Just sent a test message to the domain, and the headers are the same:

Received: from guava.uch.edu [168.200.2.37] by stat.com with ESMTP
  (SMTPD32-8.02) id A882145022C; Sun, 24 Aug 2003 10:40:18 -0700
Received: from mail pickup service by guava.uch.edu with Microsoft SMTPSVC;
         Sun, 24 Aug 2003 11:40:18 -0600
Received: from uchaex2.uch.ad.pvt ([168.200.32.18]) by guava.uch.edu with Microsoft 
SMTPSVC(5.0.2195.5329);
Sun, 24 Aug 2003 11:40:10 -0600
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Received: by uchaex2.uch.ad.pvt with Internet Mail Service (5.5.2653.19) id 
<RLYYQ30V>; Sun, 24 Aug 2003


It appears the uch.edu uses one IP for inbound, must due some
processing at 168.200.32.18 and then 168.200.2.37 for outbound
traffic.

Now I feel like a real idiot ... I wish the LAN administrator would
have just told me that and it all would have made more sense.

Or it is easier just to keep out of everyone's else's problem.  I been
hit for 3 days now by a DSL circuit with the Sobig virus.  I sent off
email to the BellSouth Abuse department, don't ever expect to see an
answer.

I would block the IP, but it keeps jumping to a new one every 6 hours
or so.  I assume this is BellSouth way of reassigning ip's so DSL
circuits don't get static numbers for free.

David

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to