'Undeliverable' spam?


Recommended Posts

Hi,

We seem to be getting a huge amount of 'undeliverable email' spam recently. As it comes through as an undeliverable, it doesn't have anything in the 'internet headers'.

I've checked the clients for mailer worms etc, where would this be coming from? Some examples below

From: System Administrator

Sent: 15 April 2008 04:48

To: [email protected] **bear in mind this is NOT our domain***

Subject: Undeliverable: Check my new photos :))

Your message did not reach some or all of the intended recipients.

Subject: Check my new photos :))

Sent: 15/04/2008 03:00

The following recipient(s) could not be reached:

[email protected] on 15/04/2008 04:48

The e-mail system was unable to deliver the message, but did not report a specific reason. Check the address and try again. If it still fails, contact your system administrator.

< ironport4.terra.cl #5.0.0 smtp; 5.1.0 - Unknown address error 550-'RCPT TO:<[email protected]> User unknown' (delivery attempts: 0)>

From: [email protected]

[mailto:[email protected]]

Sent: 14 April 2008 19:54

To: *name edited*

Subject: failure notice

Hi. This is the qmail-send program at www.dunham-bush.com.cn.

I'm afraid I wasn't able to deliver your message to the following addresses.

This is a permanent error; I've given up. Sorry it didn't work out.

<[email protected]>:

Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is a copy of the message.

Return-Path: **email edited**

Received: (qmail 31177 invoked from network); 15 Apr 2008 02:53:38 +0800

Received: from unknown (HELO 190-48-57-116.speedy.com.ar) (190.48.57.116)

by 222.135.187.29 with SMTP; 15 Apr 2008 02:53:38 +0800

Message-ID: <000801c89e64$07b06824$65e8b799@tnuehc>

From: "Julia S." name edited as it was our domain, but not 'julia s'

To: <[email protected]>

Subject: Check my new photos :))

Date: Mon, 14 Apr 2008 17:35:17 +0000

MIME-Version: 1.0

Content-Type: text/plain;

charset="iso-8859-1"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.3138

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198

Hello!

remember me?..

new fotos(archived) you asked

:))

kiss, Julia S.

What is the best way to stop these kind of emails? We are using Symantec Mail Security for SMTP v5 as our spam filter. thanks

Link to comment
https://www.neowin.net/forum/topic/631492-undeliverable-spam/
Share on other sites

Is this you? (HELO 190-48-57-116.speedy.com.ar) (190.48.57.116)

If not then you did not send it.. Spammers do NOT use their own legit address, they make them up, they use one from a list. So if you are [email protected] and I send a email to [email protected] and SAY its from "[email protected]" When that message can not be delivered to [email protected]

The gmails servers send it back where?? You guessed it [email protected] so you get a kickback saying your mail could not be delivered.

Its called backscatter

http://www.spamresource.com/2007/02/backsc...-i-stop-it.html

Backscatter: What is it? How do I stop it?

Is it also a good idea to have 'Sender ID validation" set to "Delete. The message will be accepted and deleted, no NDR will be sent back to the sender"?

Would this cause any problems?

Any other exchange settings that can be enabled to help alleviate this problem?

thanks

Additionally to randomnut - if you're going to enable recipient filtering, you should also enable tarpitting so that valid email addresses cannot be harvested from your mail server. A quick Google for Exchange tarpitting should help you out.

@CreightonB - close - it's Reverse NDR spamming. As in "non-delivery report".

HTH!

Thanks very much for your input everyone. So the plan of action is:

Enable recipient filtering

Enable tarpitting

reboot

Anything else that will help? With those 2 it should help reduce NDR spam?

thanks

EDIT: Also, will tarpitting interfere with the 3rd party spam filtering we're using?

Edited by randomnut
  • 3 weeks later...

