Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #193897 > unrolled thread
| Started by | "Michelle Konzack" <linux4michelle@tamay-dogan.net> |
|---|---|
| First post | 2018-03-19 14:00 +0100 |
| Last post | 2018-03-21 08:10 +0100 |
| Articles | 9 on this page of 29 — 17 participants |
Back to article view | Back to linux.debian.user
More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 14:00 +0100
Re: More then 2800 spams from the list... Jonathan Dowland <jmtd@debian.org> - 2018-03-19 14:20 +0100
Re: More then 2800 spams from the list... Gene Heskett <gheskett@shentel.net> - 2018-03-19 15:50 +0100
Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 15:50 +0100
Re: More then 2800 spams from the list... Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-03-19 16:10 +0100
Re: More then 2800 spams from the list... Richard Owlett <rowlett@cloud85.net> - 2018-03-19 16:30 +0100
Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 16:40 +0100
Re: More then 2800 spams from the list... Jim Popovitch <jim@k4vqc.com> - 2018-03-19 17:00 +0100
Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 17:30 +0100
Re: More then 2800 spams from the list... Miles Fidelman <mfidelman@meetinghouse.net> - 2018-03-19 18:50 +0100
Re: More then 2800 spams from the list... Tony van der Hoff <lists@vanderhoff.org> - 2018-03-19 19:20 +0100
Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-19 19:30 +0100
Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-19 19:40 +0100
Re: More then 2800 spams from the list... Gene Heskett <gheskett@shentel.net> - 2018-03-19 16:40 +0100
Re: More then 2800 spams from the list... Curt <curty@free.fr> - 2018-03-19 18:20 +0100
Re: More then 2800 spams from the list... Richard Owlett <rowlett@cloud85.net> - 2018-03-19 16:00 +0100
Re: More then 2800 spams from the list... Karol Augustin <karol@augustin.pl> - 2018-03-19 19:40 +0100
Re: More then 2800 spams from the list... Nick Boyce <nick@steelyglint.org> - 2018-03-19 22:20 +0100
Re: More then 2800 spams from the list... Karol Augustin <karol@augustin.pl> - 2018-03-19 22:40 +0100
Re: More then 2800 spams from the list... Joe <joe@jretrading.com> - 2018-03-19 23:30 +0100
Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-20 09:00 +0100
Re: More then 2800 spams from the list... Joe <joe@jretrading.com> - 2018-03-20 10:30 +0100
Re: More then 2800 spams from the list... <tomas@tuxteam.de> - 2018-03-20 10:50 +0100
Re: More then 2800 spams from the list... Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-20 13:30 +0100
Re: More then 2800 spams from the list... David Wright <deblis@lionunicorn.co.uk> - 2018-03-20 14:40 +0100
Re: More then 2800 spams from the list... Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-20 14:50 +0100
Re: More then 2800 spams from the list... "Michelle Konzack" <linux4michelle@tamay-dogan.net> - 2018-03-20 20:00 +0100
Re: More then 2800 spams from the list... Brian <ad44@cityscape.co.uk> - 2018-03-21 01:20 +0100
Re: More then 2800 spams from the list... Brad Rogers <brad@fineby.me.uk> - 2018-03-21 08:10 +0100
Page 2 of 2 — ← Prev page 1 [2]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2018-03-20 09:00 +0100 |
| Message-ID | <vvklA-1la-9@gated-at.bofh.it> |
| In reply to | #193934 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, Mar 19, 2018 at 10:21:57PM +0000, Joe wrote: [...] > > This is precisely why e-mail server should never send bounces to > > non-local senders. When sender is spoofed as in this case then is hit > > with thousands of DSNs. [delivery status notification] [...] > You do it by never accepting email for non-existent users. The problem > is the use of a mail server which accepts absolutely anything for the > domain, then finds that the end user rejects the rubbish. Having > accepted it in the first place, the receiving mail server is then > required to admit that it can't deliver it, by means of an NDR. It does > this using the reply-to address, which is easily forged. "never" is too strong a word. This is a corollary of the fundamental law "all generalizations suck". But yes, in general it is a bad idea to bounce a mail automatically if you don't have control over its provenience. FWIW, I did the experiment and sent a mail to a random user at one of Michelle's reported domains: I got no bounce. This is a strong hint (no proof, mind you!) that the whole bounces are spoofed in this case. The reported headers in those bounces do look strange (to me, anyway), but I'm willing to admit that I'm not smart enough to grok them. Cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlqwvdAACgkQBcgs9XrR2kYQ+ACfWNYAJyDeT+7vMILqV4MUcTdV V24An1I7UBTaj6BdeGV5ral2IC68oe+A =ahYU -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2018-03-20 10:30 +0100 |
| Message-ID | <vvlKF-2l7-1@gated-at.bofh.it> |
| In reply to | #193938 |
On Tue, 20 Mar 2018 08:52:48 +0100 <tomas@tuxteam.de> wrote: > > > "never" is too strong a word. This is a corollary of the fundamental > law "all generalizations suck". > How do you determine the exceptions? A SMTP server, by default, accepts email only for recipients which have an account on it. Aliases can be added, but on the whole, there is no mechanism for a 'catch-all' mailbox. Someone has to deliberately add some code to make such a thing happen. This has even been true of Exchange for the last few versions. It's generally not difficult, but it's not there out of the box. There won't be any NDR spam if all the invalid email goes into one particular account for a human to examine. The problem occurs if and when a later SMTP server attempts to download and deliver this email to multiple people who don't exist. A salesman might argue that if only valid accounts are accepted, he might miss a valuable sale because of a mis-spelled email address. In other words, no price is too high for the rest of the Internet to pay for him to get one more lead, no matter how poor. I'm not a salesman, so I see things differently. Things aren't as bad as they used to be, probably 90% of what my mail server refused was once NDR spam. I could see in the logs the same dozen obviously deliberately incorrect email addresses every day, sometimes several times a day. This has reduced with the decline of small (and large!) businesses running their own private SMTP servers but downloading their mail from a single shared external POP3 account, which used to be a very common practice. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2018-03-20 10:50 +0100 |
| Message-ID | <vvm41-2r8-1@gated-at.bofh.it> |
| In reply to | #193942 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, Mar 20, 2018 at 09:21:03AM +0000, Joe wrote: > On Tue, 20 Mar 2018 08:52:48 +0100 > <tomas@tuxteam.de> wrote: > > > > > > > "never" is too strong a word. This is a corollary of the fundamental > > law "all generalizations suck". > > > How do you determine the exceptions? With care and measure :-) > A SMTP server, by default, accepts email only for recipients which have > an account on it. Aliases can be added, but on the whole, there is no > mechanism for a 'catch-all' mailbox. Someone has to deliberately add > some code to make such a thing happen. This has even been true of > Exchange for the last few versions. It's generally not difficult, but > it's not there out of the box. I, for example, do have a "catch-all" box. That's me. And I'm not a salesman :-) But with such a setup you've got to cope with *some* spam, that's correct. What you should not do is to accept a mail for forwarding to another system you don't control (or are somewhat related to): that system could very well reject that mail, and now you have a problem. This would be what's called an "open relay". In these times, better not do that. Cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlqw1wcACgkQBcgs9XrR2kZaiwCfSeEG7MoiZOViagrxjAFyMdXa 1q4Ani0cS3rSfJmvGYO0As503h1QUnCo =Vzt2 -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2018-03-20 13:30 +0100 |
| Message-ID | <vvoyS-45M-17@gated-at.bofh.it> |
| In reply to | #193942 |
On Tue, Mar 20, 2018 at 09:21:03AM +0000, Joe wrote: > A SMTP server, by default, accepts email only for recipients which have > an account on it. If only. No, that's part of the problem. An SMTP server, *by default*, has no knowledge of which local-recipient-parts are valid and which are not. It has to communicate with some other system, process, library, or whatever, to make that determination. It's much easier for an SMTP server to validate just the domain-part (right of the @ sign), and generate bounces when it turns out that the local-recipient-part (left of the @ sign) is invalid. This is how things worked 25 years ago. Unfortunately, humans being the despicable creatures that they are, that naive system no longer works. P.S. someone said that bounces are generated using the Reply-To: header. This is incorrect (or at least, would be a violation of the protocols). Bounces are sent to the envelope sender address (the one given by the sender during the SMTP session), without looking at the message itself. Of course, the envelope sender is just as easy to forge as the Reply-To: header is. The sender only needs to lie about who it is. The receiver has no way to verify the address, other than "yeah, that domain exists in DNS". That's how backscatter (a.k.a. "joe-jobbing") works. The spammer sends mail to an invalid address and lies about the envelope sender address. The receiver generates a bounce to the forged envelope sender address. Voila, spam sent -- by the poor schmuck in the middle who was just trying to follow the SMTP protocol properly. The only one who can identify the actual sender is the one who generated the bounce, and the only identifying information that system has is the IP address from which the message was sent. Everything else (envelope sender, message headers, message body) is fabricated.
