HN Support Posted April 3, 2018 Share Posted April 3, 2018 (edited) Hi there for a couple weeks now I noticed most reporting was going to firstname.lastname@example.org. I started to get suspicious and so started looking into it. It seems as though there's some Microsoft IPv6 addresses which aren't in our "Hotmail / MSN" drop-down list of the Mailhosts section our account and every time the parser hits on one of those it decides that's the source of the spam instead of continuing through the headers to the actual origin. Case in point: www.spamcop.net/sc?id=z6456858877zb5f21cf2fa16ca99611a32e08c680ae7z As you can see in this case it stopped at 2a01:111:e400:c47c:0:0:0:49 instead of realizing that was not the sender IP and continuing on to the more likely candidate. Here's some more failures of this type: http://www.spamcop.net/sc?id=z6456858879z4145dd35d533293621e90955a03d735bz http://www.spamcop.net/sc?id=z6456858881z5f2552c0a0b58982773dc4351afcbf34z http://www.spamcop.net/sc?id=z6456858882zaf7ea911350a7960e8187700288a3ff8z I tried deleting my Hotmail/ MSN mailhost entry from within our "Mailhosts" section and recreating it didn't help. Also here's a sample of some of the IPv6 addresses that have been incorrectly identified as the source of the spam messages in some of our submissions: 2a01:111:e400:5a6b:0:0:0:40 2a01:111:e400:5a6c:0:0:0:36 2a01:111:e400:5311:0:0:0:11 2a01:111:e400:5311:0:0:0:30 2a01:111:e400:5311:0:0:0:32 2a01:111:e400:5311:0:0:0:42 2a01:111:e400:c47c:0:0:0:49 2a01:111:e400:c47c:0:0:0:52 2603:10b6:300:2c:0:0:0:28 2603:10b6:301:0:0:0:0:27 2603:10b6:403:0:0:0:0:22 2603:10b6:403:0:0:0:0:32 2603:10b6:403:0:0:0:0:33 2603:10b6:404:109:0:0:0:18 2603:10b6:404:109:0:0:0:21 2603:10b6:405:1:0:0:0:11 2603:10b6:406:bc:0:0:0:25 2603:10b6:406:bc:0:0:0:29 2603:10b6:910:3d:0:0:0:39 Also please note that whenever all the Microsoft / MSN IPv6 addresses in the message header ARE listed in the current Microsoft / MSN dropdown those messages are correctly parsed and the source of the spam message positively identified. However this seems to be only 1 out of every 10 submissions which means I'm cancelling the reporting of 9 / 10 submissions at this point. Please advise. Edited April 3, 2018 by HN Support Quote Link to comment Share on other sites More sharing options...
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.