All,
deputies replied and sent me the headers on the email complaint
I just replied back with the very long email complaint that I will include below:
Bottom line is the complaint was generated due to a "bounced email message warning" that we return. That's what the "report to Sender" subject line is.
We use the bounce replies to let valid users know that their mail did not reach the recipient.
I wonder if it's time for our company to stop sending bounce replies. This is not a decision I can make in a vacuum. Anybody have opinions on this?
-------------------------------------------------------------------------------------
Don,
In an nutshell, I think this is crap. The complaint that is referenced below was not from a spam email. Unless you consider a bounced reply message spam.
Our business-purpose email server sends about 50,000 messages a day from caci.com employees.
I just checked through our mail logs. On Sunday, there was one message sent to nicar.org (johnmiller[at]nasw.org).
The message sent was a bounce reply (from our internal Notes smtp server, 10,11.4.62) to an email sent to a bad recepient at caci.com.
Our bounce replies are sent from cacimta/caci[at]caci.com so I can tell this from the logs.
I suspect this is the makings of the MyDoom virus. As we know, an infected pc can craft an email from johnmiller[at]nasw.org and send it to baduser[at]caci.com Our email server will reply to the spoofed from address and say baduser[at]caci.com does not exist.
That is probably what happened here below. If you look at your spamcop logs on your site, you'll notice a sizable peak of complaints right about when the mydoom virus was unleashed. Coincidence? I think not.
How can we avoid being blacklisted in the future? Is this gonna force us to turn off our bounce replies ? Most of our dealings are with military customers. We'd prefer to let them know if an email has bounced. However, we can't afford to get blacklisted.
So we got a whole total of TWO COMPLAINTS and you blacklisted us!!!! Who verifies that these complaints are legitimate?? Why would you blacklist someone for 2 complaints? I realize you are trying to help rid the world of spam, but in the process you have screwed us.
Do you have any other copies of the complaints that were directed about 204.194.72.241? This one is obviously bogus. I'd like to track down the "supposed" others.
PS. I'd cc johnmiller[at]nasw.org on this reply, but I'm scared we might get blacklisted again. PLEASE FEEL FREE TO FORWARD THIS EMAIL TO THE USER WHO COMPLAINED. My phone number is below if he/she would like to call me.
- paul
Paul Gordon,
Information Technology Scientist,
CISSP, CISM, CCNA, CCNP Routing,
CIS Network Operations Manager
CACI - Federal
1100 North Glebe Road
Arlington, VA 22201
703-841-4039
Here is a trail of logs from our mailserver.
-rw-r--r-- 1 logger system 11863001 Feb 3 02:05 smtpo.log.ends20040202mailserver1.caci.com.gz
cpmrsdb1.hq.caci.com[8]:gzip -d smtpo.log.ends20040202mailserver1.caci.com.gz
cpmrsdb1.hq.caci.com[9]:grep -i nicar.org smtpo.log.ends20040202mailserver1.caci.com
325946:10:1:02012004 08:26:18:Lookup Returned. Data = <(0, 'svr1.nicar.org')>, Type = <MX>
325946:10:1:02012004 08:26:18:Lookup Returned <[(0, 'svr1.nicar.org', ('128.206.143.228',))]>.
325946:10:1:02012004 08:26:18:Connecting to MX <svr1.nicar.org> ....
325946:10:1:02012004 08:26:27:reply: '220 svr1.nicar.org ESMTP Sendmail 8.12.10/8.12.10; Sun, 1 Feb 2004 13:26:27 GMT'
325946:10:1:02012004 08:26:27:reply: '250-svr1.nicar.org Hello mailserver1.caci.com [204.194.72.241], pleased to meet you\r\n250-ENHANCEDSTATUSCODES\r\n250-PIPELINING\r\n250-EXPN\r\n250-VERB\r\n250-8BITMIME\r\n250-SIZE\r\n250-DSN\r\n250-ETRN\r\n250-DELIVERBY\r\n250 HELP'
325946:10:1:02012004 08:26:39:reply: '221 2.0.0 svr1.nicar.org closing connection'
cpmrsdb1.hq.caci.com[10]:grep -i 325946:10:1:02012004 smtpo.log.ends20040202mailserver1.caci.com
325946:10:1:02012004 08:26:18:Lookup Returned. Data = <(0, 'svr1.nicar.org')>, Type = <MX>
325946:10:1:02012004 08:26:18:Lookup Returned <[(0, 'svr1.nicar.org', ('128.206.143.228',))]>.
325946:10:1:02012004 08:26:18:Connecting to MX <svr1.nicar.org> ....
