Re: [exim] strange spam

Pàgina inicial
Delete this message
Reply to this message
Autor: Renaud Allard
Data:  
CC: Exim-users
Assumpte: Re: [exim] strange spam


Vasiliy G Tolstov wrote:
> Hello. Sometime i got strange spam e-mails like:
>
> Return-path: <gagesf0@???>
> Envelope-to: v.tolstov@???
> Delivery-date: Wed, 19 Aug 2009 11:59:31 +0400
> X-SPF: none (irish-hostmasters.com)
> X-DKIM: unsigned (irish-hostmasters.com)
> Received: from [UNAVAILABLE] ([61.74.98.247]:49525 helo=WRNYQDXF) by
> mxs.selfmail.ru with esmtp (Exim 4.69) (envelope-from
> <gagesf0@???>) id 1Mdg4l-0003fP-KX for
> v.tolstov@???; Wed, 19 Aug 2009 11:59:30 +0400
> Received: from 61.74.98.247 by irish-hostmasters.com; Wed, 19 Aug 2009
> 16:58:40 +0900
> Message-ID: <000d01ca20a2$dda5c5a0$6400a8c0@gagesf0>
> From: Domenick Reid <bashreg@???>
> To: <bashreg@???>
> Subject: =?koi8-r?B?78TOwSDOz97YIMkgz87BINTXz9EgzsHX08XHxME=?=
> Date: Wed, 19 Aug 2009 16:58:40 +0900
> MIME-Version: 1.0
> Content-Type: multipart/alternative;
> boundary="----=_NextPart_000_0007_01CA20A2.DDA5C5A0"
> X-Priority: 3
> X-MSMail-Priority: Normal
> X-Mailer: Microsoft Outlook Express 6.00.2800.1106
> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
> X-Evolution-Source: imap://vase%40selfip.ru@imap.selfmail.ru/
>
>
>
> Exim has spf check, but in this situation - From: bashreg@???
> (selfip.ru is my domain with -all spf record), but in spf check testing
> irish-hostmasters.com ? Why?
>
> My acls is:
>
>   deny          message                 = X-ACL-SMTP-DATA: SPF signature
> bad ($spf_result ($sender_address_domain))
>                 !authenticated          = *
>                 !hosts                  = +SYS_HOSTS_WHITE
>                 spf                     = fail : err_perm : err_temp
>                 log_message             = X-ACL-SMTP-DATA: SPF signature
> bad

>
>   deny          message                 = X-ACL-SMTP-DATA: SPF signature
> bad ($spf_result ($sender_address_domain))
>                 sender_domains          = aol.com : yandex.ru :
> google.com : mail.ru : inbox.ru : bk.ru : list.ru
>                 spf                     = fail : neutral
>                 log_message             = X-ACL-SMTP-DATA: SPF signature
> bad

>
>   warn          add_header              = :at_start:X-SPF: $spf_result
> ($sender_address_domain)

>
>


Well, as it seems you also reject perfectly valid email addresses :)

  v.tolstov@???
    SMTP error from remote mail server after RCPT TO:<v.tolstov@???>:
    host mx2.selfmail.ru [77.221.143.26]: 550 X-ACL-SMTP-MAIL:
    Invalid sender (<renaud/v.tolstov/selfip.ru/vuhgilkk@???>)



--
010100100110010101101110011000010111010101100100
010000010110110001101100011000010111001001100100