[exim] Massive eBay Dupe Flood

Top Page
Delete this message
Reply to this message
Author: Christopher Snell
Date:  
To: exim-users
Subject: [exim] Massive eBay Dupe Flood
Hi All,

I'm trying to figure out why folks at our site are getting massive
amounts of duplicate mail from eBay. The mail seems to be isolated
that which is generated by an automated process, for example,
end-of-auction e-mails and customer service automated responses. We
are getting the same messages delivered every five or ten minutes or
so. The logs show nothing unusual except duplicate Message IDs:

(recipient e-mail address changed to protect the innocent)

2004-11-01 00:23:55 1COVZD-000F97-J2 <= somebody@???
H=mxpool23.ebay.com (mx53.sjc.ebay.com) [66.135.197.29] P=esmtp S=6789
id=200410292150.i9TLoKbs024947@???
2004-11-01 00:23:55 1COVZD-000F97-J2 => somebody@???
R=send_to_gateway T=remote_smtp H=10.0.0.9 [10.0.0.9]
2004-11-01 00:23:55 1COVZD-000F97-J2 Completed

[ ... and then a little while later ... ]

2004-11-01 01:03:28 1COWBV-000FHT-9n <= somebody@???
H=mxpool23.ebay.com (mx53.sjc.ebay.com) [66.135.197.29] P=esmtp S=6641
id=200410292150.i9TLoKbs024947@???
2004-11-01 01:03:28 1COWBV-000FHT-9n => somebody@???
R=send_to_gateway T=remote_smtp H=10.0.0.9 [10.0.0.9]
2004-11-01 01:03:28 1COWBV-000FHT-9n Completed

That message is an automated reply sent in response to my complaint
about the issue. Five hundred messages later, I wish I never
complained in the first place. :)

When an eBay employee telnet'ed to my mail server from one of their MX
boxes, he was able to send an e-mail without any problems. This email
has not yet duped, either:

[root@mx5 root]# telnet 209.142.99.217 25
Trying 209.142.99.217...
Connected to fw-01.satx.bikeworld.net (209.142.99.217).
Escape character is '^]'.
220 web02.satx.bikeworld.net ESMTP Exim 4.34 Mon, 01 Nov 2004 12:02:08
-0600
helo ebay.com
250 web02.satx.bikeworld.net Hello mxpool03.ebay.com [66.135.197.9]
mail from:somebody@???
250 OK
rcpt to:somebody@???
250 Accepted
data
354 Enter message, ending with "." on a line by itself
test message
.
250 OK id=1COgWD-000Li2-62

eBay is blaming this on my mail server, even though we sucessfully
process around 100,000 messages a day.

Has anybody seen this? Does anybody have any contacts at eBay?

Thanks in advance,

Chris Snell