Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #193897 > unrolled thread

More then 2800 spams from the list...

Started by"Michelle Konzack" <linux4michelle@tamay-dogan.net>
First post2018-03-19 14:00 +0100
Last post2018-03-21 08:10 +0100
Articles 9 on this page of 29 — 17 participants

Back to article view | Back to linux.debian.user


Contents

  More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 14:00 +0100
    Re: More then 2800 spams from the list... Jonathan Dowland <jmtd@debian.org> - 2018-03-19 14:20 +0100
      Re: More then 2800 spams from the list... Gene Heskett <gheskett@shentel.net> - 2018-03-19 15:50 +0100
        Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 15:50 +0100
          Re: More then 2800 spams from the list... Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-03-19 16:10 +0100
            Re: More then 2800 spams from the list... Richard Owlett <rowlett@cloud85.net> - 2018-03-19 16:30 +0100
              Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 16:40 +0100
                Re: More then 2800 spams from the list... Jim Popovitch <jim@k4vqc.com> - 2018-03-19 17:00 +0100
                Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 17:30 +0100
                  Re: More then 2800 spams from the list... Miles Fidelman <mfidelman@meetinghouse.net> - 2018-03-19 18:50 +0100
                    Re: More then 2800 spams from the list... Tony van der Hoff <lists@vanderhoff.org> - 2018-03-19 19:20 +0100
                      Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 19:30 +0100
                  Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 19:40 +0100
            Re: More then 2800 spams from the list... Gene Heskett <gheskett@shentel.net> - 2018-03-19 16:40 +0100
            Re: More then 2800 spams from the list... Curt <curty@free.fr> - 2018-03-19 18:20 +0100
        Re: More then 2800 spams from the list... Richard Owlett <rowlett@cloud85.net> - 2018-03-19 16:00 +0100
    Re: More then 2800 spams from the list... Karol Augustin <karol@augustin.pl> - 2018-03-19 19:40 +0100
      Re: More then 2800 spams from the list... Nick Boyce <nick@steelyglint.org> - 2018-03-19 22:20 +0100
        Re: More then 2800 spams from the list... Karol Augustin <karol@augustin.pl> - 2018-03-19 22:40 +0100
      Re: More then 2800 spams from the list... Joe <joe@jretrading.com> - 2018-03-19 23:30 +0100
        Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-20 09:00 +0100
          Re: More then 2800 spams from the list... Joe <joe@jretrading.com> - 2018-03-20 10:30 +0100
            Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-20 10:50 +0100
            Re: More then 2800 spams from the list... Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-20 13:30 +0100
              Re: More then 2800 spams from the list... David Wright <deblis@lionunicorn.co.uk> - 2018-03-20 14:40 +0100
                Re: More then 2800 spams from the list... Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-20 14:50 +0100
            Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-20 20:00 +0100
              Re: More then 2800 spams from the list... Brian <ad44@cityscape.co.uk> - 2018-03-21 01:20 +0100
                Re: More then 2800 spams from the list... Brad Rogers <brad@fineby.me.uk> - 2018-03-21 08:10 +0100

Page 2 of 2 — ← Prev page 1 [2]


#193938

From<tomas@tuxteam.de>
Date2018-03-20 09:00 +0100
Message-ID<vvklA-1la-9@gated-at.bofh.it>
In reply to#193934
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Mar 19, 2018 at 10:21:57PM +0000, Joe wrote:

[...]

> > This is precisely why e-mail server should never send bounces to
> > non-local senders. When sender is spoofed as in this case then is hit
> > with thousands of DSNs.

[delivery status notification]

[...]

> You do it by never accepting email for non-existent users. The problem
> is the use of a mail server which accepts absolutely anything for the
> domain, then finds that the end user rejects the rubbish. Having
> accepted it in the first place, the receiving mail server is then
> required to admit that it can't deliver it, by means of an NDR. It does
> this using the reply-to address, which is easily forged.

"never" is too strong a word. This is a corollary of the fundamental
law "all generalizations suck".

But yes, in general it is a bad idea to bounce a mail automatically
if you don't have control over its provenience.

FWIW, I did the experiment and sent a mail to a random user at one
of Michelle's reported domains: I got no bounce.

