Howdy,

We have seen a trickle of complaints to our upstream naming one of our hosted
customer's IPs as a culprit.  The spamcomplain software used by the
complainant (always the same complainant) fixes on a header line like this:

>Received: from (customer's IP) (EHLO fgateway13.ISP.att.net) (207.115.11.43)
>  By mta1065.sbc.mail.bf1.yahoo.com with SMTP; Sat, 12 Mar 2016 21:11:09 +0000

and includes the customer IP in the complaint, and also helpfully looks up the
upstream abuse address.  It also complains about the actual sender's IP.

In a normal att.net header chain, the first IP shown matches the second IP
shown.  This is the only spot in the entire message where the customer IP
appears.  The X-Originating-IP lines all match the actual sender's IP.

The complainware produces essentially identical complaints with red boldface
<big><bigger> screaming about phishing sites, sent to our upstream + world +
dog.

My original speculation was ratware inserting a bogus distractor header, but
it now looks to me like "internal peculiarity at att or Y!".

Any other experiences/insights?

mdr
-- 
There's a funny thing that happens when you know the correct
answer.  It throws you when you get a different answer that
is not wrong.    -- Dr Bowman (Freefall)


_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to