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2018-03-20 14:40 +0100 |
| Message-ID | <vvpEC-4Lh-13@gated-at.bofh.it> |
| In reply to | #193947 |
On Tue 20 Mar 2018 at 08:28:20 (-0400), Greg Wooledge wrote: > P.S. someone said that bounces are generated using the Reply-To: header. > This is incorrect (or at least, would be a violation of the protocols). > Bounces are sent to the envelope sender address (the one given by the > sender during the SMTP session), without looking at the message itself. > > Of course, the envelope sender is just as easy to forge as the > Reply-To: header is. The sender only needs to lie about who it is. > The receiver has no way to verify the address, other than "yeah, that > domain exists in DNS". But if that IP address sends loads of undeliverable mail, why not just block it? I was under the impression that that's what IP address blacklisting was all about. > That's how backscatter (a.k.a. "joe-jobbing") works. The spammer > sends mail to an invalid address and lies about the envelope sender > address. The receiver generates a bounce to the forged envelope > sender address. Voila, spam sent -- by the poor schmuck in the middle > who was just trying to follow the SMTP protocol properly. The only > one who can identify the actual sender is the one who generated the > bounce, and the only identifying information that system has is the > IP address from which the message was sent. Everything else (envelope > sender, message headers, message body) is fabricated. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2018-03-20 14:50 +0100 |
| Message-ID | <vvpOh-4OW-3@gated-at.bofh.it> |
| In reply to | #193949 |
On Tue, Mar 20, 2018 at 08:30:50AM -0500, David Wright wrote: > On Tue 20 Mar 2018 at 08:28:20 (-0400), Greg Wooledge wrote: > > P.S. someone said that bounces are generated using the Reply-To: header. > > This is incorrect (or at least, would be a violation of the protocols). > > Bounces are sent to the envelope sender address (the one given by the > > sender during the SMTP session), without looking at the message itself. > > > > Of course, the envelope sender is just as easy to forge as the > > Reply-To: header is. The sender only needs to lie about who it is. > > The receiver has no way to verify the address, other than "yeah, that > > domain exists in DNS". > > But if that IP address sends loads of undeliverable mail, > why not just block it? I was under the impression that > that's what IP address blacklisting was all about. That happens, certainly. But not everyone is using a blacklist. The spammer just has to find one system that's vulnerable and keep hammering it until it, too, gets blacklisted.
