Re: [exim] Spam volume spike

Top Page
Delete this message
Reply to this message
Author: Wakko Warner
Date:  
To: Ian Eiloart
CC: exim users
Subject: Re: [exim] Spam volume spike
Ian Eiloart wrote:
> Hi,
>
> I've noticed a huge spike in spam volumes recently. For 10 months, up until
> about 3 weeks ago, we were consistently rejecting an average of about
> 250,000 spam messages per day. We'd never rejected more than 400k messages.
>
> Then, about 26 June, we rejected over 400k messages, and numbers kept
> rising with over a million messages rejected on a couple of occasions.
>
>     <http://www.sussex.ac.uk/its/email/stats/>
>     <http://www.sussex.ac.uk/its/email/stats/spamgraph.png>

>
> Stats published by Cambridge show a similar trend. Have others seen a
> similar thing?


I've noticed that for some time various IPs are attempting to send spam to
addresses that match: [A-Za-z]{0,2}[0-9]{3,6}@<localdomain>

I've done whois on some of the sending domains and most of them have
contacts at free mail providers, user accounts at large ISPs, or parked by
secureserver.net (or .com forgot which)

My rejection rate over a period of 1 day used to be around 10-20 lines, it
has now gone to pages (in a 90 row xterm). I made a special case acl for
these and just grep them out of my logs before viewing. This is on a vanity
domain too!

--
Lab tests show that use of micro$oft causes cancer in lab animals
Got Gas???