  1. I received another one (with 18 messages inside !!!). Is there a way to change my submitting email address (the one like submit.XXXXXXXXXX@spam.spamcop.net) without having to create a new account and delete the old one ?
  2. Although it could originate from the same person (if my submitting email address have been compromised), I think this problem could be a different one …
  3. Actually it is like if someone had taken my submitting email address and submitting spams on my behalf ... Could a spammer be vicious enough to do that ?
  4. Here is all five ones for the last wrong message that I received today at 14:13 CEST (France) : https://www.spamcop.net/sc?id=z6708034972zfd55febd84fb1cbd66e982f252c3ddf3z https://www.spamcop.net/sc?id=z6708034973zaa15011cff947eefd65aaf5f2af26523z https://www.spamcop.net/sc?id=z6708034974z7fff06613177fa351c546cb0cafe6329z https://www.spamcop.net/sc?id=z6708034975z8f47aee91b0584734e709ebc586bacfbz https://www.spamcop.net/sc?id=z6708034976zfe17294606aa89171417a2d879782523z
  5. Just received another one. Along with quite long mail with subject "[SpamCop] Errors encountered" and beginning with : Gingko
  6. Hello, Since yesterday I have a strange problem : I recurrently (… ahem … at least twice so far) receive spam confirmation emails where all message, when I want to "finish spam reporting" for them, display "Mailhost configuration problem, identified internal IP as source / Mailhost: / Please correct this situation - register every email address where you receive spam". I know how to proceed with "Mailhost configuration problem". Normally. But this also corresponds to messages that I actually never submitted. True for all messages in the same confirmation mail. Is it possible that there would be a bug mismatching confirmation messages, or their submitted spams themselves, between users? Regards, Gingko
    Spams received already outdated

    In the meantime, I sorted all the spams that I received from this "spam cluster" (that I identified as part of the same group by several common features). I have 158 spams so far, starting January 9th, incoming in two mailboxes hosted by the same ISP. They are coming from 10 different sources, the most active being : ncdhost.com (43 spams) hopone.net (41 spams) dacentec.com (23 spams) ni.net.tr (16 spams) The six others (datashack.net, heymman.com, layer6.net, uaservers.net, vernet.lv, wholesaleinternet.net) have less messages, and sometimes lasted only for a short period, meaning that the spammer can already having been shutted down by this hosting service. I could eventually forward all of them to their respective senders, but does it worth the attempt? Gingko
    One more thing about these spams: Although it is difficult to completely verify, I have some reasons to think that some of these spams, received once by SFR, could have be handled internally by SFR and distributed more than once to the recipient at random intervals. I receive many of these spams several times with identical contents, like if they would come back after having been completely deleted from the mailbox. After reporting, they could sometimes have been seen as duplicated reports. And if I look at my past reports history ( https://members.spamcop.net/mcgi?action=showhistory ), I can see that about half of them have been handled as "No reports filed" by Spamcop, without any more explanation. Gingko
    I don't understand. Where should I forward this if it is not to Spamcop? I hope you are not telling me to forward directly to the spammer or to some hosting service related to it? Gingko
    The ISP has be contacted by many angry users (not by me yet) for several weeks, and they only give hackneyed answers like "we are working on it" (for weeks !). About tracking URL, ok, so you are speaking about URLs specifics to a particular spam as it changes for each spam. For the quoted headers above, the tracking URL is https://www.spamcop.net/sc?id=z6611133626z038eafa006f7aed4232b8a0c6617a97az And NO, if I look at the headers of some regular mails, they do NOT go through front26-smtp-dirty.sfrmc.priv.atos.fr. Gingko
    Here is the header's of a typical spam that I received that way : You can see that the spam was sent on January 20th at 20:29 CET, but I received it today 13:59 CET. There is a "Received:" line for that, but SpamCop ignore them as the three last "Received:" lines are internal handling from the receiving ISP declared in the mailhosts setup … thus this internal handling is spanning 5 days ! A large part of the spams that I receive on this address has this huge internal handling time property. And this concerns only spam. Regular messages that I send to myself to the same address are delivered in a matter of seconds. Gingko
    Ahem… Of course, yes, but… What are you calling “A tracking URL”, and how could it be useful, especially in this case?
  13. Hello, I have a problem that for about two week, I have two mailbox (hosted by the same operator) which are flooded by spam having weird characteristics : Most of the received messages are already outdated, meaning that if I use Spamcop for reporting them, they are rejected because they are more than 2 days old, despite the fact that I submit them as soon as they are received. If I delete them from the mailbox, it happens quite often that they come back a few hours later, like if I never deleted them. All of these spams originates (apparently of course as these sender address are always fake) for me (it may be different for other users) from only 3 different mailboxes : 1 - Info@taobao.com 2 - mailer-daemon@amazon.com 3 - mailer-daemon@sourceforge.net All of this suggests that the operator itself could be involved in this situation. I'm not the only one having this problem, actually there is a large topic (38 pages so far) from the community forum of this operator where many users are complaining about the same problem : https://forum.sfr.fr/t5/votre-messagerie-sfr-mail/mail-suspect-reçu-de-ma-propre-adresse-mail-et-nombreux-spams/td-p/2164708 The hosting operator is not less than SFR, which is one of the 4 main telephony and Internet operators on the French territory. For me, this lasts since January 9th, and I got about 140 spams that way, so far. But for other users, this seems to be older. I would like to know what you think about that as I fear this is likely to defeat the Spamcop system. Regards, Gingko
  14. You are right. I tried it, it works. Although I don't understand very well why : is really pop-fr.libertysurf.net. Gingko.
  15. Hello, I have a similar problem on this message, and all messages coming from the same provider using fetchmail. The only workaround that I found is stripping "Received" headers until the fetchmail's one, and I'm not sure that this is really welcomed .... Gingko.