Kyle Quillen wrote:
> 
> Hey all,
> 
> I think I have a bit of an issue it seems as though a few of my users
> because subject to a phishing attack that was asking for their usernames
> and passwords.  How can I go about figuring out who is actually sending
> the mail out?

Look at the message header, or find the entries in the smtp log that
correspond to the message.

> I have checked the ISOQLog but that does not really throw
> any flags to me.  Any thoughts on this?

What are you going to do if/when you find out where they came from?
Blacklisting the IP will do little good. You might look into the
SaneSecurity for clamav extension. (See QMT-ISO manual).

FWIW, I think that Sam will be adding DKIM checking to spamdyke in a future
release. This should help greatly to eliminate phishing. Don't hold your
breath, but he might be giving it a high priority for enhancements.

> Thanks
> Q
> 

-- 
-Eric 'shubes'


---------------------------------------------------------------------
     QmailToaster hosted by: VR Hosted <http://www.vr.org>
---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to