Unless att is using carrier grade nat within its networks but not numbering them with rfc 1918 - just using random other IP space. That'd cause strange IPs- sometimes yours - to turn up in their headers.
An Italian ISP called fastweb used to do that years ago (probably still do, who knows) --srs > On 08-Apr-2016, at 10:14 PM, Michael Rathbun <[email protected]> wrote: > > Howdy, > > We have seen a trickle of complaints to our upstream naming one of our hosted > customer's IPs as a culprit. The spamcomplain software used by the > complainant (always the same complainant) fixes on a header line like this: > >> Received: from (customer's IP) (EHLO fgateway13.ISP.att.net) (207.115.11.43) >> By mta1065.sbc.mail.bf1.yahoo.com with SMTP; Sat, 12 Mar 2016 21:11:09 +0000 > > and includes the customer IP in the complaint, and also helpfully looks up the > upstream abuse address. It also complains about the actual sender's IP. > > In a normal att.net header chain, the first IP shown matches the second IP > shown. This is the only spot in the entire message where the customer IP > appears. The X-Originating-IP lines all match the actual sender's IP. > > The complainware produces essentially identical complaints with red boldface > <big><bigger> screaming about phishing sites, sent to our upstream + world + > dog. > > My original speculation was ratware inserting a bogus distractor header, but > it now looks to me like "internal peculiarity at att or Y!". > > Any other experiences/insights? > > mdr > -- > There's a funny thing that happens when you know the correct > answer. It throws you when you get a different answer that > is not wrong. -- Dr Bowman (Freefall) > > > _______________________________________________ > mailop mailing list > [email protected] > https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop
