Security Basics mailing list archives

Receiving spam from my own server


From: "Dave Moore" <dave.j.moore () gmail com>
Date: Fri, 1 Dec 2006 16:38:14 -0600

Hello all-

I run a webserver, let's call it foobar.net

I am receiving spam e-mails from addresses such as info () foobar net,
admin () foobar net, etc. I ran the open relay tests at ordb.org, and
they report that my server is not an open relay.

I'd appreciate any suggestions as to where I should go next.

Here are some headers that i've attempted to sanitize (i.e. remove my
hostname and ip)

Delivered-To: dave.j.moore () gmail com
Received: by 10.82.163.14 with SMTP id l14cs33696bue;
       Fri, 1 Dec 2006 13:26:41 -0800 (PST)
Received: by 10.90.103.2 with SMTP id a2mr5744854agc.1165008401102;
       Fri, 01 Dec 2006 13:26:41 -0800 (PST)
Return-Path: <info () avitas net>
Received: from www.foobar.net (www.foobar.net [66.xx.xx.xx])
       by mx.google.com with ESMTP id 12si654066wrl.2006.12.01.13.26.40;
       Fri, 01 Dec 2006 13:26:41 -0800 (PST)
Received-SPF: pass (google.com: best guess record for domain of
info () foobar net designates 66.xx.xx.xx as permitted sender)
Received: from e180234232.adsl.alicedsl.de
(e180234232.adsl.alicedsl.de [85.180.234.232])
        by www.foobar.net (8.13.1/8.13.1) with SMTP id kB1LQbEt016235
        for <info () foobar net>; Fri, 1 Dec 2006 15:26:39 -0600
Date: Fri, 1 Dec 2006 15:26:37 -0600
From: info () foobar net
Message-Id: <200612012126.kB1LQbEt016235 () www foobar net>
To: info () foobar net


Current thread: