This could be a virus- mytob or something like it. I've been getting stuff claiming to be: admin/administrator/info/mail/service/support/register/webmaster at mydomain, sending to bogus users at mydomain. I just added the above to my from_senders_bw.map, since IF they were valid senders, they would only come in through mynetworks.
>On Thursday 20 October 2005 01:37 pm, List_Mail wrote: >> Anyone else getting tons of crap from this ip. Neither the from or to is >> legit. >> >> I have emailed the admins 3 days ago and said they were looking into it. >> Guess either they are part of it or stupid and can't get it stopped. >> I have set up a filter that sends out the email to to them. >> But they still haven't done a thing about it. >> >> Out: 220 spiderman.wirelesscommunitynetworks.com - ESMTP - Postfix - Attn: >> UCE >> trespassers will be pursued. >> In: EHLO thedewars.net >> Out: 250-spiderman.wirelesscommunitynetworks.com >> Out: 250-PIPELINING >> Out: 250-SIZE 5000000 >> Out: 250-ETRN >> Out: 250 8BITMIME >> In: MAIL FROM:<[EMAIL PROTECTED]> >> Out: 250 Ok >> In: RCPT TO:<[EMAIL PROTECTED]> >> Out: 550 <unknown[216.183.72.131]>: Client host rejected: UCE Stop the >> spam >> >> Session aborted, reason: lost connection