At 12:17 PM 6/15/2004, Matt wrote:
This domain was recently moved to our DNS and I suspect that someone at their old DNS hosting provider is infected and using their old unremoved DNS entries and that is why they are bypassing us. Note though that some spammers are definitely caching old lookups in their spamware which is why I thought it might be possible that a virus was doing this as well.

I just want to interject that I'm seeing this behavior a bunch specifically with the Zafi worm. I moved to two postfix boxes to do my gatewaying many months ago, and I still occasionally get virii coming directly into my Imail box. I don't have the luxury of shutting off SMTP to my Imail box because I have some remote users that connect to it to send email.


Just my .02.

Thanks,
Russ


---
[This E-mail scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to