<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.7" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Spammers use spammee&#8217;s domain</title>
	<link>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Fri, 21 Nov 2008 05:44:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.7</generator>

	<item>
		<title>by: Jalela</title>
		<link>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-62829</link>
		<pubDate>Wed, 15 Nov 2006 21:52:43 +0000</pubDate>
		<guid>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-62829</guid>
					<description>I have the same problem, spammers use my domain to send me junk. I had one bypass address but now I have eliminated. I have no idea how to set up the instructions written below. Which files do I modify?

The trick is to use reject_sender_login_mismatch and blacklist your own doman (with message: 550 send me valid login and password) just after reject_unauth_destination.</description>
		<content:encoded><![CDATA[<p>I have the same problem, spammers use my domain to send me junk. I had one bypass address but now I have eliminated. I have no idea how to set up the instructions written below. Which files do I modify?</p>
<p>The trick is to use reject_sender_login_mismatch and blacklist your own doman (with message: 550 send me valid login and password) just after reject_unauth_destination.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Lemat</title>
		<link>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-55181</link>
		<pubDate>Wed, 25 Oct 2006 23:15:15 +0000</pubDate>
		<guid>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-55181</guid>
					<description>In my postfix configuration only authorized user can send email with it's own envelope address. The trick is to use reject_sender_login_mismatch and blacklist your own doman (with message: 550 send me valid login and password) just after reject_unauth_destination.

For Drew Neilson friend I would reccomend publishing addresses like: friend@grocery.herdomain.tld, friend@library.herdomain.tld and simply remove DNS MX,A entries after the email was compromised.</description>
		<content:encoded><![CDATA[<p>In my postfix configuration only authorized user can send email with it&#8217;s own envelope address. The trick is to use reject_sender_login_mismatch and blacklist your own doman (with message: 550 send me valid login and password) just after reject_unauth_destination.</p>
<p>For Drew Neilson friend I would reccomend publishing addresses like: <a href="mailto:friend@grocery.herdomain.tld">friend@grocery.herdomain.tld</a>, <a href="mailto:friend@library.herdomain.tld">friend@library.herdomain.tld</a> and simply remove DNS MX,A entries after the email was compromised.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: admin</title>
		<link>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-55136</link>
		<pubDate>Wed, 25 Oct 2006 20:08:46 +0000</pubDate>
		<guid>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-55136</guid>
					<description>Yes, there's a very simple solution. And it's the ONLY solution to this problem: Turn off catch all. A lot of legitimate mail will bounce until she figures out how to create forwards for all the "e-mail addresses" she gave out. But that's the price she has to pay for using that solution.

It was touted as a good solution years ago. But today it's a really bad idea.

Before large scale spamming with fake return addresses.</description>
		<content:encoded><![CDATA[<p>Yes, there&#8217;s a very simple solution. And it&#8217;s the ONLY solution to this problem: Turn off catch all. A lot of legitimate mail will bounce until she figures out how to create forwards for all the &#8220;e-mail addresses&#8221; she gave out. But that&#8217;s the price she has to pay for using that solution.</p>
<p>It was touted as a good solution years ago. But today it&#8217;s a really bad idea.</p>
<p>Before large scale spamming with fake return addresses.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Drew Neilson</title>
		<link>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-55100</link>
		<pubDate>Wed, 25 Oct 2006 17:12:18 +0000</pubDate>
		<guid>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-55100</guid>
					<description>I just came across this problem yesterday (today's Oct. 25th) and I can get examples if they would be useful. 

This type of spammer hit my girlfriend's website and started flooding her with emails from her own domain, usually with nonsense . This is a real problem, because she uses disposable addresses at her domain as a (probably rudimentary) way to track and block spammers (so the library would get library@herdomain.com and the grocery store might get groceries@herdomain.com). When someone sells one of her addresses, she simply turns off that address. However, it seems the way around this is to spam tons of possibilities from her domain so she can't block the domain and there are too many random emails to block all the recieving addresses.

She asked me to help her out, but unfortunately, I have no idea how to stop this. Though we're both a somewhat tech savvy, but we're not particularly smart in the area of spam.

Does anyone have ideas on how to stop it? Any help would be really appreciated.</description>
		<content:encoded><![CDATA[<p>I just came across this problem yesterday (today&#8217;s Oct. 25th) and I can get examples if they would be useful. </p>
<p>This type of spammer hit my girlfriend&#8217;s website and started flooding her with emails from her own domain, usually with nonsense . This is a real problem, because she uses disposable addresses at her domain as a (probably rudimentary) way to track and block spammers (so the library would get <a href="mailto:library@herdomain.com">library@herdomain.com</a> and the grocery store might get <a href="mailto:groceries@herdomain.com).">groceries@herdomain.com).</a> When someone sells one of her addresses, she simply turns off that address. However, it seems the way around this is to spam tons of possibilities from her domain so she can&#8217;t block the domain and there are too many random emails to block all the recieving addresses.</p>
<p>She asked me to help her out, but unfortunately, I have no idea how to stop this. Though we&#8217;re both a somewhat tech savvy, but we&#8217;re not particularly smart in the area of spam.</p>
<p>Does anyone have ideas on how to stop it? Any help would be really appreciated.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: THEMike</title>
		<link>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-11890</link>
		<pubDate>Wed, 24 May 2006 10:57:57 +0000</pubDate>
		<guid>http://spamhuntress.com/2006/05/21/spammers-use-spammees-domain/#comment-11890</guid>
					<description>I see this a lot. I don't have any samples to hand, but in my junk folder back home I have hundreds of them.

I often get spam that is from or to [random fake name], [realuser]@domain.com, seems to arrive at my address via a BCC a lot of the time. Sometimes I see [real name] [randomfakeuser]@domain.com.

Where domain.com is a domain I have full control of and know every single account on. There are in the order of 40 valid email addresses on that domain.

The content of the mails does not seem to be of a particular theme. Always spam of one form or another. Perhaps there is a particular botnet/service that has this behaviour and a lot of customers using it?</description>
		<content:encoded><![CDATA[<p>I see this a lot. I don&#8217;t have any samples to hand, but in my junk folder back home I have hundreds of them.</p>
<p>I often get spam that is from or to [random fake name], [realuser]@domain.com, seems to arrive at my address via a BCC a lot of the time. Sometimes I see [real name] [randomfakeuser]@domain.com.</p>
<p>Where domain.com is a domain I have full control of and know every single account on. There are in the order of 40 valid email addresses on that domain.</p>
<p>The content of the mails does not seem to be of a particular theme. Always spam of one form or another. Perhaps there is a particular botnet/service that has this behaviour and a lot of customers using it?
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