[toc] | [prev] | [next] | [standalone]
| From | "Michelle Konzack" <linux4michelle@tamay-dogan.net> |
|---|---|
| Date | 2018-03-20 20:00 +0100 |
| Message-ID | <vvuEi-7Yg-5@gated-at.bofh.it> |
| In reply to | #193942 |
Hi Joe, Am 2018-03-20 hackte Joe in die Tasten: > A SMTP server, by default, accepts email only for recipients which > have > an account on it. Aliases can be added, but on the whole, there is no > mechanism for a 'catch-all' mailbox. Someone has to deliberately add > some code to make such a thing happen. Not realy true, because I have setup a honnypot for a (new) domain which NEVER send or receive any mails and used @example.com: honigtopf which accept anything! However, this EMails are forwarded to a RBL provider which use it for analysing... ;-) > This has even been true of > Exchange for the last few versions. It's generally not difficult, but > it's not there out of the box. Courier can do this as well as exim and postfix! Out-of-the-Box! Please read the documentation! > Things aren't as bad as they used to be, probably 90% of what my mail > server refused was once NDR spam. I could see in the logs the same > dozen > obviously deliberately incorrect email addresses every day, sometimes > several times a day. Hmmm I just checked, and verified twice, but the spammers are sleeping today: ----[ /var/log/mail_err.log ]------------------------------------------- <19>1 2018-03-20T01:46:16.855550+01:00 mail courieresmtpd - - error,relay=::ffff:194.181.177.172,from=<Info.Googlepromo@info.com>: 517 Sender rejected: Info.Googlepromo@info.com <19>1 2018-03-20T01:48:27.104049+01:00 mail courieresmtpd - - error,relay=::ffff:78.47.104.44,from=<#@[]>: 517 Syntax error. <19>1 2018-03-20T02:10:01.608879+01:00 mail courieresmtpd - - error,relay=::ffff:185.174.23.54,from=<SexualHealth@visionveryclear.bid>,to=<jfc53@tdwave.net>: 556 Address unavailable. <19>1 2018-03-20T02:46:27.744330+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20090120171902.gh29556@tamay-dogan.net>: 550 User <20090120171902.gh29556> unknown <19>1 2018-03-20T02:46:28.053447+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<ga16968@tamay-dogan.net>: 550 User <ga16968> unknown <19>1 2018-03-20T02:46:28.369856+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20080919175920.gn6606@tamay-dogan.net>: 550 User <20080919175920.gn6606> unknown <19>1 2018-03-20T02:46:28.679337+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20100613011722.gt8243@tamay-dogan.net>: 550 User <20100613011722.gt8243> unknown <19>1 2018-03-20T02:46:28.988781+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20100625180153.gk21273@tamay-dogan.net>: 550 User <20100625180153.gk21273> unknown <19>1 2018-03-20T02:46:29.298216+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<cucks@glows-training.co.uk>,to=<20100625175945.gj21273@tamay-dogan.net>: 550 User <20100625175945.gj21273> unknown <19>1 2018-03-20T03:35:17.173606+01:00 mail courieresmtpd - - error,relay=::ffff:121.40.42.27,from=<subinahan57@nate.com>,to=<gg4653@tamay-dogan.net>: 550 User <gg4653> unknown <19>1 2018-03-20T03:35:17.437402+01:00 mail courieresmtpd - - error,relay=::ffff:121.40.42.27,from=<subinahan57@nate.com>,to=<gc4668@tamay-dogan.net>: 550 User <gc4668> unknown <19>1 2018-03-20T03:35:17.700985+01:00 mail courieresmtpd - - error,relay=::ffff:121.40.42.27,from=<subinahan57@nate.com>,to=<ga4668@tamay-dogan.net>: 550 User <ga4668> unknown <19>1 