This is a strong hint (no proof, mind you!) that the whole bounces
are spoofed in this case. The reported headers in those bounces
do look strange (to me, anyway), but I'm willing to admit that I'm
not smart enough to grok them.

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlqwvdAACgkQBcgs9XrR2kYQ+ACfWNYAJyDeT+7vMILqV4MUcTdV
V24An1I7UBTaj6BdeGV5ral2IC68oe+A
=ahYU
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#193942

FromJoe <joe@jretrading.com>
Date2018-03-20 10:30 +0100
Message-ID<vvlKF-2l7-1@gated-at.bofh.it>
In reply to#193938
On Tue, 20 Mar 2018 08:52:48 +0100
<tomas@tuxteam.de> wrote:

>
> 
> "never" is too strong a word. This is a corollary of the fundamental
> law "all generalizations suck".
> 
How do you determine the exceptions? 

A SMTP server, by default, accepts email only for recipients which have
an account on it. Aliases can be added, but on the whole, there is no
mechanism for a 'catch-all' mailbox. Someone has to deliberately add
some code to make such a thing happen. This has even been true of
Exchange for the last few versions. It's generally not difficult, but
it's not there out of the box. 

There won't be any NDR spam if all the invalid email goes into one
particular account for a human to examine. The problem occurs if and
when a later SMTP server attempts to download and deliver this email to
multiple people who don't exist.

A salesman might argue that if only valid accounts are accepted, he
might miss a valuable sale because of a mis-spelled email address. In
other words, no price is too high for the rest of the Internet to pay
for him to get one more lead, no matter how poor. I'm not a salesman, so
I see things differently.

Things aren't as bad as they used to be, probably 90% of what my mail
server refused was once NDR spam. I could see in the logs the same dozen
obviously deliberately incorrect email addresses every day, sometimes
several times a day. This has reduced with the decline of small (and
large!) businesses running their own private SMTP servers but
downloading their mail from a single shared external POP3 account,
which used to be a very common practice.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#193943

From<tomas@tuxteam.de>
Date2018-03-20 10:50 +0100
Message-ID<vvm41-2r8-1@gated-at.bofh.it>
In reply to#193942
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, Mar 20, 2018 at 09:21:03AM +0000, Joe wrote:
> On Tue, 20 Mar 2018 08:52:48 +0100
> <tomas@tuxteam.de> wrote:
> 
> >
> > 
> > "never" is too strong a word. This is a corollary of the fundamental
> > law "all generalizations suck".
> > 
> How do you determine the exceptions? 

With care and measure :-)

> A SMTP server, by default, accepts email only for recipients which have
> an account on it. Aliases can be added, but on the whole, there is no
> mechanism for a 'catch-all' mailbox. Someone has to deliberately add
> some code to make such a thing happen. This has even been true of
> Exchange for the last few versions. It's generally not difficult, but
> it's not there out of the box. 

I, for example, do have a "catch-all" box. That's me.

And I'm not a salesman :-)

But with such a setup you've got to cope with *some* spam, that's
correct.

What you should not do is to accept a mail for forwarding to another
system you don't control (or are somewhat related to): that system
could very well reject that mail, and now you have a problem.

This would be what's called an "open relay". In these times, better
not do that.

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlqw1wcACgkQBcgs9XrR2kZaiwCfSeEG7MoiZOViagrxjAFyMdXa
1q4Ani0cS3rSfJmvGYO0As503h1QUnCo
=Vzt2
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#193947

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2018-03-20 13:30 +0100
Message-ID<vvoyS-45M-17@gated-at.bofh.it>
In reply to#193942
On Tue, Mar 20, 2018 at 09:21:03AM +0000, Joe wrote:
> A SMTP server, by default, accepts email only for recipients which have
> an account on it.

If only.  No, that's part of the problem.  An SMTP server, *by default*,
has no knowledge of which local-recipient-parts are valid and which
are not.  It has to communicate with some other system, process, library,
or whatever, to make that determination.

It's much easier for an SMTP server to validate just the domain-part
(right of the @ sign), and generate bounces when it turns out that
the local-recipient-part (left of the @ sign) is invalid.  This is
how things worked 25 years ago.

Unfortunately, humans being the despicable creatures that they are,
that naive system no longer works.

