I have a user who's address is being forged and the mail appears to be going through our server. We are running 7.07 HF2 with no relay allowed on the server. Our Telnet port is disabled in the services.

This is one of the entries from the mail log on the weekend

01:18 09:57 SMTPD(041F00AE) [63.231.195.40] MAIL FROM:<>
01:18 09:57 SMTPD(041F00AE) [63.231.195.40] RCPT TO:<<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]>
This is just a bounce message being sent to your user.

I don't have on the server Refuse Null Senders checked off - Should I have that turned on to stop the sending of this type of mail?
Definitely do not check that box -- that will break your mailserver (time to move that option to the "Advanced" section, Ipswitch).

What can be done to stop this or at least slow it down?
This is called a "Joe Job" and is very, very common with spammers. It just means that the spammer used your customer's return address as if it were his. It is impossible to stop or slow down without resorting to non-technical means (such as contacting the spammer and asking him to stop), as the spammer is using someone else's mailserver to send the mail.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no annual licensing fees.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to