I am seeing quite a few of these in my logs:
03:02 00:00 SMTP-(0EB00924) 250-b456.cnnic.net.cn. Hello MY-IP-BACKWARDS.reverse.theplanet.com [MY-IP] (may be forged), pleased to meet you
Those come from other mailservers, that "do their own thing." Most likely, your mailserver said "EHLO mail.theplanet.com" (or something similar), but your reverse DNS is set to MY-IP-BACKWARDS.reverse.theplanet.com. I'm guessing that people using that brand of mailserver like showing off that they do reverse DNS lookups, but the "(may be forged)" is pretty meaningless here (as there is no indication that forging may be taking place).
If mail.theplanet.com (or whatever your mailserver EHLOs as) doesn't have an A record pointing back to the IP your mailserver is sending from, then it the "(may be forged)" is appropriate.
Note that it is just a diagnostic message.
So looking at this, i am thinking my provider is not blocking inbound traffic with my ip address, and this is being used to spoof my own ip and send out mail as if it was coming from me?
No. That was an outgoing E-mail that you were sending to someone else. They added that "(may be forged)".
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
