Whitelisting of spam - forged From field in MS FE MailWatch
Posted: 01 Mar 2012, 09:19
Hi,
Unsure if this is a Mailscanner FE / Mailscanner topic, so I've gone for FE as this is where the logs were
I've just been reviewing my Mailscanner FE - MailWatch logs, and found an entry that is spam whitelisted from one of my domains in MailWatch:
myserver is my email server
oneofmydomains is, well one of my domains
I have whitelisting set for *@oneofmydomains, but only if it is "From:"
My question is, is there anything I can do to prevent this whitelisting, as arxtap is not a user account on oneofmydomains (In fact, there are only two email accounts on that domain, one is mine, one is the default cpanel one).
I have gone through logs, and can see no intrusion via ssh/whm etc from that IP address in South Africa.
So, is this just a case of a spammer forging the 'From:' field and there is nothing I can do about it ? (As it gets whitelisted due to the forging of the field?) or is there some configuration in Mailscanner FE that I have missed that could prevent/flag this appropriately ?
Thanks for any help
Andy
Unsure if this is a Mailscanner FE / Mailscanner topic, so I've gone for FE as this is where the logs were
I've just been reviewing my Mailscanner FE - MailWatch logs, and found an entry that is spam whitelisted from one of my domains in MailWatch:
myserver is my email server
oneofmydomains is, well one of my domains
Code: Select all
Message Headers:
Received: from dsl-243-50-76.telkomadsl dot co dot za ([41.243.50.76])
by myserver with smtp (Exim 4.69)
(envelope-from <arxtap@oneofmydomains>)
id 1S31eo-0001mN-L2
for arxtap@oneofmydomains Thu, 01 Mar 2012 08:46:42 +0000
To: <arxtap@oneofmydomains>
Subject: arxtap@oneofmydomains Pf|zer Discount ID8308045
From: <arxtap@oneofmydomains>
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
From: arxtaponeofmydomains
To: arxtap@oneofmydomains
Subject: arxtap@oneofmydomains Pf|zer Discount ID8308045
Size: 1.1Kb
My question is, is there anything I can do to prevent this whitelisting, as arxtap is not a user account on oneofmydomains (In fact, there are only two email accounts on that domain, one is mine, one is the default cpanel one).
I have gone through logs, and can see no intrusion via ssh/whm etc from that IP address in South Africa.
So, is this just a case of a spammer forging the 'From:' field and there is nothing I can do about it ? (As it gets whitelisted due to the forging of the field?) or is there some configuration in Mailscanner FE that I have missed that could prevent/flag this appropriately ?
Thanks for any help
Andy