Jump to content

Parser "ignores" correct reporting e-mail


MaxUK

Recommended Posts

Hi everyone.

The tracking URL is

http://www.spamcop.net/sc?id=z1435557400zb...88eae2f936df48z

spam came from IP 124.7.66.103 (apnic.net)

The parser finds the correct reporting email ipadmin(AT)sifycorp.com from APNIC,

but then claims that no reporting addresses found and uses devnull.

What's wrong with e-mail ipadmin(AT)sifycorp.com ?

Why it's beeing ignored?

Link to comment
Share on other sites

Full / Technical details provided in your parse include this data:

0: Received: from [124.7.66.103] (helo=ghelde) by store8.mail.uk.easynet.net with smtp (Exim 4.63) (envelope-from <shoppingistherapy.com[at]infonair.com>) id 1IY2l6-0002Lc-UF for x; Wed, 19 Sep 2007 17:50:41 +0100

No unique hostname found for source: 124.7.66.103

UKOnline received mail from sending system 124.7.66.103

Tracking message source: 124.7.66.103:

Cached whois for 124.7.66.103 : ipadmin[at]sifycorp.com

abuse[at]sify.com bounces (6 sent : 6 bounces)

Using best contacts

host 124.7.66.103 = segment-124-7.sify.net. (cached)

Host segment-124-7.sify.net. (checking ip) IP not found ; segment-124-7.sify.net. discarded as fake.

No reporting addresses found for 124.7.66.103, using devnull for tracking.

124.7.66.103 is an open proxy

Routing Details;

Reports routes for 124.7.66.103:

routeid:30549471 124.7.0.0 - 124.7.255.255 to:ipadmin[at]sifycorp.com

Administrator found from whois records

Removing old cache entries.

Tracking details

"whois 124.7.66.103[at]whois.apnic.net" (Getting contact from whois.apnic.net mirror)

Display data:

hs51-ap = ipadmin[at]sifycorp.com

whois.apnic.net 124.7.66.103 = ipadmin[at]sifycorp.com

whois: 124.7.0.0 - 124.7.255.255 = ipadmin[at]sifycorp.com

abuse[at]sify.com bounces (6 sent : 6 bounces)

Using best contacts

whois -h whois.networksolutions.com sifycorp.com ...

Registrant:

Sify Limited

Tidel Park,2nd Floor

4,Canal Bank Road,Taramani

Chennai, TN 600113

IN

Domain Name: SIFYCORP.COM

Administrative Contact, Technical Contact:

Ltd, Sify domainadmin[at]sifycorp.com

Sify Ltd

2nd Floor, Tidel Park

#4, Canal Bank Road

Taramani, Chennai

Chennai, Tamilnadu 600113

IN

91-44-22540770 fax: 91-44-22540771

Record expires on 18-Jul-2011.

Record created on 18-Jul-2000.

Database last updated on 19-Sep-2007 18:26:54 EDT.

Domain servers in listed order:

PDNS.SATYAM.NET.IN

SDNS.SATYAM.NET.IN

Who else might you want to yell at? networksolutions for allowing this lousy Registration? APNIC for having other / different data? The Admin folks of the site in question?

The parser didn't 'see' any abuse address, didn't care for the "domainadmin" or "ipadmin" addresses, so dropped back and tried to use a default address. (I did not check what abuse.net has on file) One could complain to these folks and try to get addresses and Registration data updated, corrected, etc.

To 'fix' the parser issue, please see SpamCop Newsgroups .. pay particular attention to the comment "do your homework first"

Link to comment
Share on other sites

...(I did not check what abuse.net has on file)...
postmaster[at]sifycorp.com (for sifycorp.com)

abuse[at]sify.com (for sifycorp.com)

postmaster[at]sifycorp.com (for sifycorp.com)

postmaster[at]sify.in (for sifycorp.com)

customercare[at]satyam.net.in (for sifycorp.com)

customercare[at]sify.com (for sifycorp.com)

postmaster[at]sify.com (for sify.com)

abuse[at]sify.com (for sify.com)

postmaster[at]sifycorp.com (for sify.com)

postmaster[at]sify.in (for sify.com)

customercare[at]satyam.net.in (for sify.com)

customercare[at]sify.com (for sify.com)

The latter changing in a matter of minutes, just now, previously showing

ipadmin[at]sifycorp.com

postmaster[at]sifycorp.com

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...