'Undeliverable' spam?


Recommended Posts

Hi,

We seem to be getting a huge amount of 'undeliverable email' spam recently. As it comes through as an undeliverable, it doesn't have anything in the 'internet headers'.

I've checked the clients for mailer worms etc, where would this be coming from? Some examples below

From: System Administrator

Sent: 15 April 2008 04:48

To: [email protected] **bear in mind this is NOT our domain***

Subject: Undeliverable: Check my new photos :))

Your message did not reach some or all of the intended recipients.

Subject: Check my new photos :))

Sent: 15/04/2008 03:00

The following recipient(s) could not be reached:

[email protected] on 15/04/2008 04:48

The e-mail system was unable to deliver the message, but did not report a specific reason. Check the address and try again. If it still fails, contact your system administrator.

< ironport4.terra.cl #5.0.0 smtp; 5.1.0 - Unknown address error 550-'RCPT TO:<[email protected]> User unknown' (delivery attempts: 0)>

From: [email protected]

[mailto:[email protected]]

Sent: 14 April 2008 19:54

To: *name edited*

Subject: failure notice

Hi. This is the qmail-send program at www.dunham-bush.com.cn.

I'm afraid I wasn't able to deliver your message to the following addresses.

This is a permanent error; I've given up. Sorry it didn't work out.

<[email protected]>:

Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is a copy of the message.

Return-Path: **email edited**

Received: (qmail 31177 invoked from network); 15 Apr 2008 02:53:38 +0800

Received: from unknown (HELO 190-48-57-116.speedy.com.ar) (190.48.57.116)

by 222.135.187.29 with SMTP; 15 Apr 2008 02:53:38 +0800

Message-ID: <000801c89e64$07b06824$65e8b799@tnuehc>

From: "Julia S." name edited as it was our domain, but not 'julia s'

To: <[email protected]>

Subject: Check my new photos :))

Date: Mon, 14 Apr 2008 17:35:17 +0000

MIME-Version: 1.0

Content-Type: text/plain;

charset="iso-8859-1"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.3138

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198

Hello!

remember me?..

new fotos(archived) you asked

:))

kiss, Julia S.

What is the best way to stop these kind of emails? We are using Symantec Mail Security for SMTP v5 as our spam filter. thanks

Link to comment
https://www.neowin.net/forum/topic/631492-undeliverable-spam/
Share on other sites

Is this you? (HELO 190-48-57-116.speedy.com.ar) (190.48.57.116)

If not then you did not send it.. Spammers do NOT use their own legit address, they make them up, they use one from a list. So if you are [email protected] and I send a email to [email protected] and SAY its from "[email protected]" When that message can not be delivered to [email protected]

The gmails servers send it back where?? You guessed it [email protected] so you get a kickback saying your mail could not be delivered.

Its called backscatter

http://www.spamresource.com/2007/02/backsc...-i-stop-it.html

Backscatter: What is it? How do I stop it?

Is it also a good idea to have 'Sender ID validation" set to "Delete. The message will be accepted and deleted, no NDR will be sent back to the sender"?

Would this cause any problems?

Any other exchange settings that can be enabled to help alleviate this problem?

thanks

Additionally to randomnut - if you're going to enable recipient filtering, you should also enable tarpitting so that valid email addresses cannot be harvested from your mail server. A quick Google for Exchange tarpitting should help you out.

@CreightonB - close - it's Reverse NDR spamming. As in "non-delivery report".

HTH!

Thanks very much for your input everyone. So the plan of action is:

Enable recipient filtering

Enable tarpitting

reboot

Anything else that will help? With those 2 it should help reduce NDR spam?

thanks

EDIT: Also, will tarpitting interfere with the 3rd party spam filtering we're using?

Edited by randomnut
  • 3 weeks later...

