Unless att is using carrier grade nat within its networks but not numbering 
them with rfc 1918 - just using random other IP space.  That'd cause strange 
IPs- sometimes yours - to turn up in their headers.

An Italian ISP called fastweb used to do that years ago (probably still do, who 
knows)

--srs

> On 08-Apr-2016, at 10:14 PM, Michael Rathbun <[email protected]> wrote:
> 
> Howdy,
> 
> We have seen a trickle of complaints to our upstream naming one of our hosted
> customer's IPs as a culprit.  The spamcomplain software used by the
> complainant (always the same complainant) fixes on a header line like this:
> 
>> Received: from (customer's IP) (EHLO fgateway13.ISP.att.net) (207.115.11.43)
>> By mta1065.sbc.mail.bf1.yahoo.com with SMTP; Sat, 12 Mar 2016 21:11:09 +0000
> 
> and includes the customer IP in the complaint, and also helpfully looks up the
> upstream abuse address.  It also complains about the actual sender's IP.
> 
> In a normal att.net header chain, the first IP shown matches the second IP
> shown.  This is the only spot in the entire message where the customer IP
> appears.  The X-Originating-IP lines all match the actual sender's IP.
> 
> The complainware produces essentially identical complaints with red boldface
> <big><bigger> screaming about phishing sites, sent to our upstream + world +
> dog.
> 
> My original speculation was ratware inserting a bogus distractor header, but
> it now looks to me like "internal peculiarity at att or Y!".
> 
> Any other experiences/insights?
> 
> mdr
> -- 
> There's a funny thing that happens when you know the correct
> answer.  It throws you when you get a different answer that
> is not wrong.    -- Dr Bowman (Freefall)
> 
> 
> _______________________________________________
> mailop mailing list
> [email protected]
> https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to