> We have a client that thinks their server is being hijacked because > of some messages they have received.
That's a contradiction. Either their server is just plain being USED for local mail, albeit unwanted, or HIJACKED for remote mail. You haven't given us the full headers pertaining to IMail, since from those (readily forged, and conspicuously misplaced) Received: headers there is no SMTPD32. Basically, it doesn't matter how the message claims it got to them. As we've gone over and over, the only reliable info is the last sending IP. If that IP is blacklisted, you can assure them that they have a remedy in future mailings from this address (Declude Junkmail, IMGate, et al.). Anyway, try to get us complete info, logs, and the like. "Header tracing" isn't usually worth it with spam. -Sandy To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
