Looking at the HELO. When I did nslookup on 211.108.90.4 it did not resolve, so I assumed it was in fact libero. A bit naive I guess; something like this would not be coming from an isp. How did you get Korea? I am not arguing the point as I know you know more thna I do, but how did you get that?

> It appears to be something delivered from Korea (211.108.90.4) to
> Zianet, then from Zianet to ComCast.

Zianet hosts prunebelly and yes it forwards to a comcast address.


> Why do you think it is spoofing a prunebelly address?

It claims to be sent to user A at prunebelly but was received by user B. User A neither received not sent it.

>But without full headers it is a bit difficult to see where
> it came from exactly, so it is not clear where to report it. You might
> want to just go for the spamvertized site instead of the originator
> (which undoubtedly is a hacked/misconfigured DSL cluebie).
>

User claims nothing appears when you go View --> All Headers (Outlook Express). This may in fact be the case as she is at least competent enough to view source.

But anyway... to be honest I was thinking I had an answer from the headers. Glad I asked. And the last time I got revolted enough to chase one of these down, the domain and the domains it referred to were all registered to an address in Madagascar.  

BUT :) BUT :) this one is registered to some guy in Lynden Washington using a hosting company in Columbia Maryland.... thanks, I got it from here, unless you have further suggestions <g>

me <-- happy

Dana
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to