Jump to content

Spam trap


twi

Recommended Posts

Hi!

What should I do to understand why You found our mail server?

Query bl.spamcop.net - 195.84.105.131

195.84.105.131 is mail.tibnor.se

(Help) (Trace IP) (Senderbase lookup)

195.84.105.131 listed in bl.spamcop.net (127.0.0.2)

Since SpamCop started counting, this system has been reported less than 10 times by less than 10 users. It has been sending mail consistently for at least 20.4 days. It has been listed for less than 24 hours.

* In the past week, this system has: Been detected sending mail to spam traps

* Been witnessed sending mail less than 10 times

Is some of our adresses hijacked or are we have we a couple of users missusing our mailsystem?

We can´t find the source to this.

Regards

/Tommy

Link to comment
Share on other sites

I don't speak Swedish but it appears that you are sending anti-virus notices to the spamtraps. As almost 100% of the viruses currently in circulation are forging the "from" address these notices are being sent to innocent email addresses; most people have turned off these notices. I have delisted the IP this one time but additional autoresponses to the traps may lead to a re-listing.

Link to comment
Share on other sites

Hi!

I´m aware of that, disabled notify sender earlier, weeks ago...

I double checked that no "Notify sender" box is checked.

Could it be Subject: DELIVERY FAILURE: User fake.name (fake.name[at]tibnor.se) not listed in Domino Directory

Edit:

Tripple checked that and found one box...checked, unchecked now and hopefully problem solved.

Thanks!

/Tommy

Link to comment
Share on other sites

Had you read Ellen's response, she wasn't mentioning non-delivery messages, it was anti-virus notifictions, which puts the issue into a whole different set of campaign issues .. that against the anti-virus companies / software that generates this absurd e-mail traffic to the forged From: line addresses.

Link to comment
Share on other sites

yourbuddy simply is very sensitive to the fact that SpamCop (like all BL's) can make mistakes and that those mistakes can and do cause lost valid messages.

yourbuddy also feels that the SpamCop BL is more suseptible to abuse because it accepts anybody's word that the message is spam. While this is possible and probably has happened at some time, there are precautions in place to protect against this abuse. A person with multiple accounts, or a group of people, would need to submit messages from the same server to get it blacklisted. To keep it on the list, they would need to continue to do this as IP's are dropped when the reports stop.

I hope I have stated yourbuddy's position acurately as I do NOT wish to start another flame war.

Link to comment
Share on other sites

yourbuddy alledgedly spent some time unable to communicate with his clients due to a spamcop listing error. He promotes content filters as the solution to spam and opposes blocklists except for MAPS and, IIRC, spamhaus. He doesn't approve of spamcop bl aggressiveness so points out any possible way that spamcop could have erred when a problem is posted. Once in a great while he posts something germane and useful.

Miss Betsy

Link to comment
Share on other sites

<snip>

Once in a great while he posts something germane and useful.

...Actually, I think his volume of germane and useful has surpassed his anti-SpamCop volume. :)

Is yourbuddy an Anti-Spamcop guy, or just really cynical?  :unsure:

...daringone -- you might take a look at yourbuddy's postings so you can make up your own mind. If you click on his name where it is a hyperlink, you'll see an option labeled "Find all posts by this member" that will take you to a list of those.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...