Help - Search - Members - Calendar
Full Version: Action on Bounced Spoof?
hsc message board > Main > hsc Software Support
SusanC
Well, this one's confusing! ohmy.gif It appears as though I received a bounced mail message referencing an email message from someone that spoofed an email address at my domain. Is the mail delivery subsystem it came from at fault in any way, i.e., should I report it using Purify's usual procedure, and/or can the original spoofer be reported in any way?

From: MAILER-DAEMON@roundboxconsulting.com
Subject: Warning: could not send message for past 4 hours
Date: May 9, 2011 1:57:58 AM EDT
To: susan@wholeoctave.com
Return-Path: <MAILER-DAEMON@wholemusiclessons.com>
Received: from psmtp.com (exprod7mx257.postini.com [64.18.2.111]) by wholemusiclessons.com (8.13.1/8.13.1) with ESMTP id p495lbs6013974 for <susan@wholeoctave.com>; Mon, 9 May 2011 01:47:37 -0400
Received: from roundboxconsulting.com ([72.172.142.38]) (using TLSv1) by exprod7mx257.postini.com ([64.18.6.14]) with SMTP; Mon, 09 May 2011 01:57:59 EDT
Received: from localhost (localhost) by roundboxconsulting.com (8.13.1/8.13.1) id p4950KhU016235; Mon, 9 May 2011 01:57:58 -0400
X-Authentication-Warning: wholemusiclessons.com: h812w873 owned process doing -bs
Message-Id: <201105090557.p4950KhU016235@roundboxconsulting.com>
X-Orig: localhost
Mime-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status; boundary="p4950KhU016235.1304920678/roundboxconsulting.com"
X-Purify-Rating: HAM
X-Purify-Reason: Jeffrian Filter Rating 0.4499831
Auto-Submitted: auto-generated (warning-timeout)
X-Uidl: ,CQ"!G5#"!)<$"!LAm!!

**********************************************
** THIS IS A WARNING MESSAGE ONLY **
** YOU DO NOT NEED TO RESEND YOUR MESSAGE **
**********************************************

The original message was received at Sun, 8 May 2011 04:22:34 -0400
from truc.dsl.lasotel.fr [81.18.180.106]

----- Transcript of session follows -----
<abd_z_kerkuk@yahoo.com>,<abd_z_star@yahoo.com>... Deferred
Warning: message still undelivered after 4 hours
Will keep trying until message is 5 days old
Reporting-MTA: dns; roundboxconsulting.com
Arrival-Date: Sun, 8 May 2011 04:22:34 -0400

Final-Recipient: RFC822; abd_z_star@yahoo.com
Action: delayed
Status: 4.2.0
Remote-MTA: DNS; g.mx.mail.yahoo.com
Last-Attempt-Date: Mon, 9 May 2011 01:57:58 -0400
Will-Retry-Until: Fri, 13 May 2011 04:22:34 -0400

Final-Recipient: RFC822; abd_z_kerkuk@yahoo.com
Action: delayed
Status: 4.2.0
Remote-MTA: DNS; g.mx.mail.yahoo.com
Last-Attempt-Date: Mon, 9 May 2011 01:57:58 -0400
Will-Retry-Until: Fri, 13 May 2011 04:22:34 -0400

From: "Alexy" <susan@wholeoctave.com>
Date: May 8, 2011 4:21:04 AM EDT
To: <abd_z_kerkuk@yahoo.com>, <abd_z_star@yahoo.com>
Subject: Looking for someone special



Hello, gentleman
I always dreamt of a knight who would come and rescue me from my sadness and loneliness.
I am certainly not a silly little girl any more, however, in some meaning I still believe that man of my desire and my dreams will come into my life and into my heart.
I have the feeling of confidence that you've got the features of a real knight, and You can win my heart! I really count on your honor and honesty, my dear. I wish I can say "My Lord" to you, and if you wish to say "My Lady" to me, you can find my castle at http://love-for-all.net where I am sitting by the window in the top of a tower, looking into far away and waiting for you.
Have a nice day
Alexandra
Jeff Hendrickson
This looks like a "joe job." Someone used your email address to send a spam email, and when it bounced, the bounce response went to you.

Unless you are getting an annoying number of these, I would just delete it. Reporting spam effectively is a volume operation using something like Purify's reporting feature.

If you are getting an annoying number of these, it would be worthwhile to look at the embedded links to find out the web site that the spam is promoting, and complain directly to their ISP if the ISP is located in a country with anti-spam laws.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.