P.S. someone said that bounces are generated using the Reply-To: header.
This is incorrect (or at least, would be a violation of the protocols).
Bounces are sent to the envelope sender address (the one given by the
sender during the SMTP session), without looking at the message itself.

Of course, the envelope sender is just as easy to forge as the
Reply-To: header is.  The sender only needs to lie about who it is.
The receiver has no way to verify the address, other than "yeah, that
domain exists in DNS".

That's how backscatter (a.k.a. "joe-jobbing") works.  The spammer
sends mail to an invalid address and lies about the envelope sender
address.  The receiver generates a bounce to the forged envelope
sender address.  Voila, spam sent -- by the poor schmuck in the middle
who was just trying to follow the SMTP protocol properly.  The only
one who can identify the actual sender is the one who generated the
bounce, and the only identifying information that system has is the
IP address from which the message was sent.  Everything else (envelope
sender, message headers, message body) is fabricated.

[toc] | [prev] | [next] | [standalone]


#193949

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2018-03-20 14:40 +0100
Message-ID<vvpEC-4Lh-13@gated-at.bofh.it>
In reply to#193947
On Tue 20 Mar 2018 at 08:28:20 (-0400), Greg Wooledge wrote:
> P.S. someone said that bounces are generated using the Reply-To: header.
> This is incorrect (or at least, would be a violation of the protocols).
> Bounces are sent to the envelope sender address (the one given by the
> sender during the SMTP session), without looking at the message itself.
> 
> Of course, the envelope sender is just as easy to forge as the
> Reply-To: header is.  The sender only needs to lie about who it is.
> The receiver has no way to verify the address, other than "yeah, that
> domain exists in DNS".

But if that IP address sends loads of undeliverable mail,
why not just block it? I was under the impression that
that's what IP address blacklisting was all about.

> That's how backscatter (a.k.a. "joe-jobbing") works.  The spammer
> sends mail to an invalid address and lies about the envelope sender
> address.  The receiver generates a bounce to the forged envelope
> sender address.  Voila, spam sent -- by the poor schmuck in the middle
> who was just trying to follow the SMTP protocol properly.  The only
> one who can identify the actual sender is the one who generated the
> bounce, and the only identifying information that system has is the
> IP address from which the message was sent.  Everything else (envelope
> sender, message headers, message body) is fabricated.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#193950

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2018-03-20 14:50 +0100
Message-ID<vvpOh-4OW-3@gated-at.bofh.it>
In reply to#193949
On Tue, Mar 20, 2018 at 08:30:50AM -0500, David Wright wrote:
> On Tue 20 Mar 2018 at 08:28:20 (-0400), Greg Wooledge wrote:
> > P.S. someone said that bounces are generated using the Reply-To: header.
> > This is incorrect (or at least, would be a violation of the protocols).
> > Bounces are sent to the envelope sender address (the one given by the
> > sender during the SMTP session), without looking at the message itself.
> > 
> > Of course, the envelope sender is just as easy to forge as the
> > Reply-To: header is.  The sender only needs to lie about who it is.
> > The receiver has no way to verify the address, other than "yeah, that
> > domain exists in DNS".
> 
> But if that IP address sends loads of undeliverable mail,
> why not just block it? I was under the impression that
> that's what IP address blacklisting was all about.

That happens, certainly.  But not everyone is using a blacklist.
The spammer just has to find one system that's vulnerable and keep
hammering it until it, too, gets blacklisted.

[toc] | [prev] | [next] | [standalone]


#193963

From"Michelle Konzack" <linux4michelle@tamay-dogan.net>
Date2018-03-20 20:00 +0100
Message-ID<vvuEi-7Yg-5@gated-at.bofh.it>
In reply to#193942
Hi Joe,

Am 2018-03-20 hackte Joe in die Tasten:
> A SMTP server, by default, accepts email only for recipients which
> have
> an account on it. Aliases can be added, but on the whole, there is no
> mechanism for a 'catch-all' mailbox. Someone has to deliberately add
> some code to make such a thing happen.

Not realy true, because I have setup a honnypot for a (new) domain
which NEVER send or receive any mails and used

@example.com: honigtopf

which accept anything!  However, this EMails are forwarded to a RBL
provider which use it for analysing...  ;-)

> This has even been true of
> Exchange for the last few versions. It's generally not difficult, but
> it's not there out of the box.

Courier can do this as well as exim and postfix!
Out-of-the-Box!

Please read the documentation!

> Things aren't as bad as they used to be, probably 90% of what my mail
> server refused was once NDR spam. I could see in the logs the same
> dozen
> obviously deliberately incorrect email addresses every day, sometimes
> several times a day.

Hmmm I just checked, and verified twice, but the spammers are sleeping
today:

----[ /var/log/mail_err.log ]-------------------------------------------
<19>1 2018-03-20T01:46:16.855550+01:00 mail courieresmtpd  - - 
error,relay=::ffff:194.181.177.172,from=<Info.Googlepromo@info.com>:
517 Sender rejected: Info.Googlepromo@info.com
<19>1 2018-03-20T01:48:27.104049+01:00 mail courieresmtpd  - - 
error,relay=::ffff:78.47.104.44,from=<#@[]>: 517 Syntax error.
<19>1 2018-03-20T02:10:01.608879+01:00 mail courieresmtpd  - - 
error,relay=::ffff:185.174.23.54,from=<SexualHealth@visionveryclear.bid>,to=<jfc53@tdwave.net>:
556 Address unavailable.
<19>1 2018-03-20T02:46:27.744330+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20090120171902.gh29556@tamay-dogan.net>:
550 User <20090120171902.gh29556> unknown
<19>1 2018-03-20T02:46:28.053447+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<ga16968@tamay-dogan.net>:
550 User <ga16968> unknown
<19>1 2018-03-20T02:46:28.369856+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20080919175920.gn6606@tamay-dogan.net>:
550 User <20080919175920.gn6606> unknown
<19>1 2018-03-20T02:46:28.679337+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20100613011722.gt8243@tamay-dogan.net>:
550 User <20100613011722.gt8243> unknown
<19>1 2018-03-20T02:46:28.988781+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20100625180153.gk21273@tamay-dogan.net>:
550 User <20100625180153.gk21273> unknown
<19>1 2018-03-20T02:46:29.298216+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20100625175945.gj21273@tamay-dogan.net>:
550 User <20100625175945.gj21273> unknown
<19>1 2018-03-20T03:35:17.173606+01:00 mail courieresmtpd  - - 
error,relay=::ffff:121.40.42.27,from=<subinahan57@nate.com>,to=<gg4653@tamay-dogan.net>:
550 User <gg4653> unknown
<19>1 2018-03-20T03:35:17.437402+01:00 mail courieresmtpd  - - 
error,relay=::ffff:121.40.42.27,from=<subinahan57@nate.com>,to=<gc4668@tamay-dogan.net>:
550 User <gc4668> unknown
<19>1 2018-03-20T03:35:17.700985+01:00 mail courieresmtpd  - - 
error,relay=::ffff:121.40.42.27,from=<subinahan57@nate.com>,to=<ga4668@tamay-dogan.net>:
550 User <ga4668> unknown
<19>1 2018-03-20T04:02:31.999498+01:00 mail courieresmtpd  - - 
error,relay=::ffff:220.181.97.175,from=<sales@cubeel.com>,to=<einkauf@electronica.tamay-dogan.net>:
550 User <einkauf> unknown
<19>1 2018-03-20T04:42:16.719343+01:00 mail courieresmtpd  - - 
error,relay=::ffff:119.177.128.214,from=<chulmim5@gmail.com>,to=<ge4653@tamay-dogan.net>:
550 User <ge4653> unknown
<19>1 2018-03-20T04:42:17.023533+01:00 mail courieresmtpd  - - 
error,relay=::ffff:119.177.128.214,from=<chulmim5@gmail.com>,to=<gm2093@tamay-dogan.net>:
550 User <gm2093> unknown
<19>1 2018-03-20T04:43:09.854792+01:00 mail courieresmtpd  - - 
error,relay=::ffff:194.181.177.172,from=<Info.Googlepromo@info.com>:
517 Sender rejected: Info.Googlepromo@info.com
<19>1 2018-03-20T04:45:31.704422+01:00 mail courieresmtpd  - - 
error,relay=::ffff:182.139.29.77,from=<1991019554@qq.com>,to=<20100613011722.GT8243@tamay-dogan.net>:
550 User <20100613011722.GT8243> unknown
<19>1 2018-03-20T04:50:10.555313+01:00 mail courieresmtpd  - - 
error,relay=::ffff:182.139.29.77,from=<2302627349@qq.com>,to=<20100625175945.GJ21273@tamay-dogan.net>:
550 User <20100625175945.GJ21273> unknown
