  1. On 10/25/2018 at 10:26 PM, petzl said:

    While good advice if you must sign into "dodgy" sties use a throwaway email address with a different password! This spammer is attacking my SpamCop email address so like all spammers is lying. I never use my SpamCop email except to friends (whose computers have been hacked email addies scrapped)

    I was thinking about that.

    Anyway. The mail used in spamcop is the one to receive surveys from a company we work with my shop, prices list from that company where we work to sell in the shop, and few more i dont remember i will need to check and migrate to another place.

  2. On 10/23/2018 at 3:08 PM, Lking said:

    CaLy think you for trying, however, you did not provide the correct link. If you look at the end of the URL you posted you will se "reportid=xxxxxxxxxx"  Looking at petzl's you will see "?id=...." followed by a long code; That is a Tracking URL The tracking URL is near the top of the screen when you report an email OR in the email you receive from SpamCop when you submit spam by email.

    Sorry, i reported the last one well, i think.


  3. Hello !

    Since 3 days ago i received 3 times the mail with text

    I'm a hacker who cracked your email and device a few months ago.
    You entered a password on one of the sites you visited, and I intercepted it.
    This is your password blablabla

    and its weird because the password gave there is the one i used the 1st time i registered the email.

    I changed the passwords several times, and i got this email again , as i said, and it says to send money to a bitcoin address wich of course i will NOT do that.

    I contacted support of that email i have, and they said to forget about it , the email server is secure and blablabla.

    The other parts of the mails says:

    	Of course you can will change it, or already changed it.
    But it doesn't matter, my malware updated it every time.
    Do not try to contact me or find me, it is impossible, since I sent you an email from your account.

    I submited 2 . and it says it was reported to two postmasters. What else should I do? copy the email address and report to them again? 

    or just let spamcop do the rest?

    Thank you and have a nice week in advance!


  4. Thanks for the reply turetzsr ...

    I have downloaded one mail received today...

    Can I show you the complete mail with header?

    I mean not in here or message, just through a pastebin link or whatever ... and not in public (here), of course...

    Also, i remember some time ago i checked in some database to check spam database or something like that... my isp was in the opened ports ISPs, so i am afraid the problem can be because of that.

    Thanks and have a nice weekend in advance!

  5. Hello !

    I am Carlos Octavio, from Rosario (Argentina) ...

    My ISP is Arnet (arnet.com.ar) , i have my email there but i am migrating to another one, because i have problems with that account... And I want to know why it´s that... if it´s me, or if it´s related to my ISP.

    Everyday i have a lot of mails (like 100 or more, sometimes 300+) with mailer daemon fail message, something like

    The following message to blabla[at]bla.com was undeliverable.

    The reason for the problem:

    5.3.0 - Other mail system problem 550-'5.7.1 Message rejected as spam by Content Filtering.'


    This is an automatically generated Delivery Status Notification



    Delivery to the following recipient has been delayed:


    Message will be retried for 2 more day(s)

    ----- Original message -----


    The fact is i NEVER sent that message/s ...

    in headers it says it was my email the sender, but i dont have them in the sent messages ... so:

    is it related to my isp opened port 25, or ... what?

    Thanks !!

    Carlos Octavio

  6. Hello, i am Carlos Octavio, from Rosario / Argentina.

    I recently purged my primary email from my isp (it is [at]arnet.com.ar) where i had +15000 messages, and i cleaned it all with PopCorn.

    Now, it is clean/empty and i started to use it with pop3 program again (The Bat, if it matters).

    Well, i started to report again messages received in that account and since November 26, i reported like 20 mails total.

    The fact is: some of the mails are not directly to me, for example:

    From: Carla<can78[at]fullzero.com.ar>
    To: calvinhorobotti[at]arnet.com.ar

    That mail calvin... is not mine, but it comes to me.

    I can make a rule in The Bat telling if the mail dont have my address in "To" will be deleted instantly, right?

    And another "question".

