc. And while the actual (forged?) IP address is somewhere in Asia according to APNIC there are a number of firewalls that block my IP temporarily. I have reported the spam to the companies that are being "promoted" but only one has taken any action. I have been totally ignored by all the rest. While it is not "my" spam, is there any way I can report it??? Hi David! You can submit a report via SpamCop of the spam that you receive and only the spam that you receive. So, it is NOT permitted to reconstruct a spam item sent to someone else that bounces to you. You can report the bounce but not the message that caused the bounce. All that said, the reports are to the SpamCop system which alerts the ISP which was used to send the message. But these are not reports in the sense that you refer to ie telling a company that their products are being promoted via spam. In any case, telling these companies is likely to be fruitless since they are probably well aware that they have employed spam techniques to promote their products and have done so intentionally (IMG:style_emoticons/default/blink.gif) Andrew -------------------- A SpamCop user - all comments I make are mine and not SpamCop's :-)
All comments in these forums are from users offering help to other users unless the user explicitly identifies themselves as SpamCop staff. To contact SpamCop staff Email service[at]admin.spamcop.net |
| PaulOsborn |
Oct 10 2007, 05:23 PM
Post
#9
|
|
Newbie ![]() Group: Members Posts: 2 Joined: 10-October 07 Member No.: 8213 |
I'm having exactly the same problem as geistman and found this discussion very useful. Can I just ask for confirmation (to see if I've got it right) - I can report the "returned email" "undeliverable" etc mails through SpamCop as spam in themselves as I didn't generate the email that they are responding to. However, this doesn't get to the originator of the spam that's using my email address for the return?
I'm receiving around 50 of these returns a day so it doesn't seem too practical to report every one and in any case, there doesn't seem to be a pattern so even if one genuine company or individual that's sent a return stops, there will be a different 50 sending them to me tomorrow! Conclusion? There's no way that SpamCop is able to use the header info I've got in the returned mails to identify the spam originator (who's using my address as the return) so effectively there's no solution? Sorry if I should have understood this from the previous mails, but I'd like to make sure I've got it right before I give up on my long-standing email address! Thanks in advance. |
| Wazoo |
Oct 10 2007, 05:50 PM
Post
#10
|
|
What Life? Group: Forum Admin Posts: 12536 Joined: 22-January 04 From: Iowa Member No.: 18 |
I'm having exactly the same problem as geistman and found this discussion very useful. Can I just ask for confirmation (to see if I've got it right) - I can report the "returned email" "undeliverable" etc mails through SpamCop as spam in themselves as I didn't generate the email that they are responding to. However, this doesn't get to the originator of the spam that's using my email address for the return? What you will be reporting is the 'misdirected bounce' ... this term is defined in numerous places. The ISP/system that generated this 'bounce' is who will come up as the target for your report. The spammer forged your address into the From: and/or Reply-To: lines in the e-mail header, some ISP received that e-mail then decided that 'you' didn't exist on that network, so then later got around to sending out the notice that the e-mail didn't go through. Back in the early days, this was normal. Once the spammers started abusing this 'function' .... it is no longer considered appropriate. |
| turetzsr |
Oct 10 2007, 06:00 PM
Post
#11
|
|
T-shirt wearing out Group: Membersph Posts: 3575 Joined: 26-January 04 From: Michigan USA Member No.: 59 |
<snip> ...IMHO yes, you have it right.Can I just ask for confirmation (to see if I've got it right) - I can report the "returned email" "undeliverable" etc mails through SpamCop as spam in themselves as I didn't generate the email that they are responding to. However, this doesn't get to the originator of the spam that's using my email address for the return? <snip> ...SpamCop is just a tool that helps us identify the source of the spam we ourselves have received and to send complaints on our behalf to the abuse desk of those sources. It does this by analyzing the e-mail Internet headers that it believes it can trust to provide valid information. The e-mail Internet headers added by the server prior to the one that sent it to you can not be trusted to be accurate (they could be forged) and it would be those headers that SpamCop would have to rely on to go back to the originator of the spam. Conclusion? There's no way that SpamCop is able to use the header info I've got in the returned mails to identify the spam originator (who's using my address as the return) so effectively there's no solution? ...Not quite. You can use the SpamCop parser by entering the e-mail Internet headers you believe identify the source of the original spam, cancel the reports SpamCop offers to send on your behalf, and send your own reports manually (being sure to not mention SpamCop as being your source of information in your reports).<snip> -------------------- ..Regards,
...Steve T ...A Happy SpamCop.net user (not an employee) ...Please avoid replying via e-mail, as it is not secure |
| Miss Betsy |
Oct 11 2007, 05:07 AM
Post
#12
|
|
T-shirt wearing out Group: Membersph Posts: 3332 Joined: 2-February 04 Member No.: 174 |
Before you give up on your address, this phenomenon usually doesn't last very long. (unless you are using a catchall address also).
And, if you do change your address, be sure to make a 'strong' one that contains numbers or symbols so that dictionary spammers can't guess it. i.e. pau!0sborne and don't post it on the internet. Miss Betsy -------------------- an almost new internet user
if you don't think your post has been answered sufficiently, please email service[at]admin.spamcop.net |
| PaulOsborn |
Oct 11 2007, 03:32 PM
Post
#13
|
|
Newbie ![]() Group: Members Posts: 2 Joined: 10-October 07 Member No.: 8213 |
Many thanks for that ... it'll be a relief when it does stop! Could you tell me what a "catchall address" is tho? Don't think I have one, but you never know!
Many thanks to all for the responses ... advice is much appreciated. Paul |
| Wazoo |
Oct 11 2007, 03:48 PM
Post
#14
|
|
What Life? Group: Forum Admin Posts: 12536 Joined: 22-January 04 From: Iowa Member No.: 18 |
|
| StevenUnderwood |
Oct 11 2007, 05:57 PM
Post
#15
|
|
What Life? Group: Membersph Posts: 5141 Joined: 20-January 04 From: Whitinsville, MA USA Member No.: 12 |
Could you tell me what a "catchall address" is tho? Don't think I have one, but you never know! 2 Questions: Do emails to <anything here>@yourdomain get to you? Are any of the bounces being sent to unassigned email addresses as the forged sender? If the answer to either question is yes, you are using a "catch all address". It was designed to eliminate the problem of typos in email addresses (anything sent to your domain will be delivered to you). It has outlived its usefulness because of the spammers. -------------------- Steven P. Underwood, DNRC
Whitinsville, MA underwood+forum[at]spamcop.net -No trees were killed in the sending of this message. However, a large number of electrons were terribly inconvenienced.- |
| bwawsc |
Oct 20 2007, 12:44 PM
Post
#16
|
|
Newbie ![]() Group: Members Posts: 9 Joined: 20-October 07 From: Boulder Creek, CA USA Member No.: 8237 |
One thing that can be done about the forging of sender addresses is for every sending domain to publish an SPF policy, and every receiving server to check and process mail against it. Adoption is slow, but at some point a critical mass will be reached which will allow this to be effective.
OpenSPF Foundation -- Bill -------------------- --
Bill |
| Wazoo |
Oct 20 2007, 02:48 PM
Post
#17
|
|
What Life? Group: Forum Admin Posts: 12536 Joined: 22-January 04 From: Iowa Member No.: 18 |
One thing that can be done about the forging of sender addresses is for every sending domain to publish an SPF policy, and every receiving server to check and process mail against it. Adoption is slow, but at some point a critical mass will be reached which will allow this to be effective. Not good .. leaving out sall the down-sdie on that suggestion. |
| Farelf |
Oct 21 2007, 01:15 AM
Post
#18
|
|
T-shirt wearing out Group: Membersph Posts: 3871 Joined: 23-February 04 From: Western Australia Member No.: 491 |
Slashdot discussion at http://ask.slashdot.org/article.pl?sid=07/06/22/1547225 presents some thoughts. A reasoned "pro" observation within that on the current state of play (last June) is http://ask.slashdot.org/comments.pl?sid=24...mp;cid=19614885
-------------------- Plus ça change, plus c’est la même chose
|
| bwawsc |
Oct 21 2007, 08:17 PM
Post
#19
|
|
Newbie ![]() Group: Members Posts: 9 Joined: 20-October 07 From: Boulder Creek, CA USA Member No.: 8237 |
QUOTE Not good .. leaving out sall the down-sdie on that suggestion. Sorry, Wazoo - I don't understand this comment at all. Are you saying that there is a significant downside to senders publishing an SPF policy, or to receiving servers checking SPF? Both? What is the downside you are referring to? My personal opinion (I know, we all have one) is that there is no cost to the owner of a domain and a potential big payoff, even if it takes a while to develop. I felt I was offering a constructive suggestion and didn't realize I was leaving out the downside. I sincerely would appreciate enlightenment. -------------------- --
Bill |
| StevenUnderwood |
Oct 22 2007, 09:05 AM
Post
#20
|
|
What Life? Group: Membersph Posts: 5141 Joined: 20-January 04 From: Whitinsville, MA USA Member No.: 12 |
Are you saying that there is a significant downside to senders publishing an SPF policy, or to receiving servers checking SPF? Both? What is the downside you are referring to? 1. Everyone will need to use the ISP account they are currently connected to as the return address in order to use that SMTP server. Otherwise, everyone will need to contract with a separate mail provider to keep a uniform presence. 2. Forwarding services are also troublesome for the same reason, you can not have an alternate sender set in your email. -------------------- Steven P. Underwood, DNRC
Whitinsville, MA underwood+forum[at]spamcop.net -No trees were killed in the sending of this message. However, a large number of electrons were terribly inconvenienced.- |
![]() ![]() |
|
Lo-Fi Version | Time is now: 21st November 2009 - 07:23 PM |