Forum Moderators: phranque

Message Too Old, No Replies

what is the purpose of these multiple unidentified emails?

is someone probing our site for an email spam campaign?

         

zollerwagner

5:17 am on Feb 22, 2003 (gmt 0)

10+ Year Member



Hi,

One of my clients' sites has been receiving regular emails from what appear to be junk or fake email addresses, as though someone is testing our site for email addresses.

They'll send one to sales@domain.com, another to info@domain.com, one to webmaster@domain.com, and so on. It's slow but persistent over the past couple of weeks.

The "received from" ip addresses don't resolve when I checked them.

Can anyone tell me what this is all about? What can I do about it? Or should I worry?

Here is the detail of one of the emails (with our domains and addresses changed)

Received: from mail.DDD.com [111.111.111.111] by mail.EEE.com
(SMTPD32-7.07) id A75C40550; Fri, 21 Feb 2003 21:58:36 -0500
Received: (qmail 22818 invoked by uid 110); 22 Feb 2003 02:56:17 -0000
Delivered-To: FFF.com-GGG@GGG.com
Received: (qmail 22815 invoked by uid 110); 22 Feb 2003 02:56:17 -0000
Delivered-To: HHH@GGG.com /* ABOVE here it's just forwarding to me */
Received: (qmail 22809 invoked from network); 22 Feb 2003 02:56:16 -0000
Received: from unknown (HELO III.III.com) (222.222.222.222)
by 333.333.333.333 with SMTP; 22 Feb 2003 02:56:16 -0000
Received: from JJJ.JJJ.com (JJJ.JJJ.com [444.444.444.444])
by JJJ.JJJ.com (8.11.6/8.11.6/NNNNNN NNN Antispam Version) with ESMTP id h1M2nhn38119
for <info@MYCLIENT.com>; Sat, 22 Feb 2003 03:49:43 +0100 (CET)
Received: from 200.10.65.182 ([200.10.65.182])
by JJJ.JJJ.com (555.555.555.555/NNNNNN NNN Antispam Version) with SMTP id h1M2t5T04247
for <info@MYCLIENT.com>; Sat, 22 Feb 2003 03:55:07 +0100
Received: from aol.com (2364 [155.77.99.229])
by msn.com (8.12.1/8.12.1) with ESMTP id 14833
for <info@MYCLIENT.com>; Fri, 21 Feb 2003 18:53:26 -0800
Received: from mail.com ([82.194.116.216])
by mail.com (8.9.3/8.9.3) with SMTP id 27051
for <info@MYCLIENT.com>; Fri, 21 Feb 2003 18:53:21 -0800
Message-ID: <621023532lqirCihuulwr1frp@eudoramail.com>
From: "umanalis" <sezar_158135falsa1@yahoo.com>
To: "" <info@MYCLIENT.com>
Date: Fri, 21 Feb 2003 18:53:17 -0800
Subject:
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
MIME-Version: 1.0
Content-Type: multipart/related;
boundary="----=_NextPart_000_000B_7B7040C3.06160D2F"
X-RCPT-TO: <MY EMAIL ADDRESS!-->AAA@AAA.com>
Status: U
X-UIDL: 329473067

------=_NextPart_000_000B_7B7040C3.06160D2F
Content-Type: text/html;
Content-Transfer-Encoding: base64

PCEtLTc2MzcyMTQ0MC0tPjxib2R5PjwhLS0zMDQwODU1NjgtLT50ZTwhLS0yNDcwNzExOTg2
LS0+c3QsIG48IS0tNzMzMzAyOTItLT5vIHJlcDwhLS0yMjUyMjIzODc0LS0+bGF5IHBsZTwh
LS0yODk0MDYxNy0tPmFzZTwvYm9keT4=

(Yes, that's really how many of these things end.)

TIA

buckworks

6:16 am on Feb 22, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



I have no answers, but in the last few days my catchall has picked up several emails that sound similar. The text in the body is always the same: "Test, no replay please".

Jane_Doe

6:24 am on Feb 22, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I've gotten the "replay" emails too for nonexistent prefixes ending with @ my domain name. It's like on Star Trek when they send out a probe to gather data about another vessel. I feel like my email boxes are being probed by some alien spammers.

zollerwagner

6:50 am on Feb 22, 2003 (gmt 0)

10+ Year Member



Exactly, it creeps me out!

Let's hope someone has an answer for us.

Phil_C

7:15 am on Feb 22, 2003 (gmt 0)

10+ Year Member



I've also been getting these "Test, no reply please" messages, in addition to the 10-20 other spam messages per day. I guess they hope people will reply so they can be added to their live database...

Phil