    A lot (or all) of the spams reported to Spamcop have the same abuse contact: abuse[at]iplan.com.ar

    So, if the abuse or abuse-contact is that, it appears like iplan.com.ar have their port 25 opened to anyone to send mails through there, right ?

    And i also checked in :

    http://www.spamhaus.org/security/cookies.l...sp=arnet.com.ar (MY ISP) and it says:

    SBL56730 arnet.com.ar

    18-Jul-2007 08:26 GMT Malware hosting


    Do i need to do something about that? I mean, it is the isp i am using :S

    O well, and about iplan.com.ar it says: Found 18 SBL listings for IPs under the responsibility of iplan.com.ar

    Tell me please, if i need to do something, or just stay like i am.

    Thanks in advance.

    Carlos Octavio

  7. Hello, i am running as trial the Mailwasher so i can see the incoming mails before downloading them.I have adsl connection, so it is not a problem to download a big number but anyway, i am tired of this kind of mails. Always porn, always the same.

    I reported them through Spamcop and going to dnsstuff and getting the mail addresses but some fails, like the abuse of att.com email, and others. (I mean they are not valid).

    I reported few ones today from spamcop site (not the 140 i received). But in fact, even if i report, if i unsubscribe, i am STILL receiving same emails, from a lot of diff addresses.

    I wonder if in any way there is a possibility of stop them but without changing my mail address. Because:

    my mail address is my username on the isp i am using, and its the same user as on the webspace, and i am using this space of webhosting in something important. What u think?

    U can see it by yourself here:

    Moderator Edit: No you can't directly. Admin has chosen to 'break' this URL, due to the construct and content of this provided link .... linking to an off-site image is one thing, running that link with codes is another, and not allowed in here.

    ht tp:// Serv1. ima gehigh. com/view.php? id =229 79_spam.jpg& path =/im gs//ih000001

    ht tp:// Se rv1.image hi gh.com/imgs/ih000 001/229 79_spam.th.jpg

    Example of one i received:

    Received: from qsmtp-mx-06 ([]) by BE-EXCH-01.ti.local with Microsoft SMTPSVC(5.0.2195.6713);

    Tue, 27 Jun 2006 12:35:24 -0300

    Received: from unknown (HELO (

    by qsmtp-mx-06.arnet.net.ar with SMTP; 27 Jun 2006 15:30:18 -0000

    Received: from dilatory [] (helo=melon.tidy.dearriba.com)

    by smtp2.cistron.nl with esmtp (done 3.35 #1 (geodesy))

    id 184LFL-0081PT-49

    Message-ID: <46080483144732.R37499[at]gunflint.noc.quadrillion.gr>

    Sender: freeradius-devel-KEVTFXJIVHZL[at]taxfreewarehouse.com

    X-Mailman-Version: 2.0.1

    Date: Tue, 27 Jun 2006 17:25:10 +0100

    From: "Benito Oliver" <KEVTFXJIVHZL[at]taxfreewarehouse.com>

    To: carlosnob[at]arnet.com.ar

    Subject: Fwd: important

    Return-Path: KEVTFXJIVHZL[at]taxfreewarehouse.com

    X-OriginalArrivalTime: 27 Jun 2006 15:35:24.0184 (UTC) FILETIME=[4EA5D980:01C699FF]

    Sensationall revoolution in medicine!

    E''nlarge your p''enis up to 10 cm or up to 4 inches!

    Its h'erbal solution what hasnt side effect, but has 100% guaranted results!

    Dont lose your chance and but know wihtout doubts, you will be impressed with results!

    Clisk here: http://irecordslink.info

    To who i will report, if i want to report manually?

    Ah BTW , the TO is NOT my address.

    I need to report to this IPs abuse addresses?

    Received: from unknown (HELO ( (to them?)

    Received: from dilatory [] (helo=melon.tidy.dearriba.com) (to them?)

    by smtp2.cistron.nl > To them?

    And to the domain abuse or registrar contact?