Quantumcat Posted January 10, 2008 Share Posted January 10, 2008 Someone used my domain name to send out untold numbers of spam mail. All I am seeing of it is 1200+ bounced back emails for "failure notice, undeliverable, etc. I contacted the ISP for my website since they run the mail servers, etc but all I got was a reply from a "outsourced" tech whose English was a second language. All I got from his email was there was nothing they could do about it and a link to spamcop.net. Many of the bounced back emails contained a copy of the original spam in a .eml format. I am unable to figure out how to get that file into the spamcop system. From what I can tell the original offender IP is 188.8.131.52. I didn't want to submit the spam wrong and get my own domain on a ban list. Here is a sample of the Received: lines from one of the attachments. Received: (qmail 6787 invoked from network); 8 Jan 2008 20:44:50 +0100 Received: from host59-184-dynamic.8-87-r.retail.telecomitalia.it (HELO host22-253-dynamic.8-87-r.retail.telecomitalia.it) (184.108.40.206) by bcl00442.empresas.ya.com with SMTP; 8 Jan 2008 20:44:48 +0100 Received: from sempron3000 ([220.127.116.11]:6032 "EHLO sempron3000" smtp-auth: <none> TLS-CIPHER: <none> TLS-PEER-CN1: <none>) by host22-253-dynamic.8-87-r.retail.telecomitalia.it with ESMTP id S22YSSKCMCJQNWJT (ORCPT <rfc822;antiquingrecreation%granitosdelval.com[at]mail.granitosdelval.com>); Tue, 8 Jan 2008 20:45:26 +0100 And a second: Received: from host22-253-dynamic.8-87-r.retail.telecomitalia.it (localhost [127.0.0.1]) by barracuda2.g-o.be (spam Firewall) with ESMTP id 75D70AE40C0 for <annie.ict[at]rago.be>; Tue, 8 Jan 2008 20:42:44 +0100 (CET) Received: from host22-253-dynamic.8-87-r.retail.telecomitalia.it (host59-184-dynamic.8-87-r.retail.telecomitalia.it [18.104.22.168]) by barracuda2.g-o.be with ESMTP id q8UoHvPbTLXoLKMo for <annie.ict[at]rago.be>; Tue, 08 Jan 2008 20:42:44 +0100 (CET) Received: from sempron3000 ([22.214.171.124] helo=sempron3000) by host22-253-dynamic.8-87-r.retail.telecomitalia.it ( sendmail 8.13.3/8.13.1) with esmtpa id 1BckVW-000GWV-Zi for annie.ict[at]rago.be; Tue, 8 Jan 2008 20:43:27 +0100 Link to comment Share on other sites More sharing options...
This topic is now archived and is closed to further replies.