Hey neurotronix,

Yes I implemented several things which seems to have sorted the problem out:

- enabled recipient filtering in exchange

- enabled tarpitting

- added the zen.spamhaus.org list to exchange to help drop known spam if it gets past the spam filter

- set our spam filter to have LDAP connectivity with our domain controller and not to pass any mail to people not in ADUC

Now we have a lot fewer emails getting through. Hope it helps.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Less powerful than a PS5 at twice the price! I wonder if they use that for marketing? Totally DoA.
    • Astra 0.6.1 Beta by Razvan Serea Astra is an audiophile music player designed for local music libraries, supporting MP3, FLAC, WAV, AAC, OGG, M4A, OPUS, WMA, AIFF, and more via FFmpeg. It offers gapless playback with pre-buffering, multichannel audio remapping, and Dolby Atmos decoding, ensuring albums play seamlessly while maintaining high-fidelity sound. Astra features real-time DSP visualizers powered by a native C++ engine, including an oscilloscope, spectrum analyzer, and vectorscope. A fully parametric 10-band EQ with live frequency response, built-in presets, and AutoEQ headphone calibration import lets you precisely shape your sound. Playback controls include shuffle, repeat, and drag-and-drop queue management, while the library automatically extracts metadata, album artwork, and supports global search, favorites, and recently played tracking. Additional features include output device selection, delay calibration, customizable themes, fullscreen and mini-player modes, Discord Rich Presence, optional Last.fm scrobbling, and an opt-in local API for integrations. Astra delivers a complete, high-quality desktop audio experience with no telemetry, accounts, or streaming. Astra 0.6.1 Beta changelog: Lyrics Initial XLRC support via @boof2015/xlrc 0.2.0 (#131) XLRC sidecar scanning, manual import, and renderer support Word timing, furigana, translations, voice labels, and translation-priority controls for XLRC Fullscreen lyrics overhaul with additional layout polish Manual lyrics editor with LRC, XLRC, and plain-text modes Drag-and-drop lyrics import plus sync offset controls Clickable synced lyrics for seeking, with popout and transport lyrics updates (#138) Fixed lyrics info sidebar scrolling (#138) Added a workaround for LRCLIB instability Metadata & Library Metadata editor rebuilt as a side panel Virtual DB metadata overrides and optional direct file tag writing Bulk metadata editing for title, artist, album, album artist, genre, year, track/disc numbers, and artwork Undo/redo support for virtual metadata edits Clear overrides action and default save-mode preference Artist page grid view added, with later design and sizing refinements Improved Jump to Playing with smart source, queue, album, artist, and library track targets Fixed smart source jump behavior Playlists Fixed VLC-style M3U import failures (#127) Added playlist export to M3U/M3U8 (#118) Improved imported playlist path resolution and missing-entry preservation Shuffle added to playlist pages (#121) Remove tracks directly from playlist views (#128) Fixed create-playlist-from-track modal closing when clicking inside it (#137) Multi-select quality-of-life fixes Right-click context menus no longer clear multiselections UI & Navigation Fixed UI scaling regressions in sidebar and home surfaces (#122, #123) Fixed transport bar regression (#126) Fixed horizontal scrolling on Home and Library rails Fixed artist grid sizing while searching Updated playlist action buttons and related layout polish Additional fullscreen lyrics visual adjustments Visualization Scopes and visualizers now respect UI scaling settings (#155) Added shared canvas sizing logic for correct DPR/backing-store behavior Canvas sizing tests added for visualizer scaling regressions Discord RPC Discord Rich Presence activity structure refactored Compact status can prioritize title or artist Profile info line can show file info or album Title and artist links can target YouTube Music, Last.fm, or be disabled Optional small Astra badge for cover-art presence Configurable “clear when paused” timing Added Discord activity tests Scrobbling Fixed custom Last.fm2 API profiles being accidentally blocked Expanded scrobbler profile protocol handling coverage Stability & Tests Added/expanded tests for XLRC parsing, lyrics presentation, metadata editor state, playlist import/export path handling, artist grid layout, horizontal scrolling, canvas sizing, and Discord RPC activity building Download: Astra 0.6.1 Beta | 138.0 MB (Open Source) View: Astra Home Page | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • How does it compare to the "SeeStar S30 Pro" and the "Vespera PRO 2"?
    • Indeed. And note that those units are MUCH cheaper than this new Steam Machine...ahem.
  • Recent Achievements

    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      +Edouard
      209
    3. 3
      PsYcHoKiLLa
      100
    4. 4
      Michael Scrip
      85
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!