<19>1 2018-03-20T04:50:11.067588+01:00 mail courieresmtpd  - - 
error,relay=::ffff:182.139.29.77,from=<1991019554@qq.com>,to=<20100625180153.GK21273@tamay-dogan.net>:
550 User <20100625180153.GK21273> unknown
<19>1 2018-03-20T06:55:51.421165+01:00 mail courieresmtpd  - - 
error,relay=::ffff:111.160.38.150,from=<chulmim5@gmail.com>,to=<gc4668@tamay-dogan.net>:
550 User <gc4668> unknown
<19>1 2018-03-20T06:55:51.770953+01:00 mail courieresmtpd  - - 
error,relay=::ffff:111.160.38.150,from=<chulmim5@gmail.com>,to=<ga4668@tamay-dogan.net>:
550 User <ga4668> unknown
<19>1 2018-03-20T06:55:52.105612+01:00 mail courieresmtpd  - - 
error,relay=::ffff:111.160.38.150,from=<chulmim5@gmail.com>,to=<gg4653@tamay-dogan.net>:
550 User <gg4653> unknown
<19>1 2018-03-20T07:12:27.384536+01:00 mail courieresmtpd  - - 
error,relay=::ffff:78.47.104.44,from=<#@[]>: 517 Syntax error.
<19>1 2018-03-20T07:22:53.284402+01:00 mail courieresmtpd  - - 
error,relay=::ffff:119.90.24.64,from=<subinahan57@nate.com>,to=<ge4653@tamay-dogan.net>:
550 User <ge4653> unknown
<19>1 2018-03-20T07:22:53.603333+01:00 mail courieresmtpd  - - 
error,relay=::ffff:119.90.24.64,from=<subinahan57@nate.com>,to=<gm2093@tamay-dogan.net>:
550 User <gm2093> unknown
<19>1 2018-03-20T07:53:55.102715+01:00 mail courieresmtpd  - - 
error,relay=::ffff:40.92.65.48,from=<ahmedhakim@live.com>: 517 Sender
rejected: ahmedhakim@live.com
<19>1 2018-03-20T08:53:15.523049+01:00 mail courieresmtpd  - - 
error,relay=::ffff:61.160.101.114,from=<natminroll@gmail.com>,to=<ga4668@tamay-dogan.net>:
550 User <ga4668> unknown
<19>1 2018-03-20T08:53:15.813412+01:00 mail courieresmtpd  - - 
error,relay=::ffff:61.160.101.114,from=<natminroll@gmail.com>,to=<gc4668@tamay-dogan.net>:
550 User <gc4668> unknown
<19>1 2018-03-20T08:53:16.105498+01:00 mail courieresmtpd  - - 
error,relay=::ffff:61.160.101.114,from=<natminroll@gmail.com>,to=<gg4653@tamay-dogan.net>:
550 User <gg4653> unknown
<19>1 2018-03-20T10:06:35.760419+01:00 mail courieresmtpd  - - 
error,relay=::ffff:114.237.210.113,from=<support@itsystems.tamay-dogan.net>,to=<2326410519@qq.com>:
513 Relaying denied.
<19>1 2018-03-20T10:11:42.659188+01:00 mail courieresmtpd  - - 
error,relay=::ffff:114.237.210.128,from=<support@jiangmin.com>,to=<2326410519@qq.com>:
513 Relaying denied.
<19>1 2018-03-20T10:36:14.814806+01:00 mail courieresmtpd  - - 
error,relay=2607:f8b0:4001:c06::246,from=<399WwWgcLAEIrsvitp22syxyfi.gsq@youtube-subscriptions.bounces.google.com>,to=<google@electronica.tamay-dogan.net>:
550 User <google> unknown
<19>1 2018-03-20T11:00:14.046567+01:00 mail courieresmtpd  - - 
error,relay=::ffff:185.174.23.49,from=<FixYourTightHips@fixtighthips.bid>,to=<jfc53@tdwave.net>:
556 Address unavailable.
<19>1 2018-03-20T12:12:43.298844+01:00 mail courieresmtpd  - - 
error,relay=::ffff:61.175.186.125,from=<fma@fmtunisie.com>: 517-Domain
does not exist: fmtunisie.com.
<19>1 2018-03-20T12:12:43.299010+01:00 mail courieresmtpd  - - 
error,relay=::ffff:61.175.186.125,from=<fma@fmtunisie.com>: 517
Invalid domain, see <URL:ftp://ftp.isi.edu/in-notes/rfc1035.txt>
<19>1 2018-03-20T12:12:48.359610+01:00 mail courieresmtpd  - - 
error,relay=::ffff:61.175.186.125,from=<fma@fmtunisie.com>: 517-Domain
does not exist: fmtunisie.com.
<19>1 2018-03-20T12:12:48.359760+01:00 mail courieresmtpd  - - 
error,relay=::ffff:61.175.186.125,from=<fma@fmtunisie.com>: 517
Invalid domain, see <URL:ftp://ftp.isi.edu/in-notes/rfc1035.txt>
<19>1 2018-03-20T12:17:00.588129+01:00 mail courieresmtpd  - - 
error,relay=::ffff:185.174.23.43,from=<LossofNails@fixtoenails.bid>,to=<jfc53@tdwave.net>:
556 Address unavailable.