2018-03-20T04:02:31.999498+01:00 mail courieresmtpd - - error,relay=::ffff:220.181.97.175,from=<sales@cubeel.com>,to=<einkauf@electronica.tamay-dogan.net>: 550 User <einkauf> unknown <19>1 2018-03-20T04:42:16.719343+01:00 mail courieresmtpd - - error,relay=::ffff:119.177.128.214,from=<chulmim5@gmail.com>,to=<ge4653@tamay-dogan.net>: 550 User <ge4653> unknown <19>1 2018-03-20T04:42:17.023533+01:00 mail courieresmtpd - - error,relay=::ffff:119.177.128.214,from=<chulmim5@gmail.com>,to=<gm2093@tamay-dogan.net>: 550 User <gm2093> unknown <19>1 2018-03-20T04:43:09.854792+01:00 mail courieresmtpd - - error,relay=::ffff:194.181.177.172,from=<Info.Googlepromo@info.com>: 517 Sender rejected: Info.Googlepromo@info.com <19>1 2018-03-20T04:45:31.704422+01:00 mail courieresmtpd - - error,relay=::ffff:182.139.29.77,from=<1991019554@qq.com>,to=<20100613011722.GT8243@tamay-dogan.net>: 550 User <20100613011722.GT8243> unknown <19>1 2018-03-20T04:50:10.555313+01:00 mail courieresmtpd - - error,relay=::ffff:182.139.29.77,from=<2302627349@qq.com>,to=<20100625175945.GJ21273@tamay-dogan.net>: 550 User <20100625175945.GJ21273> unknown <19>1 2018-03-20T04:50:11.067588+01:00 mail courieresmtpd - - error,relay=::ffff:182.139.29.77,from=<1991019554@qq.com>,to=<20100625180153.GK21273@tamay-dogan.net>: 550 User <20100625180153.GK21273> unknown <19>1 2018-03-20T06:55:51.421165+01:00 mail courieresmtpd - - error,relay=::ffff:111.160.38.150,from=<chulmim5@gmail.com>,to=<gc4668@tamay-dogan.net>: 550 User <gc4668> unknown <19>1 2018-03-20T06:55:51.770953+01:00 mail courieresmtpd - - error,relay=::ffff:111.160.38.150,from=<chulmim5@gmail.com>,to=<ga4668@tamay-dogan.net>: 550 User <ga4668> unknown <19>1 2018-03-20T06:55:52.105612+01:00 mail courieresmtpd - - error,relay=::ffff:111.160.38.150,from=<chulmim5@gmail.com>,to=<gg4653@tamay-dogan.net>: 550 User <gg4653> unknown <19>1 2018-03-20T07:12:27.384536+01:00 mail courieresmtpd - - error,relay=::ffff:78.47.104.44,from=<#@[]>: 517 Syntax error. <19>1 2018-03-20T07:22:53.284402+01:00 mail courieresmtpd - - error,relay=::ffff:119.90.24.64,from=<subinahan57@nate.com>,to=<ge4653@tamay-dogan.net>: 550 User <ge4653> unknown <19>1 2018-03-20T07:22:53.603333+01:00 mail courieresmtpd - - error,relay=::ffff:119.90.24.64,from=<subinahan57@nate.com>,to=<gm2093@tamay-dogan.net>: 550 User <gm2093> unknown <19>1 2018-03-20T07:53:55.102715+01:00 mail courieresmtpd - - error,relay=::ffff:40.92.65.48,from=<ahmedhakim@live.com>: 517 Sender rejected: ahmedhakim@live.com <19>1 2018-03-20T08:53:15.523049+01:00 mail courieresmtpd - - error,relay=::ffff:61.160.101.114,from=<natminroll@gmail.com>,to=<ga4668@tamay-dogan.net>: 550 User <ga4668> unknown <19>1 2018-03-20T08:53:15.813412+01:00 mail courieresmtpd - - error,relay=::ffff:61.160.101.114,from=<natminroll@gmail.com>,to=<gc4668@tamay-dogan.net>: 550 User <gc4668> unknown <19>1 2018-03-20T08:53:16.105498+01:00 mail courieresmtpd - - error,relay=::ffff:61.160.101.114,from=<natminroll@gmail.com>,to=<gg4653@tamay-dogan.net>: 550 User <gg4653> unknown <19>1 2018-03-20T10:06:35.760419+01:00 mail courieresmtpd - - error,relay=::ffff:114.237.210.113,from=<support@itsystems.tamay-dogan.net>,to=<2326410519@qq.com>: 513 Relaying denied. <19>1 2018-03-20T10:11:42.659188+01:00 mail courieresmtpd - - error,relay=::ffff:114.237.210.128,from=<support@jiangmin.com>,to=<2326410519@qq.com>: 513 Relaying denied. <19>1 2018-03-20T10:36:14.814806+01:00 mail courieresmtpd - - error,relay=2607:f8b0:4001:c06::246,from=<399WwWgcLAEIrsvitp22syxyfi.gsq@youtube-subscriptions.bounces.google.com>,to=<google@electronica.tamay-dogan.net>: 550 User <google> unknown <19>1 2018-03-20T11:00:14.046567+01:00 mail courieresmtpd - - error,relay=::ffff:185.174.23.49,from=<FixYourTightHips@fixtighthips.bid>,to=<jfc53@tdwave.net>: 556 Address unavailable. <19>1 2018-03-20T12:12:43.298844+01:00 mail courieresmtpd - - error,relay=::ffff:61.175.186.125,from=<fma@fmtunisie.com>: 517-Domain does not exist: fmtunisie.com. <19>1 2018-03-20T12:12:43.299010+01:00 mail courieresmtpd - - error,relay=::ffff:61.175.186.125,from=<fma@fmtunisie.com>: 517 Invalid domain, see <URL:ftp://ftp.isi.edu/in-notes/rfc1035.txt> <19>1 2018-03-20T12:12:48.359610+01:00 mail courieresmtpd - - error,relay=::ffff:61.175.186.125,from=<fma@fmtunisie.com>: 517-Domain does not exist: fmtunisie.com. <19>1 2018-03-20T12:12:48.359760+01:00 mail courieresmtpd - - error,relay=::ffff:61.175.186.125,from=<fma@fmtunisie.com>: 517 Invalid domain, see <URL:ftp://ftp.isi.edu/in-notes/rfc1035.txt> <19>1 2018-03-20T12:17:00.588129+01:00 mail courieresmtpd - - error,relay=::ffff:185.174.23.43,from=<LossofNails@fixtoenails.bid>,to=<jfc53@tdwave.net>: 556 Address unavailable. <19>1 2018-03-20T13:40:39.638981+01:00 mail courieresmtpd - - error,relay=::ffff:112.116.220.112,from=<gjungmin81@korea.com>,to=<gg4653@tamay-dogan.net>: 550 User <gg4653> unknown <19>1 2018-03-20T13:40:40.089566+01:00 mail courieresmtpd - - error,relay=::ffff:112.116.220.112,from=<gjungmin81@korea.com>,to=<ga4668@tamay-dogan.net>: 550 User <ga4668> unknown <19>1 2018-03-20T13:40:40.529563+01:00 mail courieresmtpd - - error,relay=::ffff:112.116.220.112,from=<gjungmin81@korea.com>,to=<gc4668@tamay-dogan.net>: 550 User <gc4668> unknown <19>1 2018-03-20T14:12:53.871912+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20090120171902.gh29556@tamay-dogan.net>: 550 User <20090120171902.gh29556> unknown <19>1 2018-03-20T14:12:54.150525+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<ga16968@tamay-dogan.net>: 550 User <ga16968> unknown <19>1 2018-03-20T14:12:54.428472+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20080919175920.gn6606@tamay-dogan.net>: 550 User <20080919175920.gn6606> unknown <19>1 2018-03-20T14:12:55.068198+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20100613011722.gt8243@tamay-dogan.net>: 550 User <20100613011722.gt8243> unknown <19>1 2018-03-20T14:12:55.346134+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20100625180153.gk21273@tamay-dogan.net>: 550 User <20100625180153.gk21273> unknown <19>1 2018-03-20T14:12:55.623873+01:00 mail courieresmtpd - - error,relay=::ffff:27.116.21.218,from=<xzrofnihhl@glowpak.com>,to=<20100625175945.gj21273@tamay-dogan.net>: 550 User <20100625175945.gj21273> unknown <19>1 2018-03-20T14:38:50.419729+01:00 mail courieresmtpd - - error,relay=::ffff:117.92.197.86,from=<linux4michelle@tamay-dogan.net>,to=<357302542@qq.com>: 513 Relaying denied. <19>1 2018-03-20T14:41:27.958625+01:00 mail courieresmtpd - - error,relay=::ffff:117.92.197.127,from=<linliu@nwpu.edu.cn>,to=<357302542@qq.com>: 513 Relaying denied. <19>1 2018-03-20T15:09:00.471862+01:00 mail courieresmtpd - - error,relay=::ffff:185.174.23.64,from=<UseItTonight!