Spam - ideas for action
Author
Discussion

Size Nine Elm

Original Poster:

5,167 posts

314 months

Thursday 7th July 2005
quotequote all
I'm very, very angry.

Some spammer has sent out email to their pet spam list, but using my personal domain as the 'sender' address, so I have recieved the initial batch of 'rejected email' responses, and await the flames against spammers from those who will have recieved the spam emails. I'm also concerned that my domain will be blacklisted by such action.

The company has (obviously) included their URL in the spam (bit pointless otherwise).

What can I do - legitimately or otherwise - about them?

simpo two

92,862 posts

295 months

Thursday 7th July 2005
quotequote all
That recently happened to me as well.

An IT friend wrote:

Email - you need to set up two mailboxes at your ISP if they will let you. One needs to be 'yourname'@ and only get that email, the other needs to a "postmaster" account that gets all other email for the domain.
Then you need to set OE to download the 'yourname' mailbox only and ignore the other one.
Check with the ISP to see what happens when to other mailbox is full - can you ignore it or will it also affect 'yourname'?

Pigeon

18,535 posts

276 months

Thursday 7th July 2005
quotequote all
Complain to the generators of the reject messages that their mail server is misconfigured. It should be rejecting the incoming message with a 550 during the SMTP transaction to ensure it gets sent back to the sender. A lot of them wait until the SMTP transaction has completed and then bounce the mail to the forged address in the headers. Unfortunately most people don't know about this so there are a vast number of misconfigured servers out there and people like you get joe-jobbed as a result.

_dobbo_

14,619 posts

278 months

Friday 8th July 2005
quotequote all
Pigeon said:
Complain to the generators of the reject messages that their mail server is misconfigured. It should be rejecting the incoming message with a 550 during the SMTP transaction to ensure it gets sent back to the sender. A lot of them wait until the SMTP transaction has completed and then bounce the mail to the forged address in the headers. Unfortunately most people don't know about this so there are a vast number of misconfigured servers out there and people like you get joe-jobbed as a result.


Problem is if it's been relayed through an ISP mail server, then even if your server is generating a 550 error message then the relay server will still generate a failure response.

Ultimately this is something you can't do anything about. The recent introduction of SPF records might have an impact on this but not until all the legitimate senders have correclty configured SPF records. Given that 99.99999% of people have no clue what an SPF record is, I don't hold out much hope.

I administer about 8 or 9 dedicated email servers for several domains, and this happens many times every day. As postmaster for each of these domains I have never had a single complaint.

I would guess that our domain is faked many thousands of times a day by spammers. It's a sad fact of email life and can't be helped. I remember being gutted the first time it happened with my personal domain name - don't sweat it, it's not worth the effort!

Size Nine Elm

Original Poster:

5,167 posts

314 months

Friday 8th July 2005
quotequote all
Thanks for the responses.

In the light of everything else yesterday I feel a little shallow at being angry about such a trivial issue...