<19>1 2018-03-20T13:40:39.638981+01:00 mail courieresmtpd  - - 
error,relay=::ffff:112.116.220.112,from=<gjungmin81@korea.com>,to=<gg4653@tamay-dogan.net>:
550 User <gg4653> unknown
<19>1 2018-03-20T13:40:40.089566+01:00 mail courieresmtpd  - - 
error,relay=::ffff:112.116.220.112,from=<gjungmin81@korea.com>,to=<ga4668@tamay-dogan.net>:
550 User <ga4668> unknown
<19>1 2018-03-20T13:40:40.529563+01:00 mail courieresmtpd  - - 
error,relay=::ffff:112.116.220.112,from=<gjungmin81@korea.com>,to=<gc4668@tamay-dogan.net>:
550 User <gc4668> unknown
<19>1 2018-03-20T14:12:53.871912+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20090120171902.gh29556@tamay-dogan.net>:
550 User <20090120171902.gh29556> unknown
<19>1 2018-03-20T14:12:54.150525+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<ga16968@tamay-dogan.net>:
550 User <ga16968> unknown
<19>1 2018-03-20T14:12:54.428472+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20080919175920.gn6606@tamay-dogan.net>:
550 User <20080919175920.gn6606> unknown
<19>1 2018-03-20T14:12:55.068198+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20100613011722.gt8243@tamay-dogan.net>:
550 User <20100613011722.gt8243> unknown
<19>1 2018-03-20T14:12:55.346134+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20100625180153.gk21273@tamay-dogan.net>:
550 User <20100625180153.gk21273> unknown
<19>1 2018-03-20T14:12:55.623873+01:00 mail courieresmtpd  - - 
error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20100625175945.gj21273@tamay-dogan.net>:
550 User <20100625175945.gj21273> unknown
<19>1 2018-03-20T14:38:50.419729+01:00 mail courieresmtpd  - - 
error,relay=::ffff:117.92.197.86,from=<linux4michelle@tamay-dogan.net>,to=<357302542@qq.com>:
513 Relaying denied.
<19>1 2018-03-20T14:41:27.958625+01:00 mail courieresmtpd  - - 
error,relay=::ffff:117.92.197.127,from=<linliu@nwpu.edu.cn>,to=<357302542@qq.com>:
513 Relaying denied.
<19>1 2018-03-20T15:09:00.471862+01:00 mail courieresmtpd  - - 
error,relay=::ffff:185.174.23.64,from=<UseItTonight!@edhealthnews.bid>:
517 Syntax error.
<19>1 2018-03-20T15:41:10.257348+01:00 mail courieresmtpd  - - 
error,relay=::ffff:172.82.152.171,from=<tejrryt@ecookinggames.com>,to=<paypal-20100801@electronica.tamay-dogan.net>:
550 User <paypal-20100801> unknown
<19>1 2018-03-20T16:14:00.353685+01:00 mail courieresmtpd  - - 
error,relay=::ffff:208.75.123.179,from=<AQI+Wk8iNSxS0XolMljf1PA==_1116135183271_t/XSwIj2EeOG0dSuUpLDbw==@in.constantcontact.com>:
517 Sender rejected:
AQI+Wk8iNSxS0XolMljf1PA==_1116135183271_t/XSwIj2EeOG0dSuUpLDbw==@in.constantcontact.com
<19>1 2018-03-20T16:34:48.052173+01:00 mail courieresmtpd  - - 
error,relay=::ffff:182.42.41.202,from=<support@itsystems.tamay-dogan.net>,to=<2326410519@qq.com>:
513 Relaying denied.
<19>1 2018-03-20T16:38:36.411862+01:00 mail courieresmtpd  - - 
error,relay=::ffff:144.255.49.177,from=<support@itsystems.tamay-dogan.net>,to=<2326410519@qq.com>:
513 Relaying denied.
<19>1 2018-03-20T16:42:22.206625+01:00 mail courieresmtpd  - - 
error,relay=::ffff:106.6.96.21,from=<Henry.bny5@hotmail.com>: 517
Sender rejected: Henry.bny5@hotmail.com
<19>1 2018-03-20T16:48:08.209013+01:00 mail courieresmtpd  - - 
error,relay=::ffff:208.75.123.168,from=<AgQ9YUHscSU2PUBnZ5q2g2A==_1116135183271_t/XSwIj2EeOG0dSuUpLDbw==@in.constantcontact.com>:
517 Sender rejected:
AgQ9YUHscSU2PUBnZ5q2g2A==_1116135183271_t/XSwIj2EeOG0dSuUpLDbw==@in.constantcontact.com
<19>1 2018-03-20T17:05:49.162600+01:00 mail courieresmtpd  - - 
error,relay=::ffff:66.135.215.120,from=<ebay@ebay.de>,to=<ebay@itsystems.tamay-dogan.net>:
550 User <ebay> unknown
------------------------------------------------------------------------