Hey neurotronix,

Yes I implemented several things which seems to have sorted the problem out:

- enabled recipient filtering in exchange

- enabled tarpitting

- added the zen.spamhaus.org list to exchange to help drop known spam if it gets past the spam filter

- set our spam filter to have LDAP connectivity with our domain controller and not to pass any mail to people not in ADUC

Now we have a lot fewer emails getting through. Hope it helps.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • TLDR. Here is a far better title (just a basic example): Windows 11 26H2 to allow disabling Web search results
    • Restore will get my vote, only if to see if things are any different, doubt it though but Labour and Conservatives too out of touch and same thing over and over and over…, Lib Dem who?
    • There is nothing wrong with this title. You have completely missed the plot when it comes to "clickbait." The issue was never that a title tries to entice you to click, that is how titles have worked for over 100 years. The issue is when the title subverts expectations, getting you to click expecting something that isn't there. The classic clickbait example is "Boyfriend caught cheating, what happens next will shock you," then what happened next is the girlfriend was upset...which is probably the least shocking outcome imaginable. If sounds like what you want is for the titles to be a collection of 10-word summaries that you can skim, get the just of the story, and only click if you want more details. That is not, never has been, and never will be what titles are. You can go all the way back to print newspapers during the great depression and see the same thing. The newspaper was locked in a vending machine, all you can see is the headline, you choose to put in 5¢ to buy the paper and read the rest if you want. Those headlines were written in a way to sell the paper, not just to provide a summery. Here are two actual headlines from that time, "Wall Street Lays an Egg," or "Stocks Hit Bottom?" Maybe you'd say something like "it was wrong then and it's still wrong now." Okay, fine opinion to have, but it isn't like Neowin is doing something unjurnalistic, they are just following the age-old standards for written media.
    • AMD 26.6.2 driver brings FSR 4.1 support to RDNA 3 RX 7000 series graphics cards by Pulasthi Ariyasinghe A new driver is rolling out to Radeon graphics hardware owners, and alongside support for new games, AMD has just made its FSR 4.1 upscaling tech available to an entire generation of its products. Last month, AMD announced it is answering community requests to bring FSR 4.1 to past generations of its Radeon graphics cards. This would be starting with RDNA 3 RX 7000 products. Right on schedule, this is what's rolling out now with the AMD Software: Adrenalin Edition 26.6.2 driver containing official support for over 300 games. Following this, AMD is planning to bring out RDNA 2 (RX 6000 series) support for FSR 4.1 sometime in early 2027. As for the games, this Adrenalin 26.6.2 driver is a recommended install for anyone jumping into Ubisoft's upcoming Assassin's Creed Black Flag Resynced remake or id Software's DOOM: The Dark Ages' Revelations expansion. The two fixed issues in this release are these: Intermittent application crash or driver timeout may be observed while playing RoadCraft on Radeon™ RX 7000 series products. Purple screen may be displayed when using an HP Reverb G2 headset with SteamVR on Radeon™ RX 6000 series graphics products. The known issues AMD is still working on are the following: Intermittent application crash or driver timeout may be observed while playing Battlefield 6 on AMD Ryzen AI 9 HX 370. AMD is actively working on a resolution with the developer to be released as soon as possible. Texture flickering or corruption may appear while playing Battlefield 6 with AMD Record and Stream on some AMD graphics products. AMD FSR Upscaling and AMD FSR Frame Generation may show as inactive in AMD Software: Adrenalin Edition while playing Battlefield 6 when enabled on Radeon™ RX 9000 series graphics products. Failure to install may be observed while installing AI Bundle components in some regions with limited access to HuggingFace and GitHub. Model flickering or rendering failure may be observed in Maxon Cinema 4D and Blender on Radeon RX 7000 series and above graphics products. Users experiencing this issue are recommended to install AMD Software: Adrenalin Edition 26.3.1. Intermittent application crash may be observed on some models while running Blender on Radeon RX 7000 and above graphics products. Users experiencing this issue are recommended to install AMD Software: Adrenalin Edition 26.3.1. The newly released AMD Software: Adrenalin Edition 26.6.2 driver is now available for download from the AMD Software app. Find the official changelog here.
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      525
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      94
    4. 4
      Michael Scrip
      82
    5. 5
      neufuse
      68
  • Tell a friend

    Love Neowin? Tell a friend!