Community Discussions and Support
Spam message from restricted IP address

Thanks a lot, Rolf

I've changed the entry.

Cheers!

<P>Thanks a lot, Rolf</P> <P>I've changed the entry.</P> <P>Cheers!</P>

Hi Folks

Today we received some spam which came in from an address that is in a banned range.

MercuryS SMTP Server's connection control is set up so that 0.0.0.0 to 255.255.255.255 is refused. The only address ranges allowed are those which are used by MessageLabs and a single address for a separate domain. None of the allowed address ranges encompass the IP address that the spam email originated from.

Here's the email:

Received: from spooler by apsarchaeology.co.uk (Mercury/32 v4.62); 6 Mar 2009 09:48:31 -0000
X-Envelope-To: Electronic Postmaster <Admin@apsarchaeology.co.uk>
To: Electronic Postmaster <Admin@apsarchaeology.co.uk>
From: Electronic Postmaster <postmaster@apsarchaeology.co.uk>
Date: Fri, 6 Mar 2009 09:48:20 -0000
Subject: Postmaster Notify: Delivery Failure.
MIME-Version: 1.0
Content-type: multipart/mixed; boundary=28209.740667140
X-PMFLAGS: 570949760 0 1 YWURDGYK.CNM                      

This message is in MIME format. If you are seeing this text,
then your mailer does not understand this format properly.

--28209.740667140
Content-type: Text/Plain; charset=US-ASCII
Content-Disposition: Inline
Content-Description: Reason for delivery failure.

The attached message has failed delivery and has been referred
to you as postmaster. The following error report or reports
were given to explain the problem:

   *** <u@apsarchaeology.co.uk>
   User <u@apsarchaeology.co.uk> not known at this site.

--28209.740667140
Content-type: Message/RFC822

From: Mail Delivery System <postmaster@apsarchaeology.co.uk>
To: <u@apsarchaeology.co.uk>
Date: Fri, 6 Mar 2009 09:48:09 -0000
Subject: Delivery failure notification
MIME-Version: 1.0
Content-Type: Multipart/Report; boundary=Part_Boundary-2C2582F3

--Part_Boundary-2C2582F3
Content-type: Text/plain; charset=US-ASCII
Content-description: Mail delivery failure report
Content-disposition: Inline

With reference to your message with the subject:
   "Casino St. Valentine's Day"

The local mail transport system has reported the following problems
it encountered while trying to deliver your message:

-------------------------------------------------------------------

--- Problems not related to specific addresses in the message:
Job has invalid or illegal from address.
*** <enquiries@apsarchaeology.co.uk>
-------------------------------------------------------------------

Your mail message is being returned to you in the next part of this
message.

Should you need assistance, please mail greenman@apsarchaeology.co.uk.

--Part_Boundary-2C2582F3
Content-type: Message/RFC822
Content-description: Contents of original mail message

Return-path: <u@apsarchaeology.co.uk>
Received: from A-YJZJ5ICO29RPP (151.66.202.210) by apsarchaeology.co.uk (Mercury/32 v4.62) ID MG000195;
   6 Mar 2009 09:48:06 -0000
Received: from [151.66.202.210] (port=48734 helo=151.66.202.210)
        by mail.apsarchaeology.co.uk with esmtp
        id bda41a-39ab34-56
        for enquiries@apsarchaeology.co.uk; Fri, 06 Mar 2009 10:48:51 +0100
Message-ID: <49B0F183.9080802@apsarchaeology.co.uk>
Date: Fri, 06 Mar 2009 10:48:51 +0100
From: "Anita" <u@apsarchaeology.co.uk>
User-Agent: Thunderbird 2.0.0.9 (Windows/20071031)
MIME-Version: 1.0
To: "Dean" <enquiries@apsarchaeology.co.uk>
Subject: Casino St. Valentine's Day
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Please, to win in our casino now!
>address removed by Greenman<

 


--Part_Boundary-2C2582F3--


--28209.740667140--

Does anyone have any thoughts about how this ended up being delivered to us? All email that is addressed to apsarchaeology.co.uk is delivered by MessageLabs and has a banner appended to the bottom stating it has been scanned by the MessageLabs system. As you can see, no such banner exists on this message.

Cheers!

