Just sent a test message to the domain, and the headers are the same:
Received: from guava.uch.edu [168.200.2.37] by stat.com with ESMTP
(SMTPD32-8.02) id A882145022C; Sun, 24 Aug 2003 10:40:18 -0700
Received: from mail pickup service by guava.uch.edu with Microsoft SMTPSVC;
Sun, 24 Aug 2003 11:40:18 -0600
Received: from uchaex2.uch.ad.pvt ([168.200.32.18]) by guava.uch.edu with Microsoft
SMTPSVC(5.0.2195.5329);
Sun, 24 Aug 2003 11:40:10 -0600
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Received: by uchaex2.uch.ad.pvt with Internet Mail Service (5.5.2653.19) id
<RLYYQ30V>; Sun, 24 Aug 2003
It appears the uch.edu uses one IP for inbound, must due some
processing at 168.200.32.18 and then 168.200.2.37 for outbound
traffic.
Now I feel like a real idiot ... I wish the LAN administrator would
have just told me that and it all would have made more sense.
Or it is easier just to keep out of everyone's else's problem. I been
hit for 3 days now by a DSL circuit with the Sobig virus. I sent off
email to the BellSouth Abuse department, don't ever expect to see an
answer.
I would block the IP, but it keeps jumping to a new one every 6 hours
or so. I assume this is BellSouth way of reassigning ip's so DSL
circuits don't get static numbers for free.
David
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus". The archives can be found
at http://www.mail-archive.com.