  1. Hi Clive, Bad news indeed. But the spambots seldom retain any particular spoofed sender address for long (unless you have REALLY upset someone) - that is counter-productive for them. Being a spoofed sender is usually fairly rare and truly random. But even random rare occurrences can (even more rarely) recur in close succession - or maybe there have been inbuilt delays for retry attempts as used by some networks. The idea of reporting misdirected bounces is to educate the errant postmasters doing that bouncing. One way or another the situation does seem to have actually improved over the years. E-mail providers, depending on their resources, are able to filter out incoming misdirected non-delivery notices - perhaps that is the real reason for the general improvement, but education may have something to do with it as well. People with the bandwidth (and lack of flood control) used to get thousands of bounces an hour to the spoofed sender/return address for a few days. That doesn't happen any more. If you use e-mail submissions for reporting, you can send whole batches of them in each submission which streamlines the process. Since analysis of the bounce message body is pointless, "Quick" reporting might be a useful further streamlining option - but note there are risks of reporting your own provider if your network configuration changes unexpectedly. I see veronyka.co.ua is listed in the SURBL (real-time URI blacklists), which is probably one of the reasons for the reliance on "shortening" services. It will surely appear on other lists and reputation alerts as well (but not on the URIBL, the shortening services are working well in protecting that "spamvertized" website). Anyway, you can contribute to some of those lists and alerts since you possess evidence, even if it is not "your" spam directly. Also, some of those shortening services are amenable to complaints and will block attempts to abuse their services, Unfortunately bounce reporting doesn't involve content analysis of the original spam, that is something to be addressed, if at, outside of the SC reporting system. Those are some things to consider if it persists unreasonably - but for most it does not last long (it just SEEMS like an outrageously long time while it is happening).
    Commercial 'search' spam?

    In any event, I'm unsure if our members http://forum.spamcop.net/forums/user/2593-c2h5oh/ and http://forum.spamcop.net/forums/user/2984-137-trimethylxanthin/ have been alerted to any requirement for their propinquity.
    Report email rejected by someone

    Sounds like they're hitting anything with "spam" in it, so a fair bet the service[at]admin.spamcop,net would be blocked too - that is a domain but so is your "submit" address. Worth trying though. If that doesn't work either then I or someone else here will contact Don and alert him, maybe you can work out something between you. Sheesh, providers! - and we thought spammers were dumb ...
    Report email rejected by someone

    Sounds awfully like your provider/network has started filtering your outgoing. As has happened to many of us . Write to Don D'Minion with your reporting account detail and full copy of that bounce to see whether he can determine what is happening - spamcop[at]spro.net
    Commercial 'search' spam?

    The most visible tracks of the beast - http://research.google.com/pubs/DataMining.html Not just Google of course, Google is just (arguably) the most open (and openly mines e-mail as well as search-engine queries and some browser history). Depending how you define it, AI is up and running - neural networks accessing and digesting databases of almost unimaginable size, finding associations and "patterns" without mind or mentation, merely probability distributions for filters and some simple rules for discrimination. None of which should "out" e-mail addresses for commercial exploitation by third parties. Study the privacy policies of the enterprises you deal with and jump all over them if there is any evidence of a data breach (it might even be inadvertent and they might be grateful for the 'heads up' - well, pigs might fly too, though in a slightly different universe). Welcome to the 21st century. It took a long time and much anticipation but the future is finally here. Unfortunately, the most potent general driver of innovation and 'progress' remains the same as it always was - greed. Guess I'd best lay off on the 1,3,7-trimethylxanthine and resume the meds ...
    Latest Dumb spam

    Different forums, different fleas. That IP address (iliad-entreprises.fr/poneytelecom.eu) not banned "here", no cause - well, probable cause maybe - but the registration e-mail domain (once) a different matter. Latest IP banned "here" (an IP address range) is (193.201.224.*), part of Alpha-Telecom-NET (UA), due to continuing use by a reputed spammer - and no regular members (just 1/27 unbanned and that "he" is a 'known spammer' as well) - using a variety of aliases and credentials, ever since the last implementation of this forum. That one likes to register with an account from any of the major free e-mail providers and seems to be into scraping this board, not spamming it as such (so no reportable activity here). In time he will go away/find new proxies and I can lift the restriction. Or maybe not - it is a spectacularly abused range, the owners must be complicit or dead. But goodness knows what exactly that spammer/associate has been doing here and why for the past several months (collecting the phoney backlink stats that SEO agencies use to bill their clueless clients, maybe?) but frustrating the ungodly is a duty gladly undertaken by the ... erm ... not so ungodly
    Latest Dumb spam