@edhealthnews.bid>: 517 Syntax error. <19>1 2018-03-20T15:41:10.257348+01:00 mail courieresmtpd - - error,relay=::ffff:172.82.152.171,from=<tejrryt@ecookinggames.com>,to=<paypal-20100801@electronica.tamay-dogan.net>: 550 User <paypal-20100801> unknown <19>1 2018-03-20T16:14:00.353685+01:00 mail courieresmtpd - - error,relay=::ffff:208.75.123.179,from=<AQI+Wk8iNSxS0XolMljf1PA==_1116135183271_t/XSwIj2EeOG0dSuUpLDbw==@in.constantcontact.com>: 517 Sender rejected: AQI+Wk8iNSxS0XolMljf1PA==_1116135183271_t/XSwIj2EeOG0dSuUpLDbw==@in.constantcontact.com <19>1 2018-03-20T16:34:48.052173+01:00 mail courieresmtpd - - error,relay=::ffff:182.42.41.202,from=<support@itsystems.tamay-dogan.net>,to=<2326410519@qq.com>: 513 Relaying denied. <19>1 2018-03-20T16:38:36.411862+01:00 mail courieresmtpd - - error,relay=::ffff:144.255.49.177,from=<support@itsystems.tamay-dogan.net>,to=<2326410519@qq.com>: 513 Relaying denied. <19>1 2018-03-20T16:42:22.206625+01:00 mail courieresmtpd - - error,relay=::ffff:106.6.96.21,from=<Henry.bny5@hotmail.com>: 517 Sender rejected: Henry.bny5@hotmail.com <19>1 2018-03-20T16:48:08.209013+01:00 mail courieresmtpd - - error,relay=::ffff:208.75.123.168,from=<AgQ9YUHscSU2PUBnZ5q2g2A==_1116135183271_t/XSwIj2EeOG0dSuUpLDbw==@in.constantcontact.com>: 517 Sender rejected: AgQ9YUHscSU2PUBnZ5q2g2A==_1116135183271_t/XSwIj2EeOG0dSuUpLDbw==@in.constantcontact.com <19>1 2018-03-20T17:05:49.162600+01:00 mail courieresmtpd - - error,relay=::ffff:66.135.215.120,from=<ebay@ebay.de>,to=<ebay@itsystems.tamay-dogan.net>: 550 User <ebay> unknown ------------------------------------------------------------------------ only arround 60 today! On a spammy day I get more then 50.000 (!) entries. However, I host more then 200 domains and hosts on the server and ALL get spamed, even if they have never used for mailing. (I asked my customers to use unused mailaccounts as catchall to get the spamers) ;-) > This has reduced with the decline of small (and > large!) businesses running their own private SMTP servers but > downloading their mail from a single shared external POP3 account, > which used to be a very common practice. Who is still offering pop3? Thanks in advance -- Michelle Konzack Miila ITSystems @ TDnet GNU/Linux Developer 00372-54541400
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2018-03-21 01:20 +0100 |
| Message-ID | <vvzDX-34n-1@gated-at.bofh.it> |
| In reply to | #193963 |
On Tue 20 Mar 2018 at 20:54:47 +0200, Michelle Konzack wrote: > Am 2018-03-20 hackte Joe in die Tasten: [...] > > This has reduced with the decline of small (and > > large!) businesses running their own private SMTP servers but > > downloading their mail from a single shared external POP3 account, > > which used to be a very common practice. > > Who is still offering pop3? Gmail and gmx and probably lots of others. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Brad Rogers <brad@fineby.me.uk> |
|---|---|
| Date | 2018-03-21 08:10 +0100 |
| Message-ID | <vvG2J-7qm-3@gated-at.bofh.it> |
| In reply to | #193973 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, 21 Mar 2018 00:18:55 +0000
Brian <ad44@cityscape.co.uk> wrote:
Hello Brian,
>On Tue 20 Mar 2018 at 20:54:47 +0200, Michelle Konzack wrote:
>> Who is still offering pop3?
>Gmail and gmx and probably lots of others.
Most others, I suspect.
I won't use IMAP at all.
--
Regards _
/ ) "The blindingly obvious is
/ _)rad never immediately apparent"
Well you tried it just the once and found it alright for kicks
Orgasm Addict - Buzzcocks
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | linux.debian.user
csiph-web