Jonathon Gumbley Posted April 13, 2004 Share Posted April 13, 2004 Hi there. I have just been informed that my company has been listed in your list of possible spamming servers. I have checked our mail server and our MailMarshal server and we are not open relay and not forwarding any non-local email domains. Can you please remove mail.o-business.co.nz internet address = 210.54.16.178 from your list. Thank you Jonathon Gumbley - MCSE CCA Project Manager Origin Business Solutions Origin Business Park A1, 8 Saturn Place Albany, Auckland Phone: +64 9 414 2350 Fax: +64 9 414 2351 Tech Support: +64 9 414 2354 Website: www.o-business.co.nz Link to comment Share on other sites More sharing options...
Wazoo Posted April 13, 2004 Share Posted April 13, 2004 Parsing input: 210.54.16.178 host 210.54.16.178 = adsl-210.54.16.178.quicksilver.net.nz (cached) Reporting addresses: ks61[at]netgate.net.nz dbk1[at]netgate.net.nz Any idea who either of these folks might be? This is where any spam complaint reports would have gone, if they went out. In theory, one or both of these indivuduyals would have the actual reason behind the reports. But wondering why there's not an actual "abuse" address identified (and secondarily, have "you" registered with abuse.net?) we are not open relay and not forwarding any non-local email domains The next thing to check afyer these obvious items usually turns out to be the firewall logs to find out which machine behind the router/mail server/ etc. has been compromised. Or, owrst case, you're unning one of the wonderful Microsoft products and you're way behind the security issues or you have weak / default / non-existent passwords on some of the admin accounts. So for starters, have you yet gone through the (work in progress) FAQ found at http://forum.spamcop.net/forums/index.php?showtopic=972 ? Are there issues there that aren't yet covered that may answer your next query? Link to comment Share on other sites More sharing options...
Merlyn Posted April 13, 2004 Share Posted April 13, 2004 Hi there. I have just been informed that my company has been listed in your list of possible spamming servers. I have checked our mail server and our MailMarshal server and we are not open relay and not forwarding any non-local email domains. Can you please remove mail.o-business.co.nz internet address = 210.54.16.178 from your list. Thank you Jonathon Gumbley - MCSE CCA Project Manager Origin Business Solutions Origin Business Park A1, 8 Saturn Place Albany, Auckland Phone: +64 9 414 2350 Fax: +64 9 414 2351 Tech Support: +64 9 414 2354 Website: www.o-business.co.nz Your company has not been listed and Spamcop is not a list of open relays. The IP address of a server possibly the one your company uses or shares has been placed on the Spamcop blocklist because people have reported it for sending them spam that they have not requested. You should check your server logs for a spammer or check for virus/trojaned machines on your network. The good part is the IP will be delisted 48 hours from the last spam report. Link to comment Share on other sites More sharing options...
Jonathon Gumbley Posted April 13, 2004 Author Share Posted April 13, 2004 Parsing input: 210.54.16.178 host 210.54.16.178 = adsl-210.54.16.178.quicksilver.net.nz (cached) Reporting addresses: ks61[at]netgate.net.nz dbk1[at]netgate.net.nz Any idea who either of these folks might be? This is where any spam complaint reports would have gone, if they went out. In theory, one or both of these indivuduyals would have the actual reason behind the reports. But wondering why there's not an actual "abuse" address identified (and secondarily, have "you" registered with abuse.net?) we are not open relay and not forwarding any non-local email domains The next thing to check afyer these obvious items usually turns out to be the firewall logs to find out which machine behind the router/mail server/ etc. has been compromised. Or, owrst case, you're unning one of the wonderful Microsoft products and you're way behind the security issues or you have weak / default / non-existent passwords on some of the admin accounts. So for starters, have you yet gone through the (work in progress) FAQ found at http://forum.spamcop.net/forums/index.php?showtopic=972 ? Are there issues there that aren't yet covered that may answer your next query? I have tracked those hosts to Telecom NZ, Netgate.net.nz is Telecom NZ's ADSL network. I have contacted them and should find out who, when and what for soon. Thank you for your help Jonathon Link to comment Share on other sites More sharing options...
mrfurryman Posted April 13, 2004 Share Posted April 13, 2004 There is of course another possibility: that somebody has considered one of your mailings to be spam, and has reported it as such. The following is part of the report from the samcop blocklist lookup: "210.54.16.178 is adsl-210.54.16.178.quicksilver.net.nz Since SpamCop started counting, this system has been reported less than 10 times by less than 10 users. In the past 854.4 days, it has been listed 3 times for a total of 16.5 days A sample sent sometime during the 24 hours beginning Tuesday, April 13, 2004 01:00:00 +0100: Received: from -.-.-.- (-210.54.16.178.-.net.- [210.54.16.178]) by -.-.com (Postfix) with - id - for <-[at]-.-.->- Tue, - Apr 2004 - - (-) Subject: - you - invited - a special - From: na.. at ..co.nz " Chris Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.