We had moved the problem domain (it has been
constantly spammed by about 7000+ Ip's over the
last 10 days) to a machine running Eval Imail 8
 from Exchange. We were trying to see if the
antispam features would reduce the incoming spam

All along the spam consists of emails to unknown
email addresses at our domain.

What you are experiencing is a "dictionary attack", and isn't a spam issue (related, but it isn't spam you are receiving). It's a method that spammers use to harvest E-mail addresses. They are checking each possible address that they can think of on your server to see if it is valid.


These can be very nasty, and I haven't heard of a single mailserver that has good protection against this (especially the distributed harvesting that you are experiencing). Some people use BlackIce Server to handle this; someone on this list has been working on a tool to help as well.

As a first attempt we moved the domain for an
hour or 2 to test it on the server running Imail
8 and then moved it back to Exchange as we ran
into a few problems. After we removed the domain
off the IMAIL server, the logs show that email
is still coming in to non-existing users of that
domain. I assume the spam is being sent to the
servers IP and not the domain anymore.

You can't trust spammers. It used to be that they were scared, and so they would have a small amount of ethics (not sending to postmaster@, support@, etc. addresses, and at one point I heard they wouldn't send to .org addresses). But when you are dealing with someone that is willing to break into 7,000+ computers, you're dealing with someone with 0 ethics. They do what they want, when they want, and how they want.


In this case, they are probably caching the DNS information longer than you are telling them to. Note that many spammers also will send directly to backup mailservers, knowing that they are less likely to have spam control.

It seems for all these junk mails coming in
the mail server sends a reply back to each one
of them

What would you like IMail to do?


You can have it set to respond with a "Yes, that's a valid user!" -- but then you end up with a dumb spammer thinking you have millions of addresses -- and then they will send you millions of E-mails.

You can't have IMail time out or drop the connection, but that's good (as it would cause problems when legitimate people send E-mail to the wrong addresses).

My questions
a) Is there any way to delete these emails for a
NonExistent domain and not bounce them back as
that is what the spammer wants.

You can receive them by using the "nobody" alias, but that is dangerous (you're setting yourself up for an even bigger attack -- if you're overwhelmed by 7,000 IPs checking for valid accounts, you're going to be even more overwhelmed by 7,000 IPs sending you constant spam).


b) Why does the mail server not do any
validation / DNS blocklist search on these
emails.

Unfortunately, IMail spam control solutions (built-in and addons) only work after the E-mail is received. In most cases this works very well, but it does mean that you can't prevent a dictionary attack (which would be hard to do even if those tests were run before the E-mail was received, just so you are aware).


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you have been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to