> I'm curious: I'm too ;-)
> Why did these NDRs contain a "blocked" URL? Were they indeed > "wanted" NDRs, or were they NDRs for Spam that wasn't > delivered, which happened to have one of your users as the > faked sender? After searching trough the logfiles I've discovered that this messages are NDR's or "Notifications" from other mailservers (Exchange, ...) that are in use on customers side as in-house mailserver. This MTAs are using our Mailserver as smart host/gateway. Talking with on of this customers I've discovered that they're retrieving also messages from another (old) mailbox. So I asume this NDR's contains part of the original body and so also some blacklisted URLs. Markus --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com.
