Mass Spam

Soldato
OP
Joined
21 Jul 2004
Posts
6,332
Location
Bromley / Uxbridge
Hxc said:
cPanel's email programs are absolutly awful at dealing with spam, I'd use a mail client and a software spam filter to do anything to a domain account.

Well it has just started today... so it is someone using my domain. And at present I am not worried about receiving it, but more about my domain being blacklisted :(
 
Soldato
OP
Joined
21 Jul 2004
Posts
6,332
Location
Bromley / Uxbridge
Syk3 said:
:p I get a lot of spam on my website emails - i just filter dodgey words at the front of the email addresses and it automatically deletes them.

Yes, but this is not from the spammer... these emails are "failed delivery" emails because the spammer is using my domain name as the sender's details...

Filtering the content will stop me receiving them, but will not stop the spammer using my domain and getting it blacklisted...
 
Suspended
Joined
4 Aug 2003
Posts
3,054
Danger Phoenix said:
Oh... hmm... GRRR! My domain name is (my name), and I want to keep it! Who would blacklist it? I may contact them right now...
You may have a long day and night ahead of you then :(

Here are some links that might help:
The first time I got added to a Blacklist was many years ago over one Christmas when someone exploited the sendmail open relay that I had left open. Got into work after the holiday to discover masses of emails telling me to stop sending out spam and that I couldn't send or receive email - nightmare!

For what it is worth, you may never get put onto any list - good luck, truly.
 
Associate
Joined
11 Sep 2005
Posts
1,883
Location
Southport
Shackley said:
The first time I got added to a Blacklist was many years ago over one Christmas when someone exploited the sendmail open relay that I had left open. Got into work after the holiday to discover masses of emails telling me to stop sending out spam and that I couldn't send or receive email - nightmare!

For what it is worth, you may never get put onto any list - good luck, truly.
Had the same thing here, except it wasn't so much an exploit, just me not securing the SMTP server properly :) Took literally about 2 days from me turning the server on for spammers to find it and send about 3000 emails through my poor p233 box :p

To the OP: Good luck with whatever you try and do to fix it, sounds like you could be screwed though if somebody is spoofing your domain :(
 
Soldato
Joined
1 Aug 2006
Posts
3,468
Location
GU21
I've had the same issue with bounced emails. I came back from holiday in June to find I was receiving about 1000 emails every half hour or so. I have basically had to block (in cpanel) anything from postmaster or mailer-daemon or the like, and anything with ***SPAM*** in the title.

I don't get many of them now but unfortunately I would imagine my domain's reputation will suffer somewhat.

:(
 
Soldato
OP
Joined
21 Jul 2004
Posts
6,332
Location
Bromley / Uxbridge
I randomly emailed someone from Spamhaus, and this is what they said:

Hi, no, you can not be blacklisted for this problem. This problem happens all the time to thousands of people every day, the blacklists never act on the address the spam says it is "From" as we know this is always false.

The 'bounce attack' on you will stop in a day or two, as the spammer will change to using someone else's domain as his 'From'. So for the moment there's nothing you can do except trash the bounces.

Regards,

Steve Linford
The Spamhaus Project
http://www.spamhaus.org
 
Soldato
Joined
25 Mar 2004
Posts
15,774
Location
Fareham
yup the spam databases blacklist based upon the IP address of the sending server as it's so easy to spoof a from address.

This isn't SPAM per se, it's legitimate NDR messages that are being generated as some tard has spoofed your email addresses, the fact you have a catchall means that you will receive every last email sent to your domain.

unlucky :8
 
Soldato
OP
Joined
21 Jul 2004
Posts
6,332
Location
Bromley / Uxbridge
Phaser said:
How come you always use [email protected]

Wouldn't it be better to just setup one account for registrations etc and use that with no catchall?

I use it because it allows me to filter emails easily in my Outlook, and also if one website starts sending me spam, I can block that [email protected]...

I suppose that doesn't help when something like this happens :p


Eulogy said:
yup the spam databases blacklist based upon the IP address of the sending server as it's so easy to spoof a from address.

This isn't SPAM per se, it's legitimate NDR messages that are being generated as some tard has spoofed your email addresses, the fact you have a catchall means that you will receive every last email sent to your domain.

unlucky :8

Yeah... I wish I could kill the guy, because sifting through the emails trying to spot the ones I want to keep is becoming a headache. The spam has picking up again to around 5 every minute... still less than this morning.

If tomorrow there is a news article saying "Spammer Killed In Frenzied Attack" it wasn't me ;)
 

Bry

Bry

Associate
Joined
24 Jul 2005
Posts
1,374
depending upon how many different [email protected] you could try setting up forwarders in cpanel.
As i was getting around 300 spam emails a day and i had a catchall email and have about 5 email addresses like forum@domain and support@domain

What i did was turn catch all off, setup my main address and then forward the other address (forum@ support@ etc) to my main address.
This had the effect of stopping all the random names@domain email from getting through but still allowing me to use the few other addresses i wanted to use.

Obviously the degree of success with this will only work depending upon how amny addresses you have and whether or not they are all going to certain addresses or random ones
 
Soldato
OP
Joined
21 Jul 2004
Posts
6,332
Location
Bromley / Uxbridge
I have hundreds of addresses, which makes it near impossible to do... for every site I have signed up at, or for everything I have put my email address down, it is a different alias.

Ranging from giving Barclays my email address to placing an order online at HSS...
 
Back
Top Bottom