Lots of SPAM mails
Posted: Thu Feb 04, 2010 6:24 am
Hello,
Our client are complaining that they are receiving in huge volumes of SPAM mails everyday, below are the some headers.
1.
Received: (qmail 19383 invoked from network); 4 Feb 2010 16:42:08 +0530
Received-SPF: pass (plesk01.diadem-tech.com: domain of t-com.hr designates 93.142.175.186 as permitted sender) client-ip=93.142.175.186; envelope-from=geisisytoj4461@t-com.hr; helo=t-com.hr;
Received: from 93-142-175-186.adsl.net.t-com.hr (HELO t-com.hr) (93.142.175.186)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 4 Feb 2010 16:42:08 +0530
From: "VIAGRA (c) Trusted Dealer" <geisisytoj4461@t-com.hr>
To: kaushikm@adept-software.com
Subject: User kaushikm Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 04 16:42:08
2.
Received: (qmail 20682 invoked from network); 4 Feb 2010 16:20:55 +0530
Received-SPF: pass (plesk01.diadem-tech.com: domain of airbites.ro designates 89.34.241.1 as permitted sender) client-ip=89.34.241.1; envelope-from=zaiecywiou6645@airbites.ro; helo=airbites.ro;
Received: from user2305.bc.airbites.ro (HELO airbites.ro) (89.34.241.1)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 4 Feb 2010 16:20:53 +0530
From: "VIAGRA (c) Trusted Dealer" <zaiecywiou6645@airbites.ro>
To: kaushikm@adept-software.com
Subject: User kaushikm Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 04 16:20:55
3.
Received: (qmail 16264 invoked from network); 4 Feb 2010 17:23:34 +0530
Received-SPF: pass (plesk01.diadem-tech.com: domain of superkabel.de designates 95.90.196.171 as permitted sender) client-ip=95.90.196.171; envelope-from=juadi7080@superkabel.de; helo=superkabel.de;
Received: from 95-90-196-171-dynip.superkabel.de (HELO superkabel.de) (95.90.196.171)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 4 Feb 2010 17:23:34 +0530
From: "VIAGRA (c) Trusted Dealer" <juadi7080@superkabel.de>
To: sanjoyd@aptsoftware.com
Subject: User sanjoyd Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 04 17:23:34
4.
Received: (qmail 4059 invoked from network); 3 Feb 2010 22:02:00 +0530
Received-SPF: neutral (plesk01.diadem-tech.com: 80.122.195.70 is neither permitted nor denied by domain of mediaways.net) client-ip=80.122.195.70; envelope-from=exope2440@mediaways.net; helo=mediaWays.net;
Received: from mail.wbg-business.at (HELO mediaWays.net) (80.122.195.70)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 3 Feb 2010 22:01:59 +0530
From: "VIAGRA (c) Trusted Dealer" <exope2440@mediaWays.net>
To: sanjoyd@aptsoftware.com
Subject: User sanjoyd Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 03 22:02:00
5.
Received: (qmail 20274 invoked from network); 3 Feb 2010 21:27:14 +0530
Received-SPF: pass (plesk01.diadem-tech.com: domain of archi.fr designates 194.199.202.253 as permitted sender) client-ip=194.199.202.253; envelope-from=ogesyw4176@archi.fr; helo=archi.fr;
Received: from anto.versailles.archi.fr (HELO archi.fr) (194.199.202.253)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 3 Feb 2010 21:27:12 +0530
From: "VIAGRA (c) Trusted Dealer" <ogesyw4176@archi.fr>
To: sanjoyd@aptsoftware.com
Subject: User sanjoyd Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 03 21:27:15
Below are the MagicSpam settings.
Best Practices Policies
Block messages from IP (no domain) Enabled
Block Mail Servers on Dynamic/Dial-up Addresses Disabled
Perform reverse lookup check Disabled
Block Mail Servers reported as Spam Source Enabled
Confirm Server Identification Resolves (HELO) Disabled
Strict address parsing Enabled
Sending server must identify itself (HELO) Enabled
Valid FROM domain Enabled
Server Identification must be valid (HELO) Enabled
IP Reputation
UCEPROTECT-1 Disabled
UCEPROTECT-2 Disabled
UCEPROTECT-3 Disabled
PSBL Enabled
SORBS-DUL Enabled
MIPSPACE Disabled
RATS-DYNA Enabled
RATS-NOPTR Enabled
RATS-SPAM Enabled
Please suggest the best solution.
Regards,
Diadem
Our client are complaining that they are receiving in huge volumes of SPAM mails everyday, below are the some headers.
1.
Received: (qmail 19383 invoked from network); 4 Feb 2010 16:42:08 +0530
Received-SPF: pass (plesk01.diadem-tech.com: domain of t-com.hr designates 93.142.175.186 as permitted sender) client-ip=93.142.175.186; envelope-from=geisisytoj4461@t-com.hr; helo=t-com.hr;
Received: from 93-142-175-186.adsl.net.t-com.hr (HELO t-com.hr) (93.142.175.186)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 4 Feb 2010 16:42:08 +0530
From: "VIAGRA (c) Trusted Dealer" <geisisytoj4461@t-com.hr>
To: kaushikm@adept-software.com
Subject: User kaushikm Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 04 16:42:08
2.
Received: (qmail 20682 invoked from network); 4 Feb 2010 16:20:55 +0530
Received-SPF: pass (plesk01.diadem-tech.com: domain of airbites.ro designates 89.34.241.1 as permitted sender) client-ip=89.34.241.1; envelope-from=zaiecywiou6645@airbites.ro; helo=airbites.ro;
Received: from user2305.bc.airbites.ro (HELO airbites.ro) (89.34.241.1)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 4 Feb 2010 16:20:53 +0530
From: "VIAGRA (c) Trusted Dealer" <zaiecywiou6645@airbites.ro>
To: kaushikm@adept-software.com
Subject: User kaushikm Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 04 16:20:55
3.
Received: (qmail 16264 invoked from network); 4 Feb 2010 17:23:34 +0530
Received-SPF: pass (plesk01.diadem-tech.com: domain of superkabel.de designates 95.90.196.171 as permitted sender) client-ip=95.90.196.171; envelope-from=juadi7080@superkabel.de; helo=superkabel.de;
Received: from 95-90-196-171-dynip.superkabel.de (HELO superkabel.de) (95.90.196.171)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 4 Feb 2010 17:23:34 +0530
From: "VIAGRA (c) Trusted Dealer" <juadi7080@superkabel.de>
To: sanjoyd@aptsoftware.com
Subject: User sanjoyd Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 04 17:23:34
4.
Received: (qmail 4059 invoked from network); 3 Feb 2010 22:02:00 +0530
Received-SPF: neutral (plesk01.diadem-tech.com: 80.122.195.70 is neither permitted nor denied by domain of mediaways.net) client-ip=80.122.195.70; envelope-from=exope2440@mediaways.net; helo=mediaWays.net;
Received: from mail.wbg-business.at (HELO mediaWays.net) (80.122.195.70)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 3 Feb 2010 22:01:59 +0530
From: "VIAGRA (c) Trusted Dealer" <exope2440@mediaWays.net>
To: sanjoyd@aptsoftware.com
Subject: User sanjoyd Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 03 22:02:00
5.
Received: (qmail 20274 invoked from network); 3 Feb 2010 21:27:14 +0530
Received-SPF: pass (plesk01.diadem-tech.com: domain of archi.fr designates 194.199.202.253 as permitted sender) client-ip=194.199.202.253; envelope-from=ogesyw4176@archi.fr; helo=archi.fr;
Received: from anto.versailles.archi.fr (HELO archi.fr) (194.199.202.253)
by mailer01.diadem-tech.com with (RC4-MD5 encrypted) SMTP; 3 Feb 2010 21:27:12 +0530
From: "VIAGRA (c) Trusted Dealer" <ogesyw4176@archi.fr>
To: sanjoyd@aptsoftware.com
Subject: User sanjoyd Great Offer, 84% off
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Scanned: 4PSA Clean Server on Feb 03 21:27:15
Below are the MagicSpam settings.
Best Practices Policies
Block messages from IP (no domain) Enabled
Block Mail Servers on Dynamic/Dial-up Addresses Disabled
Perform reverse lookup check Disabled
Block Mail Servers reported as Spam Source Enabled
Confirm Server Identification Resolves (HELO) Disabled
Strict address parsing Enabled
Sending server must identify itself (HELO) Enabled
Valid FROM domain Enabled
Server Identification must be valid (HELO) Enabled
IP Reputation
UCEPROTECT-1 Disabled
UCEPROTECT-2 Disabled
UCEPROTECT-3 Disabled
PSBL Enabled
SORBS-DUL Enabled
MIPSPACE Disabled
RATS-DYNA Enabled
RATS-NOPTR Enabled
RATS-SPAM Enabled
Please suggest the best solution.
Regards,
Diadem