'Undeliverable' spam?


Recommended Posts

Hi,

We seem to be getting a huge amount of 'undeliverable email' spam recently. As it comes through as an undeliverable, it doesn't have anything in the 'internet headers'.

I've checked the clients for mailer worms etc, where would this be coming from? Some examples below

From: System Administrator

Sent: 15 April 2008 04:48

To: [email protected] **bear in mind this is NOT our domain***

Subject: Undeliverable: Check my new photos :))

Your message did not reach some or all of the intended recipients.

Subject: Check my new photos :))

Sent: 15/04/2008 03:00

The following recipient(s) could not be reached:

[email protected] on 15/04/2008 04:48

The e-mail system was unable to deliver the message, but did not report a specific reason. Check the address and try again. If it still fails, contact your system administrator.

< ironport4.terra.cl #5.0.0 smtp; 5.1.0 - Unknown address error 550-'RCPT TO:<[email protected]> User unknown' (delivery attempts: 0)>

From: [email protected]

[mailto:[email protected]]

Sent: 14 April 2008 19:54

To: *name edited*

Subject: failure notice

Hi. This is the qmail-send program at www.dunham-bush.com.cn.

I'm afraid I wasn't able to deliver your message to the following addresses.

This is a permanent error; I've given up. Sorry it didn't work out.

<[email protected]>:

Sorry, no mailbox here by that name. vpopmail (#5.1.1)

--- Below this line is a copy of the message.

Return-Path: **email edited**

Received: (qmail 31177 invoked from network); 15 Apr 2008 02:53:38 +0800

Received: from unknown (HELO 190-48-57-116.speedy.com.ar) (190.48.57.116)

by 222.135.187.29 with SMTP; 15 Apr 2008 02:53:38 +0800

Message-ID: <000801c89e64$07b06824$65e8b799@tnuehc>

From: "Julia S." name edited as it was our domain, but not 'julia s'

To: <[email protected]>

Subject: Check my new photos :))

Date: Mon, 14 Apr 2008 17:35:17 +0000

MIME-Version: 1.0

Content-Type: text/plain;

charset="iso-8859-1"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.3138

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198

Hello!

remember me?..

new fotos(archived) you asked

:))

kiss, Julia S.

What is the best way to stop these kind of emails? We are using Symantec Mail Security for SMTP v5 as our spam filter. thanks

Link to comment
https://www.neowin.net/forum/topic/631492-undeliverable-spam/
Share on other sites

Is this you? (HELO 190-48-57-116.speedy.com.ar) (190.48.57.116)

If not then you did not send it.. Spammers do NOT use their own legit address, they make them up, they use one from a list. So if you are [email protected] and I send a email to [email protected] and SAY its from "[email protected]" When that message can not be delivered to [email protected]

The gmails servers send it back where?? You guessed it [email protected] so you get a kickback saying your mail could not be delivered.

Its called backscatter

http://www.spamresource.com/2007/02/backsc...-i-stop-it.html

Backscatter: What is it? How do I stop it?

Is it also a good idea to have 'Sender ID validation" set to "Delete. The message will be accepted and deleted, no NDR will be sent back to the sender"?

Would this cause any problems?

Any other exchange settings that can be enabled to help alleviate this problem?

thanks

Additionally to randomnut - if you're going to enable recipient filtering, you should also enable tarpitting so that valid email addresses cannot be harvested from your mail server. A quick Google for Exchange tarpitting should help you out.

@CreightonB - close - it's Reverse NDR spamming. As in "non-delivery report".

HTH!

Thanks very much for your input everyone. So the plan of action is:

Enable recipient filtering

Enable tarpitting

reboot

Anything else that will help? With those 2 it should help reduce NDR spam?

thanks

EDIT: Also, will tarpitting interfere with the 3rd party spam filtering we're using?

Edited by randomnut
  • 3 weeks later...

Hey neurotronix,

Yes I implemented several things which seems to have sorted the problem out:

- enabled recipient filtering in exchange

- enabled tarpitting

- added the zen.spamhaus.org list to exchange to help drop known spam if it gets past the spam filter

- set our spam filter to have LDAP connectivity with our domain controller and not to pass any mail to people not in ADUC

Now we have a lot fewer emails getting through. Hope it helps.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • My Photos app is version 2026.11050.1001.0 and it remembers the window size and position. My Snipping Tool is version 11.2602.49.0 and it can capture the taskbar.
    • MusicBee 3.6.9668 by Razvan Serea MusicBee is an application geared toward managing extensive music collections, easy to use and with a comprehensive feature set. It makes it easy to organize, find, and play music files on your computer, on portable devices, and on the Web. It provides playback of a wide range of audio formats, smart playlists with the ability to discover and play new music from the web, advanced tag editing with automated artwork and tag look up, folder monitoring, automated file re-organization, portable device synchronization, and secure CD ripping with AccurateRip verification. MusicBee features: Supported formats: MP3, AAC, M4A, MPC, OGG, FLAC, APE, TAK, WV, WMA and WAV. Audio CDs: Audio CD playback and ripping (with CD-Text capabilities) is supported. CD tracks can be ripped (in fast or secure mode) as individual files or as a single album with embedded cuesheet. Conversion: Conversion from and to all supported formats as metadata are preserved. Synchronization of tags only (in case that the output file already exists) instead of reencoding is possible. ReplayGain support: both playback and calculation. File Organization: Organization and renaming of music files into folders and files based on tag values such as artist, album, name, track number, etc. that can be specified. MusicBee can do this automatically for all files in a music library or the user can choose the files or folders themselves. Web Browsing: Browsing of the web using Mozilla's XULRunner environment. Scrobbling: Tracks played from MusicBee can optionally be scrobbled to Last.fm. Customizable user interface layout. Customizable keyboard shortcuts. MiniLyrics support Download: MusicBee 3.6.9668 | MusicBee Portable | ~9.0 MB (Freeware) Download: Windows Store Edition View: MusicBee Home page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • On xiaomi hyperos there's also an option to disable google assistant. I've got everything disabled. Only thing I do have installed is a web wrapped for duck.ai which claims to let you use various AIs anonymously
    • I need to understand the rationale of not shipping all of these K2 improvements in a single update/release. It's giving "we will fix Windows 11 but no commitments". It seems to me that they just announce these improvements just to appease the community.
    • The term "RTM" is long gone starting with Windows 10. Every current release is a GA build. This is the result of MS making Windows as a Service (WaaS).
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      520
    2. 2
      +Edouard
      185
    3. 3
      PsYcHoKiLLa
      87
    4. 4
      Michael Scrip
      81
    5. 5
      Steven P.
      73
  • Tell a friend

    Love Neowin? Tell a friend!