danmoran Posted November 13, 2012 Share Posted November 13, 2012 Once again, the parser is completely ignoring URL's in a submitted spam: http://www.spamcop.net/sc?id=z5429551767z4...054f9ae92a8279z I've seen this before, but very sporadically. Link to comment Share on other sites More sharing options...
Farelf Posted November 14, 2012 Share Posted November 14, 2012 Interesting! The parser handled it as a bounce: Re: 195.214.192.8 (Bounce) Not sure why, can't quite follow/see it in the headers myself, but the spam has been configured to appear as a bounce/autoreply with subject ("Autoreply from green-card[at]ukr.net ...") and body: "Good day! Your message has been received. We will contact you at this address if necessary." (in Russian). Neat trick - of course the parser will not look at the message body if it "thinks" it is dealing with a bounce. You used the webform with the Outlook/Eudora 2-part submission. I suppose the result is the same whatever submission method is used? Hard for you to tell but any others receiving the "same" spam (Subject: Autoreply from green-card[at]ukr.net {EFTPS Federal Payment Batch Has Been Failed.. ID: 6284364}) might be able to tell - looks like you are the only one reporting re 195.214.192.8 though. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.