only arround 60 today!

On a spammy day I get more then 50.000 (!) entries.

However, I host more then 200 domains and hosts on the server and ALL
get spamed, even if they have never used for mailing. (I asked my
customers to use unused mailaccounts as catchall to get the spamers)

;-)

> This has reduced with the decline of small (and
> large!) businesses running their own private SMTP servers but
> downloading their mail from a single shared external POP3 account,
> which used to be a very common practice.

Who is still offering pop3?

Thanks in advance

-- 
Michelle Konzack        Miila ITSystems @ TDnet
GNU/Linux Developer     00372-54541400

[toc] | [prev] | [next] | [standalone]


#193973

FromBrian <ad44@cityscape.co.uk>
Date2018-03-21 01:20 +0100
Message-ID<vvzDX-34n-1@gated-at.bofh.it>
In reply to#193963
On Tue 20 Mar 2018 at 20:54:47 +0200, Michelle Konzack wrote:

> Am 2018-03-20 hackte Joe in die Tasten:

[...]

> > This has reduced with the decline of small (and
> > large!) businesses running their own private SMTP servers but
> > downloading their mail from a single shared external POP3 account,
> > which used to be a very common practice.
> 
> Who is still offering pop3?

Gmail and gmx and probably lots of others.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#193976

FromBrad Rogers <brad@fineby.me.uk>
Date2018-03-21 08:10 +0100
Message-ID<vvG2J-7qm-3@gated-at.bofh.it>
In reply to#193973

[Multipart message — attachments visible in raw view] — view raw

On Wed, 21 Mar 2018 00:18:55 +0000
Brian <ad44@cityscape.co.uk> wrote:

Hello Brian,

>On Tue 20 Mar 2018 at 20:54:47 +0200, Michelle Konzack wrote:
>> Who is still offering pop3?  
>Gmail and gmx and probably lots of others.

Most others, I suspect.

I won't use IMAP at all.

-- 
 Regards  _
         / )           "The blindingly obvious is
        / _)rad        never immediately apparent"
Well you tried it just the once and found it alright for kicks
Orgasm Addict - Buzzcocks

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | linux.debian.user


csiph-web