325946:10:1:02012004 08:26:27:reply: '220 svr1.nicar.org ESMTP Sendmail 8.12.10/8.12.10; Sun, 1 Feb 2004 13:26:27 GMT'
325946:10:1:02012004 08:26:27:reply: '250-svr1.nicar.org Hello mailserver1.caci.com [204.194.72.241], pleased to meet you\r\n250-ENHANCEDSTATUSCODES\r\n250-PIPELINING\r\n250-EXPN\r\n250-VERB\r\n250-8BITMIME\r\n250-SIZE\r\n250-DSN\r\n250-ETRN\r\n250-DELIVERBY\r\n250 HELP'
325946:10:1:02012004 08:26:39:reply: '221 2.0.0 svr1.nicar.org closing connection'
cpmrsdb1.hq.caci.com[10]:grep 325946:10:1:02012004 smtpo.log.ends20040202mailserver1.caci.com
325946:10:1:02012004 08:26:18:Starting to process for domain <nasw.org> and msgids <[30680808]>
325946:10:1:02012004 08:26:18:Processing nasw.org
325946:10:1:02012004 08:26:18:Lookup Returned. Data = <(0, 'svr1.nicar.org')>, Type = <MX>
325946:10:1:02012004 08:26:18:Lookup Returned <[(0, 'svr1.nicar.org', ('128.206.143.228',))]>.
325946:10:1:02012004 08:26:18:Connecting to Domain nasw.org
325946:10:1:02012004 08:26:18:Block time out set to = (300) seconds.
325946:10:1:02012004 08:26:18:Connecting to MX <svr1.nicar.org> ....
325946:10:1:02012004 08:26:18:Connecting to A <128.206.143.228> ....
325946:10:1:02012004 08:26:27:reply: '220 svr1.nicar.org ESMTP Sendmail 8.12.10/8.12.10; Sun, 1 Feb 2004 13:26:27 GMT'
325946:10:1:02012004 08:26:27:Connection Status ------<1>
325946:10:1:02012004 08:26:27:reply: '250-svr1.nicar.org Hello mailserver1.caci.com [204.194.72.241], pleased to meet you\r\n250-ENHANCEDSTATUSCODES\r\n250-PIPELINING\r\n250-EXPN\r\n250-VERB\r\n250-8BITMIME\r\n250-SIZE\r\n250-DSN\r\n250-ETRN\r\n250-DELIVERBY\r\n250 HELP'
325946:10:1:02012004 08:26:27:Starting SendSmtpMsg for msg_id <30680808> in domain <nasw.org>
325946:10:1:02012004 08:26:27:Sendmail Begin from : cacimta/caci[at]caci.com
325946:10:1:02012004 08:26:27:Sending MAIL FROM: <cacimta/caci[at]caci.com> size=707
325946:10:1:02012004 08:26:28:reply: '250 2.1.0 <cacimta/caci[at]caci.com>... Sender ok'
325946:10:1:02012004 08:26:28:Sending RCPT TO: <johnmiller[at]nasw.org>
325946:10:1:02012004 08:26:28:reply: '250 2.1.5 <johnmiller[at]nasw.org>... Recipient ok'
325946:10:1:02012004 08:26:28:Sending DATA
325946:10:1:02012004 08:26:28:reply: '354 Enter mail, end with "." on a line by itself'
325946:10:1:02012004 08:26:28:RETR COMMAND RECEIVED ('/ct/data/mss/00/03/06/80/810',)
325946:10:1:02012004 08:26:39:reply: '250 2.0.0 i11DQQYJ010374 Message accepted for delivery'
325946:10:1:02012004 08:26:39:LOG_STAT|cacimta/caci[at]caci.com|['johnmiller[at]nasw.org']|707|2004/02/01 08:26:39|0
325946:10:1:02012004 08:26:39:Sending RSET
325946:10:1:02012004 08:26:39:reply: '250 2.0.0 Reset state'
325946:10:1:02012004 08:26:39:Closing SMTP Connection
325946:10:1:02012004 08:26:39:reply: '221 2.0.0 svr1.nicar.org closing connection'
325946:10:1:02012004 08:26:39:Finished to process for domain <nasw.org> and msgids <[30680808]>
SpamCop Admin <service[at]admin.spamcop.net>
02/03/2004 12:25 AM
To
Paul Gordon <pgordon[at]caci.com>
cc
bl[at]admin.spamcop.net, CIS Network <CIS_Network[at]caci.com>
Subject
Re: why is 204.194.72.241 listed as blackholed?
Paul Gordon writes:
>One of our users recently received an email that our main mail server,
>204.194.72.241 or mailserver1.caci.com, was being blacklisted by
>blacklist.bl.spamcop.net.
204.194.72.241 has been sending spam to our users and to our
spamtraps. Not a lot, but enough to get it listed. The spam appears to
have stopped about 24 hours ago. The server will automatically come off
our list 48 hours after the last complaint came in.
http://www.spamcop.net/sc?id=z278998573z25...05be1ca647c284zYou can use that link to review the headers from the recent user
complaint. The complaint was sent to postmaster[at]caci.com
http://www.spamcop.net/w3m?action=checkblo...=204.194.72.241- Don -