Forum Moderators: phranque
How do I tell if a spammer is simply using my email address as the from address or if there is a more serious problem like an virus on my computer or server?
I'm sure there are clues in the header but I don't know what I'm looking at and I'm sure it's againts the TOS to just post the header.
It looks like a mail header is built from the bottom up in which case it seems like the email wa sent from my server. Could it be somebody is just relaying through the server?
Then, if you have an form mail script on your site check to see that it's locked down so the bad folks can't get at it.
Also, it looks like there's another round of virus e-mails. I've been getting 10 to 20 'undeliverable mail' messages a day carrying payloads.
Other than that, many spam email systems use collected addresses as fake "from" addresses when sending emails. If these emails bounce they are returned to the faked from address. It's a common problem. Just don't worry about it.
Matt
The user portion of the emails I'm seeing the bounces for is mostly random characters or random names. I mean I'm the only user of one domain and there's one additional user of the second...
One complaint from spamcop is all that it seems to take to get you booted off a host lately. I know this since one of my clients I did a site for had a legit, though not double opt-in mailing list. All it took was one or two people who forgot they signed up for the list to lodge a complaint and we were thrown off the host. Needless to say this client is now double opt-in with traceable records.
I had an old, unpatched version of that installed on a webserver that I had moved away from long ago. Some spider crawling IP addresses must have located it and put it into use.
If you haven't suckered into the scam yet, then you're ok. The messages are sent to you by infected computers. Nothing to do with any message you ever sent. They just compose messages to addresses that the virus finds either on the infected computer or from a list or somewhere.
I don't think there is any relarionship to any real message like from somebody faking their from fields using your address or ip. It's just a fake message from an infected computer.
CaboWabo