Our true addresses are being embedded in the first "Received" line, as follows:
QUOTE
Received: from name.of.connection.to.web.server
(name.of.connection.to.web.server [IP# of connection]) by
webmail.spamcop.net (Horde) with HTTP for
<mytrueaddress@spamcop.net[at]cesmail.net>; Sat, 03 Mar 2007 15:01:59 -0700
(name.of.connection.to.web.server [IP# of connection]) by
webmail.spamcop.net (Horde) with HTTP for
<mytrueaddress@spamcop.net[at]cesmail.net>; Sat, 03 Mar 2007 15:01:59 -0700
(I've put the munged variables in green, for clarity, and the "spamcop.net" can be either that or "cesmail.net" or "cqmail.net" depending upon which SC email domain hosts your address. Also the forum software substituted "[at]" for the "@" before cesmail.net)
Even though the address is somewhat mangled in that there's an additional "@cesmail.net" appended, it's still going out in headers and I don't think that's good or necessary. The potential problem is that our address is being revealed without our consent or control and is then subject to the potential problems found on all of the other machines/networks that receive the messages we send (botnets, harvesting/spamming worms, etc.).
No wonder I now receive spams directly at my spamcop.net address! I thought it was due to some other security breech, but it's probably due to the messages I've sent out using webmail. I haven't found mention of this anywhere else yet, so if anyone can find such mention, I'd be interested. I don't think this should be happening. I think that we need to ask JT to alter the mail server so that it doesn't add our actual addresses to the Received headers.
DT
