I have never has a problem with spamcop until this week. I somehow ended up on their blacklist. I followed the link on the NDR and it said the mail was sent to a spam trap.

I'm wondering if the fact that our mail server was down for 4 days due to a problem with my telephone service being down and had no DSL. Anyone emailing people in my office would have received a NDR. Could this have cause the problem.

Like I said, we never had a problem until the mail server was off-line for those days.

My mail server ip is

Any help will be greatly appreciated!


Well, the NDR would not have been sent by your system's IP if your mail server were down. It might have been sent by another server, but that would not list your server.

And if the machine was really down (off the net) for 4 days, the spamtrap happened since then since there is a 48 hour expiration on all IP's with no new reports.

There is one old spam sample available from Aug 29 and it is a pharm spam.

What was done to this server? Seeing: In the past 33.7 days, it has been listed 7 times for a total of 6.0 days, I hope it was removed from the internet for maintenance to find the hole the spammers were using.

Did someone leave a hole open and allow a new attack?

I don't believe that is what is meant by an NDR.

If your server was down the mail would not be rejected to the "From" address. The sending server would just get it back after a specified period.

To send an NDR your server needs to be up and running.

It is more likely your exchange server has been hacked, this is just a guess as there are no samples to view.





This exploit allows spammers to relay thru your exchange server. This relaying does not show up using standard open relay tests as the spammer has gained "legal" access to your server by hacking an account/password combination.

There may be yet another issue involved;

Parsing input:

host = 65-86-159-199.client.dsl.net (cached)

Reporting addresses:



The "client.dsl.net" may actually place your e-mail server into some BLs because it' falls into what is normally called "dial-up space" ... an IP address that is assigned to a (home) customer as compared to a business (assigned to a static IP address) ... so some ISPs may reject your e-mail just for this reason.

However, the real issue does appear to be that already suggested, you have what appears to be a compromised system sitting at that IP (are you in control of this system?)


Volume Statistics for this IP

........Magnitude ...... Vol Change vs. Average

Last day ........ 3.4 ....... 315%

Last 30 days .. 3.6 ....... 472%

Average ........ 2.8

Is it possible someone was trying to "fix" this server when the phone was turned off and made some configuration changes that weren't put back to "normal" after the real reason for the e-mails stoppage was made known?

I disabled the GUEST account on my server.

Basically, it means that; (no real reason to post all that stuff anyway, it's just evidence that this server has been compromised, as suggested already)

I disabled the GUEST account on my server.

may not be enough. Are you still doing some research or did you just stop at the first "likely" item? Not meaning to give you a hard time, but .....

I disabled the GUEST account on my server.

My Exhcange server is not a open relay but it did have some history in their spam database.  See below.  What does this mean?  Thanks for any help you may provide.


It appears that your machine has been compromised either by a virus/trojan or that the mail server itself has been compromised (SMTP AUTH HACK?)

Disabling the guest account is a good start, however you really should disable any accounts that are not currently being used. For all accounts that are being used you should change *ALL* the passwords to something that is non-trivial.

Unless someone who uses that mail server needs to access it from outside of your LAN I'd suggest than you disable all remote sending capabilities.

A full virus/trojan scan of the machine should also be in order. If the machine has been compromised by a virus/trojan it would be in your best interest to format the drive and rebuild the machine taking all the proper security measues.

Thanks for your desire to resolve the core problem leading to the listing of your server. You may also want to send an email to deputies <at> spamcop <dot> net who may provide you some additional information as to what is happening.

I disabled the GUEST account on my server.


My Exhcange server is not a open relay but it did have some history in their spam database.

<big snip>


...There are other possible causes of a spam problem. See the links in Merlyn's reply, above as well as Chris Parker's reply, above (which I presume summarizes what's in at least one of Merlyn's links), which he apparently posted at the same time I was authoring this reply prior to my Edit.
I disabled the GUEST account on my server.

I came across this report from my server on http://www.mail-abuse.com/services/mds_rss.html.  My Exhcange server is not a open relay but it did have some history in their spam database.  See below.  What does this mean?  Thanks for any help you may provide.

Your server is being used by spammers using the SMTP/AUTH exploit:





The spammer has now also evolved according to what I am hearing and in addition to the usual guest account and demo/test etc accounts they are also running long crack lists of names/passwords. In any case if you can turn off auth completely that would be good and if not then you should change the passwords on *all* accounts to strong passwords.

Fixed the quoting <g> ... Ralsky has been using the "long account/password list" thing for a long time, thus his continued success at owning all these servers. Not sure where someone would be listing this mode as "new" .... but the referenced links have been provided (plus additional ones via the FAQ here) .... in fact, one of my previous questions was whether or not all data found in these links was evaluated, as the only thing mentioned was "deleted the GUEST account" ... There's been like another half-dozen posts suggesting that there was more to do <g>

Merlyn, I've added a couple of more links to that list in the FAQ here if you'd want to update your copy of that reference list ... I recall that Ellen recently caught one of them ...


Thanks Wazoo, I just returned. I will update my list, Actually I will just point to the FAQ from now on :-)

Wow I am gone 2 1/2 days and I miss all the fun :o

..you just have no idea, it was like Gingis Hun invaded and no one here to stop the assault... :P


Actually the last few days were just about the best time I've had on these forums since their creation. Frankly, I get more laughs around here each day than I do from my nightly sitcom input!

Okay, I'm no longer list on the spamcop blacklist but one of my users is still getting the undeliverables.

From: System Administrator

Sent: Sunday, September 12, 2004 3:18 PM

To: aaa[at]aaa.com

Subject: Undeliverable: RE: cc authorization

Your message did not reach some or all of the intended recipients.

Subject: RE: cc authorization

Sent: 9/12/2004 3:18 PM

The following recipient(s) could not be reached:

aaa[at]aaa.comon 9/12/2004 3:18 PM

There was a SMTP communication problem with the recipient's email server. Please contact your system administrator.

<nbtaexchange.nbta.org #5.5.0 smtp;554 Service unavailable; Client host [] blocked using bl.spamcop.net; Blocked - see http://www.spamcop.net/bl.shtml?>

This Forum software made the BL URL "clickable," but it got mangled due to the angle bracket after the IP number and it results in an incorrect lookup for those of us reading the thread.

Here's the correct URL:


But, even when fixed, that IP is NOT currently blocked, which means that the people that are actually doing the blocking, the receiving ISP, should be contacted for an explanation. Their SCBL data is not current...maybe they've got their server misconfigured and it's not pulling updates at regular intervals.


There are 2 possibilities I can think of. There may be others.

1. (most likely) The server you are receiving this rejection from is caching the lookups locally rather than doing a fresh lookup each time and the TTL has not expired yet. You could contact them another way and ask them to clear their cache or keep retrying. Eventually, it should get the refreshed data automatically.

2. Recently, if I understand correctly, there was at lease 1 mirror that was "out of sync" and giving stale data. The deputies would need to check into that.

If most messages that were being returned are now going through, you can see that most people are getting the correct information. I double checked both the web page and nslookup directly and confirmed you are not listed.

Okay, I'm no longer list on the spamcop blacklist but one of my users is still getting the undeliverables.


The SpamCop blocklist is likely to be the least of your troubles: you're listed by SORBS, now, and CBLabuseat among others for sending mail to spamtraps. What have you done to stop the spew, if you don't mind my asking?

The SpamCop blocklist is likely to be the least of your troubles: you're listed by SORBS, now, and CBLabuseat among others for sending mail to spamtraps. What have you done to stop the spew, if you don't mind my asking?


I just checked both SORBS and CBLabuseat and I'm no longer listed.

What did I do to stop this? A lot of hope and praying :P. But really, I disable all user accounts with a blank passoword and I dismounted my public folders in Exchange since we don't use them. A couple weeks a ago I was playing a round with it and left it enabled. I don't know if the user accounts or public folder caused the problem but I'm no longer listed.

