[clue-tech] HELP!! Someone has hijacked my mailserver for spam

Mike lister-clue at gantsfort.com
Thu Feb 24 08:15:35 MST 2005


On Wed, Feb 23, 2005 at 09:48:26PM -0700, Charles Oriez wrote:
> At 09:02 PM 2/23/2005, Mike wrote:
> >(sorry if this is a dupe used wrong email on first mailing)
> >
> >I recently switched to postfix from qmail (i know don't fix it if it's
> >not broken) and today I have hundreds of undeliverable emails in my
> >inbox that were sent from my account. It looks like to me that someone
> >has spoofed my email address. All the emails are from me but there is no
> >corresponding log messages for any of th emails.
> 
> 
> I know this is a dumb question, but I assume you looked at the headers and 
> confirmed the mail really went through your server and it isn't just a case 
> of forged from addresses.

I didn't look at the logfiles initially but when I examined the header
of one the bounced emails there was no indication that it ever went
through my server. I then checked the logs and nothing was sent by my
server.

> 
> There are no reports on .sightings or elsewhere showing any spam coming 
> from your IPA, nothing in spamcop, and you didn't post any of the bounces. 
> 

That's good, I suppose. What I'm worried about is my domain being
blacklisted because my email in the From: header. Or is blacklisting
smarter than that and the actual originating IP address is looked at and
not the From: header? Also, would I have any success reporting this
abuse to the originating IP address?

Thanks,
Mike

> _______________________________________________
> CLUE-tech mailing list
> CLUE-tech at clue.denver.co.us
> http://clue.denver.co.us/mailman/listinfo/clue-tech



More information about the clue-tech mailing list