Community Discussions and Support
Dealing with Hotmail spam

Short of blocking hotmail.com completely, what can be done to deal with Hotmail spam?  Here are a couple of ideas I've used with great success.

 

1. Delete all messages sent from or relayed through Hotmail using a blind CC.

Go into Configuration -> Filtering Rules -> Edit global rules

Create an Expression and enter "@your_domain_name", check Headers only, Action: Logical AND operator, click Ok, then click the NOT button.

Directly after this statement, create another Expression and enter "bay0.hotmail.com", Headers only, Action: Delete message.

How many businesses send legitimate messages from Hotmail accounts using a blind CC:?  I've not seen any.

 

2. Check for patterns.

One of the spammers using Hotmail lumps around 20-30 addresses to various domains in the To: or CC: headers, along with one legitimate address on my system.  I was looking at these and it dawned on me the spammer was using the same list of names over and over again for months now.  I set up a rule to tag on one of these other addresses and delete any message with that address in the header.  Obviously, you'll want to check to make sure the address you choose is not someone sending mail to or from your system, but odds are the other victims are people who no one using your system know.

 

Hope this helps and of course, your mileage may vary. 

<p>Short of blocking hotmail.com completely, what can be done to deal with Hotmail spam?  Here are a couple of ideas I've used with great success.</p><p> </p><p>1. Delete all messages sent from or relayed through Hotmail using a blind CC. </p><p>Go into Configuration -> Filtering Rules -> Edit global rules</p><p>Create an Expression and enter "@your_domain_name", check Headers only, Action: Logical AND operator, click Ok, then click the NOT button.</p><p>Directly after this statement, create another Expression and enter "bay0.hotmail.com", Headers only, Action: Delete message.</p><p>How many businesses send legitimate messages from Hotmail accounts using a blind CC:?  I've not seen any. </p><p> </p><p>2. Check for patterns.</p><p>One of the spammers using Hotmail lumps around 20-30 addresses to various domains in the To: or CC: headers, along with one legitimate address on my system.  I was looking at these and it dawned on me the spammer was using the same list of names over and over again for months now.  I set up a rule to tag on one of these other addresses and delete any message with that address in the header.  Obviously, you'll want to check to make sure the address you choose is not someone sending mail to or from your system, but odds are the other victims are people who no one using your system know.</p><p> </p><p>Hope this helps and of course, your mileage may vary. </p>

I'm pretty close to ground Hotmail altogether as well. I will soon start a survey among my users, domain owners and the owners of the domains I do Backup-MX for.

It gets worse weekly and M$ does not seem to care about the problem a tiny bit, while I would expect some improved identity verification from them for new user accounts. So simply block that shop worldwide would put some pressure on those "email-cowboys"...

 

 

<p>I'm pretty close to ground Hotmail altogether as well. I will soon start a survey among my users, domain owners and the owners of the domains I do Backup-MX for.</p><p>It gets worse weekly and M$ does not seem to care about the problem a tiny bit, while I would expect some improved identity verification from them for new user accounts. So simply block that shop worldwide would put some pressure on those "email-cowboys"...</p><p> </p><p> </p>

All  very well but now Hotmail seems to have improved its filtering system and for three days my messages to Hotmail users have been refused by Hotmail. for alleged Spam like qualities. My ISP says they cannot do anything.  

All  very well but now Hotmail seems to have improved its filtering system and for three days my messages to Hotmail users have been refused by Hotmail. for alleged Spam like qualities. My ISP says they cannot do anything.  
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft