Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | spoofing of my domain


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Internet Discussion

spoofing of my domain
Reply
 
Thread Tools
Old 01-06-2006, 11:44   #1
cynicism theme ****
 
Scarlett's Avatar
 
Join Date: Jun 2003
Location: St Neots
Posts: 778
Scarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpack
Send a message via MSN to Scarlett
spoofing of my domain

Myself and the wife have our own domains that we use for emails only. recently though, someone has started to spoof my wifes domain to spam people with.

I'm 99% certain its spoofing because we have up to date anti-virus and ZA firewall and we use opera for mails and we don't open attachements etc. we dont use P2P and only have MSN chat on but rarely active.

Since this started we have been getting Tons of emails from people's ISP's with returned type headers.

All the emails are of the form sdfhsd@mydomain.com so clearly spam but the problem is that we are now getting 10-15 a day and although we are moving them all to a seperate folder its still anoying.

any suggestions apart from moving domains
__________________
Founder member of the cynicism theme team
Scarlett is offline   Reply With Quote
Old 01-06-2006, 11:52   #2
is lurking
 
Jon M's Avatar
 
Join Date: Oct 2003
Location: Bracknell
Age: 30
Services: Freeview, NTL phone, NTL 4mbit BB SACM
Posts: 3,281
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Jon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze arrayJon M has a bronze array
Send a message via MSN to Jon M
Re: spoofing of my domain

If you run your own mailserver, you should reject any mail item to your domain that isn't "postmaster@", "abuse@", "admin@" possibly "info@" and any of you own addresses. All unrecognised addresses should be rejected rather than forwarded to a catch all address (usually set as postmaster).

Using a false or spoofed domain/address in a spam is one of the most common tactics you'll see, anyone that knows what they're doing will ignore a sender address and check the originating IP from the header.
__________________
Forum Etiquette | Anti-Spam
'slightly pious, very sanctimonious and far too serious'
information is not a property of matter, it's applied to matter by intelligence
Jon M is offline   Reply With Quote
Old 01-06-2006, 11:56   #3
cf.pondlife
 
abailey152's Avatar
 
Join Date: Nov 2003
Location: In hiding!
Services: Sky+, 4Mb VM BB
Posts: 712
abailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation eraabailey152 has entered a golden reputation era
Send a message via MSN to abailey152 Send a message via Yahoo to abailey152
Re: spoofing of my domain

I had this a few months back. Like you, I wasn't sure whether the emails were really bounced messages from other ISP's etc., or whether they were spoof emails, just trying to get me to respond.

In the end, I found a common link between them all. The originiating IP range, in this case, so I just set up a SPAM filter to remove them.

Not sure if it is any consolation, but in my case the emails did stop after a few weeks, and I've not had anything similar since.
__________________
Andy



abailey152 is offline   Reply With Quote
Old 01-06-2006, 12:21   #4
cynicism theme ****
 
Scarlett's Avatar
 
Join Date: Jun 2003
Location: St Neots
Posts: 778
Scarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpack
Send a message via MSN to Scarlett
Re: spoofing of my domain

I see what you mean, the common originating IP is 212.227.15.XX which leads back to a German Webhosting company.
__________________
Founder member of the cynicism theme team
Scarlett is offline   Reply With Quote
Old 01-06-2006, 12:27   #5
Programming Monkey
 
Join Date: Jan 2004
Location: Between Somerset and Essex
Age: 25
Services: 8MB Office MAX on Freeola, Freeview, Freesat
Posts: 833
Strzelecki has reached the bronze age
Strzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze ageStrzelecki has reached the bronze age
Re: spoofing of my domain

If you are getting quite a lot of these emails and you have the option, instead of rejecting the emails your should 'blackhole' them. This means your mail server just swallows them up and destroys them instead of wasting resources trying to reject them and return them to sender. Filtering by IP won't always stop them as all the spammer has to do is change their IP.
__________________
www.strzelecki.co.uk
www.sagemhelp.info Help, advice and discussion about Sagem mobiles.
Exmoor Explorer On yer bike!
Strzelecki is offline   Reply With Quote
Old 01-06-2006, 13:51   #6
cynicism theme ****
 
Scarlett's Avatar
 
Join Date: Jun 2003
Location: St Neots
Posts: 778
Scarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpackScarlett has a very nice sixpack
Send a message via MSN to Scarlett
Re: spoofing of my domain

I set the filter up on the first 3 numbers of the IP address. 99% of the mails gone in one go.

I know the spammer may change the IP address but at least I can change my filter easily
__________________
Founder member of the cynicism theme team
Scarlett is offline   Reply With Quote
Old 01-06-2006, 17:13   #7
Busy Admin
 
Paul M's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 45
Services: VM Phone : Sky+ Multiroom : VM Cable (20 Mbps)
Posts: 14,489
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Send a message via ICQ to Paul M
Re: spoofing of my domain

I get loads on one of my domains, they simply send the spam with a false address as the return address so any rejects come back to you.
__________________
DigiGuide Click here for a real, interactive, tv guide.
Paul M is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 01:40.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)