Catch all test
I’ve seen a number of double bounced mails addressed to a1aaa1azzzz1zaaaaa@domain.com
I finally smelled a rat and did some log grepping.
Yep, it’s looks like a test mail, sent to multiple domains.
I see some of those coming multiple times to the same domain. But even so, it’s a mark of a spammer.
But that’s my theory. There are lots of other theories on the net:
Joe Wein has a different perspective. He saw some joe jobs where the spammers sent mail to that account, with a link to a domain he owns.
I checked my spam bin, and I had one fairly recent mail sent to one such address.
Straight viagra mail, sent by Jarrod Glass. The investigation has already been done on NANAS. There’s lots of spam delivered to that a1aaa1azzzz1zaaaaa address on NANAS as well.
I saw someone saying it must be a virus.
And here’s someone with the same theory as mine. Well, except by now I wouldn’t block IP numbers based on that. The spammer appears to be using zombies. I’d say an e-mail with that recipient is enough to put the sending IP on a list of machines to check out to see if they’re zombies, though.