    Priceless - spamkiller spam served with a straight face/no evident conception of irony. That user-registration e-mail domain was the first ever banned on these forums, back in early 2006. With the evolution of spammer methods (and of counter-spam resources to match) we should probably reconsider that restriction for this forum. Can't see that the domain is currently particularly "toxic", whatever the situation might have been more than eight years ago. Anyway, it is possibly better to allow instances of spam and remove/keep it from public view so to authoritatively report the perpetrators' credentials for subsequent alerts to the wider internet community about current spam "campaigns" (exactly as you have done). That would/should be more effective in limiting the (supposed) profits of spam and its proliferation than will simple denial on an individual, isolated forum/bulletin board basis. Will consider ...
  8. E-mail Richard W at deputies[at]admin.spamcop.net to see if he can help with your forwarding problems.
  9. Are you saying you still have not received the e-mail from SC Admin at your registered address for your reporting account? (Only you and SC Admin know that address, do not reveal it here in public.) Have you followed the link on the form as posted above? Have you tried to contact SC Admin at spamcop[at]spro.net? You might like to use the "Follow this topic" link to be notified of further responses to your query in this topic.
    My turn in the barrel

    Yes, this forum has seen a bit of a surge in the past 24 hours or so. Some commentary suggests increased activity from the Russian Federation and the Ukraine but not seeing any pattern changes myself - just a bit more of it, so far. Origins, including "banned" at registration (which most of them are): Country CIDR Australia Canada Canada China France France,, France France France France France Germany Germany Germany,,, Pakistan Russian Federation Russian Federation Russian Federation Russian Federation Turkey Ukraine Ukraine Ukraine Ukraine Ukraine Ukraine, USA - California USA - California USA - Illinois USA - Kansas,,, USA - Missouri USA - Missouri USA - Nevada, USA - Pennsylvania USA - Texas USA - Utah
  11. And it is listed again. https://www.spamcop.net/w3m?action=checkblock&ip= Currently, As can be seen - it slips in and out of the BL, depending on reports received, The idiot owners tried to de-list it without stopping the spam so now they are not trusted to "express-delist", they must wait for the full time to expire.
  12. Good idea - it is my impression that the client was the problem, outlook.com webmail was then hotmail and never "in the frame" as far as the curiously variable mangling of the "Received:" header sequencing goes, which was/is at the heart of the Outlook client problem. Outlook Express was never implicated either.
  14. Nothing relevant in the Email Error Logs - Don's notices should have gone out OK.
  15. Hi Pavel. Only SC staff can view that spam from the report ID links you provide (you would need to post Tracking URLs if you wanted the general membership to see what it is you are discussing). However, you can retrieve the reporting history for any IP address* (last 90 days) by pasting the address into the submission window in your member's page, hitting "Process spam" then selecting the "[report history]" link from the resulting display - and select "Last 90 days" for all the data. That will give you an idea of how many others are reporting that address. Alternatively, you can "drill down" through the IPv4 netspace map at https://members.spamcop.net/w3m?action=map to successive levels of detail. As noted in the link about what is on the SC BL indicated by Steve T, an address can pump out a lot of spam but if it also handles a much greater amount of real e-mail it is unlikely to be listed through reporter action alone. * (if you are a paying reporter)
  16. Hi Schmide, Haven't heard of a (properly constructed) header breaking the parser before. Does that mean the parser page does not display a tracking URL (up near the head of the parse) before you dismiss it? If it does you could copy that and paste it here, even though no reports are generated and the reference is not recoverable from your report history. What errors does the parser bleat? Are you "pasting in" the spam in the submission form or e-mailing? First thought is this could be a mangling introduced by the tools used in whichever submission method (supposing paste in given Yahoo problems with forwarding attachments).
  17. Well, that's good news, thanks for passing it on. Although apparently not COMPLETELY so, marking this topic resolved.
    Thank you Elves and Gnomes

    Haven't changed browsers/browser settings/cookie management have you? Can't actually "see" the kind of changes that might change the board behaviour (no permissions at all in those areas) but I would anyway have to depreciate board change as a likely cause (and, like, good luck with Chrome, come what may). But of course possible. And your generous spirit is much appreciated
  19. ... Fortunately it was kind of short, but what if a spam has a big bunch of attachments -- won't the source be so big it won't fit into the text field? I remember reading somewhere that the text field has a limit, and there's also a limit to the Email size, but it's a lot bigger. ... __________________________________________________________________________________________ In addition to what Steve T has said, it is permissible to truncate the body of a spam submission. You can even eliminate it entirely (but you have to have something there - the parser looks for at least a blank line following the headers, then some following content, even if it is just your own note, such as "spam body removed"). That might also save on fuel, if you are a paying reporter.
  20. Thanks, that's progress. When providers filter spam (filtering both inwards and outwards) there will be a lag in recognition - thus they let in more than they let out. The shorter the interval between receiving it and reporting it, the better the chance of getting it through, one imagines. When I used to get lots of spam (and with the sort of filtering my provider was doing) I found they weren't quite so smart in picking up multiple spam submissions - that is one submission with multiple spam attached. Alternatively making the FIRST attachment non-spam seemed to work (if it was an old e-mail the parser wouldn't process reports for it so don't even need to cancel). An unnecessary botheration of electrons, but they make us do such things, our lame and limited service providers.
  21. Hi jasmith, sorry to hear of your problems. This topic belongs in the "Reporting help" section I think, Wazoo's diagnostic might be worth looking at - http://forum.spamcop.net/forums/topic/1848-emailed-spam-submissions-disappearing/ It seems to me that the incidence of providers silently filtering submissions (on the grounds that they contain spam ... duh!) has been steadily increasing. A quick and painless test would be to try submitting a non-spam email. Just be sure to CANCEL the report if it does get through. If it doesn't, you need further help. If it does get through, you probably have an issue with Comcast, Will move the topic to that other section shortly.
    Hmmm ... softlayer,com hosting (mentioned earlier above) - https://www.spamcop.net/sc?id=z6022803755z675f6f7f0149e72fb6e07ccf7f700a84z - used by flipmailer.com in some pseudo "social networking" spam malarky. Social? I'm barely civil, where did they get my detail? When I go to SenderScore.org (need an account - free - to get full detail) I see softlayer is only the tip of the iceberg, the flipmailer junk is going through at least 296 servers in many different networks in some sort of concerted way (despite softlayer hosting the designated MX servers - 10 of them - in DNS records). Maybe the same or similar in the NameCheap case which is the subject of the discussion. We know about snow-shoeing but that is ridiculous! I fear the myrmidons of spamdom may have hit upon a new and infinitely vile "paradigm" for the distribution of their feculence.
  23. Are you actually using the quick submission address bairhair, like quick.somecode[at]spam.spamcop.net, or the "ordinary" submission address, like submit.some code[at]spam.spamcop.net? IIUC you can't use both (or at least you can't use quick reporting without it being enabled). Unless something has recently changed at Comcast, you may need to enlist the help of SC admin or deputies to look at it for you (deputies[at]admin.spamcop.net). They would need your reporting account name (don't post it here), and probably your submission address (ditto, don't post it here). The "... less than 10% of what I forward is making it through ..." is a bit weird - would expect all or nothing if there has been no change in the transmission. Probably best if you read through Wazoo's diagnostic first which I will link as soon as I find it. Ah yes: http://forum.spamcop.net/forums/topic/1848-emailed-spam-submissions-disappearing/
  24. Many thanks Richard - marked "Resolved" so others can find the procedure to progress from the dreaded "... appears to traverse more than one domain." auto response.
    SC Contacts

    Great - thanks Richard.