Kyle Quillen wrote:
>
> Hey all,
>
> I think I have a bit of an issue it seems as though a few of my users
> because subject to a phishing attack that was asking for their usernames
> and passwords. How can I go about figuring out who is actually sending
> the mail out?
Look at the message header, or find the entries in the smtp log that
correspond to the message.
> I have checked the ISOQLog but that does not really throw
> any flags to me. Any thoughts on this?
What are you going to do if/when you find out where they came from?
Blacklisting the IP will do little good. You might look into the
SaneSecurity for clamav extension. (See QMT-ISO manual).
FWIW, I think that Sam will be adding DKIM checking to spamdyke in a future
release. This should help greatly to eliminate phishing. Don't hold your
breath, but he might be giving it a high priority for enhancements.
> Thanks
> Q
>
--
-Eric 'shubes'
---------------------------------------------------------------------
QmailToaster hosted by: VR Hosted <http://www.vr.org>
---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]