&lt;P&gt;Hi Folks&lt;/P&gt; &lt;P&gt;Today we received some spam which came in from an address that is in a banned range.&lt;/P&gt; &lt;P&gt;MercuryS SMTP Server&#039;s connection control is set up so that 0.0.0.0 to 255.255.255.255 is refused. The only address ranges allowed are those which are used by MessageLabs and a single address for a separate domain. None of the allowed address ranges encompass the IP address that the spam email originated from.&lt;/P&gt; &lt;P&gt;Here&#039;s the email:&lt;/P&gt; &lt;P&gt;Received: from spooler by apsarchaeology.co.uk (Mercury/32 v4.62); 6 Mar 2009 09:48:31 -0000 X-Envelope-To: Electronic Postmaster &amp;lt;Admin@apsarchaeology.co.uk&amp;gt; To: Electronic Postmaster &amp;lt;Admin@apsarchaeology.co.uk&amp;gt; From: Electronic Postmaster &amp;lt;postmaster@apsarchaeology.co.uk&amp;gt; Date: Fri, 6 Mar 2009 09:48:20 -0000 Subject: Postmaster Notify: Delivery Failure. MIME-Version: 1.0 Content-type: multipart/mixed; boundary=28209.740667140 X-PMFLAGS: 570949760 0 1 YWURDGYK.CNM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt; &lt;P&gt;This message is in MIME format. If you are seeing this text, then your mailer does not understand this format properly.&lt;/P&gt; &lt;P&gt;--28209.740667140 Content-type: Text/Plain; charset=US-ASCII Content-Disposition: Inline Content-Description: Reason for delivery failure.&lt;/P&gt; &lt;P&gt;The attached message has failed delivery and has been referred to you as postmaster. The following error report or reports were given to explain the problem:&lt;/P&gt; &lt;P&gt;&amp;nbsp;&amp;nbsp; *** &amp;lt;u@apsarchaeology.co.uk&amp;gt; &amp;nbsp;&amp;nbsp; User &amp;lt;u@apsarchaeology.co.uk&amp;gt; not known at this site.&lt;/P&gt; &lt;P&gt;--28209.740667140 Content-type: Message/RFC822&lt;/P&gt; &lt;P&gt;From: Mail Delivery System &amp;lt;postmaster@apsarchaeology.co.uk&amp;gt; To: &amp;lt;u@apsarchaeology.co.uk&amp;gt; Date: Fri, 6 Mar 2009 09:48:09 -0000 Subject: Delivery failure notification MIME-Version: 1.0 Content-Type: Multipart/Report; boundary=Part_Boundary-2C2582F3&lt;/P&gt; &lt;P&gt;--Part_Boundary-2C2582F3 Content-type: Text/plain; charset=US-ASCII Content-description: Mail delivery failure report Content-disposition: Inline&lt;/P&gt; &lt;P&gt;With reference to your message with the subject: &amp;nbsp;&amp;nbsp; &quot;Casino St. Valentine&#039;s Day&quot;&lt;/P&gt; &lt;P&gt;The local mail transport system has reported the following problems it encountered while trying to deliver your message:&lt;/P&gt; &lt;P&gt;-------------------------------------------------------------------&lt;/P&gt; &lt;P&gt;--- Problems not related to specific addresses in the message: Job has invalid or illegal from address. *** &amp;lt;enquiries@apsarchaeology.co.uk&amp;gt; -------------------------------------------------------------------&lt;/P&gt; &lt;P&gt;Your mail message is being returned to you in the next part of this message.&lt;/P&gt; &lt;P&gt;Should you need assistance, please mail greenman@apsarchaeology.co.uk.&lt;/P&gt; &lt;P&gt;--Part_Boundary-2C2582F3 Content-type: Message/RFC822 Content-description: Contents of original mail message&lt;/P&gt; &lt;P&gt;Return-path: &amp;lt;u@apsarchaeology.co.uk&amp;gt; Received: from A-YJZJ5ICO29RPP (151.66.202.210) by apsarchaeology.co.uk (Mercury/32 v4.62) ID MG000195; &amp;nbsp;&amp;nbsp; 6 Mar 2009 09:48:06 -0000 Received: from [151.66.202.210] (port=48734 helo=151.66.202.210) &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; by mail.apsarchaeology.co.uk with esmtp &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; id bda41a-39ab34-56 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; for enquiries@apsarchaeology.co.uk; Fri, 06 Mar 2009 10:48:51 +0100 Message-ID: &amp;lt;49B0F183.9080802@apsarchaeology.co.uk&amp;gt; Date: Fri, 06 Mar 2009 10:48:51 +0100 From: &quot;Anita&quot; &amp;lt;u@apsarchaeology.co.uk&amp;gt; User-Agent: Thunderbird 2.0.0.9 (Windows/20071031) MIME-Version: 1.0 To: &quot;Dean&quot; &amp;lt;enquiries@apsarchaeology.co.uk&amp;gt; Subject: Casino St. Valentine&#039;s Day Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit&lt;/P&gt; &lt;P&gt;Please, to win in our casino now! &amp;gt;address removed by Greenman&amp;lt;&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt; --Part_Boundary-2C2582F3--&lt;/P&gt; &lt;P&gt; --28209.740667140--&lt;/P&gt; &lt;P&gt;Does anyone have any thoughts about how this ended up being delivered to us? All email that is addressed to apsarchaeology.co.uk is delivered by MessageLabs and has a banner appended to the bottom stating it has been scanned by the MessageLabs system. As you can see, no such banner exists on this message.&lt;/P&gt; &lt;P&gt;Cheers!&lt;/P&gt;

Try changing the restricted range to 0.0.0.1 - 255.255.255.255.

/Rolf
 

&lt;p&gt;Try changing the restricted range to 0.0.0.1 - 255.255.255.255.&lt;/p&gt;&lt;p&gt;/Rolf &amp;nbsp;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft