QUOTE(jeffslife @ Feb 10 2009, 09:40 AM)

Also, I'd love more than anything to read an FAQ, which one are you referring to?
At the top of this page, both the
SpamCop FAQ and the
SpamCop WIki are offered via several links. In this Forum section, there was a
Pinned entry, also titled "Why am I Blocked?" ....
QUOTE
550-"JunkMail rejected -
mohawk.mtrsd.k12.ma.us (mail.mohawkschools.org)
550-[159.250.29.8]:45506 is
in an RBL, see Blocked - see 550
http://www.spamcop.net/bl.shtml?159.250.29.8 I edited your post to make the link functional .... but you didn't say whether you bothered to follow it yourself or not.
http://www.spamcop.net/w3m?action=blcheck&...ip=159.250.29.8159.250.29.8 listed in bl.spamcop.net (127.0.0.2)
If there are no reports of ongoing objectionable email from this system it will be delisted automatically in approximately 21 hours.
Causes of listing
* System has sent mail to SpamCop spam traps in the past week (spam traps are secret, no reports or evidence are provided by SpamCop)
* SpamCop users have reported system as a source of spam about 20 times in the past week
Listing History
System has been listed for 7.4 days.
This fits the infected/compromised system scenario, based on both spamtrap hits and user Reports.
http://www.senderbase.org/senderbase_queri...ng=159.250.29.8Volume Statistics for this IP
Magnitude Vol Change vs. Last Month
Last day ........ 3.7 5%
Last month .... 3.7
No sign of a slow-down in traffic, so it would appear that there is more than just he one system involved.
QUOTE
been scanning packets on known trouble ports (eg. 25) for hours, and I've found nothing.
Per
http://forum.spamcop.net/forums/index.php?showtopic=4556 .. you're looking at something around 10,000 e-mails a day. It would seem that if you're not "finding anything" you're not looking in the right spot.
Nothing said about a firewall in use, or log files analyzed.
Nothing said that actually explains anything abut the network, i.e. an actual/separate e-mail server involved (Hostname: mohawk.mtrsd.k12.ma.us doesn't really suggest this) Iis there any wireless networking involved?
dig mohawk.mtrsd.k12.ma.us @ 208.67.220.220
Dig mohawk.mtrsd.k12.ma.us[at]dns-auth1.crocker.com (204.97.12.58) ...
failed, couldn't connect to nameserver
Dig mohawk.mtrsd.k12.ma.us[at]dns-auth2.crocker.com (204.97.12.57) ...
failed, couldn't connect to nameserver
Dig mohawk.mtrsd.k12.ma.us[at]208.67.220.220 ...
Non-authoritative answer
Recursive queries supported by this server
Query for mohawk.mtrsd.k12.ma.us type=255 class=1
mohawk.mtrsd.k12.ma.us NS (Nameserver) dns-auth2.crocker.com
mohawk.mtrsd.k12.ma.us NS (Nameserver) dns-auth1.crocker.com
telnet 159.250.29.8 25
Trying 159.250.29.8...
telnet: Unable to connect to remote host: Connection timed out
Trace mohawk.mtrsd.k12.ma.us (159.250.29.8) ...
144.232.19.143 RTT: 17ms TTL:170 (sl-crs1-chi-0-12-2-0.sprintlink.net ok)
144.232.18.59 RTT: 39ms TTL:170 (sl-crs2-spr-0-4-5-0.sprintlink.net ok)
144.232.1.9 RTT: 42ms TTL:170 (sl-gw6-spr-15-0-0.sprintlink.net ok)
144.223.76.22 RTT: 37ms TTL:170 (sl-crock5-96615-0.sprintlink.net probable bogus rDNS: No DNS)
159.250.29.8 RTT: 43ms TTL: 50 (mohawk.mtrsd.k12.ma.us ok)
http://www.mxtoolbox.com/index.aspxns.amaranth.net did not respond with MX records for 'mohawk.mtrsd.k12.ma.us'
Mail for mohawk.mtrsd.k12.ma.us is handled by mail.mtrsd.k12.ma.us
Trace mail.mtrsd.k12.ma.us (159.250.29.160) ...
144.232.1.9 RTT: 37ms TTL:170 (sl-gw6-spr-15-0-0.sprintlink.net ok)
144.223.76.22 RTT: 46ms TTL:170 (sl-crock5-96615-0.sprintlink.net probable bogus rDNS: No DNS)
159.250.29.8 RTT: 43ms TTL:170 (mohawk.mtrsd.k12.ma.us ok)
* * * failed
* * * failed
* * * failed
* * * failed
telnet 159.250.29.160 25
Trying 159.250.29.160...
telnet: Unable to connect to remote host: Connection timed out
Too much guessing going on at this side of the screen.