Howdy, We have seen a trickle of complaints to our upstream naming one of our hosted customer's IPs as a culprit. The spamcomplain software used by the complainant (always the same complainant) fixes on a header line like this:
>Received: from (customer's IP) (EHLO fgateway13.ISP.att.net) (207.115.11.43) > By mta1065.sbc.mail.bf1.yahoo.com with SMTP; Sat, 12 Mar 2016 21:11:09 +0000 and includes the customer IP in the complaint, and also helpfully looks up the upstream abuse address. It also complains about the actual sender's IP. In a normal att.net header chain, the first IP shown matches the second IP shown. This is the only spot in the entire message where the customer IP appears. The X-Originating-IP lines all match the actual sender's IP. The complainware produces essentially identical complaints with red boldface <big><bigger> screaming about phishing sites, sent to our upstream + world + dog. My original speculation was ratware inserting a bogus distractor header, but it now looks to me like "internal peculiarity at att or Y!". Any other experiences/insights? mdr -- There's a funny thing that happens when you know the correct answer. It throws you when you get a different answer that is not wrong. -- Dr Bowman (Freefall) _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop
