Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

How do I catch this spammer?

Posted on 2009-07-13
3
Medium Priority
?
323 Views
Last Modified: 2013-12-09
I have a client who's been getting these bounce-backs to his email. I've tried to use the exchange message tracker, but the bounced messsages don't show up. I'm guessing that someone who associates with him has a spammer virus that is using the addresses in their mailbox as return addresses for spam. I have a copy of one of the bounces, and I see some interesting data, but I don't know what to do with it. Can someone tell me if there is anything in this that I could use to track down this spammer? The user and company name have been changed for privacy.
readthis.txt
0
Comment
Question by:numb3rs1x
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 65

Accepted Solution

by:
Mestha earned 2000 total points
ID: 24845407
Short answer. No.
Long answer. Don't waste your time.

Spammers have a lot of techniques for hiding, the use of bots, compromised Exchange servers etc. Finding how is behind it is impossible.

The spammer will just be picking a random email address to use as the from field.
The real problem is the clueless network admins who reject spam AFTER delivery and try to send it back to the sender. The sender is always spoofed so this is a waste of time.

Simon.
0
 

Author Comment

by:numb3rs1x
ID: 24846512
Is there something I can do to prevent this?
0
 
LVL 65

Expert Comment

by:Mestha
ID: 24847781
No.
Its known as back scatter. Under the terms of the RFC (which is basically the instructions as to how SMTP works) your server has to accept the NDRs. What you do with them after they have been delivered to your server is up to you.

Some may suggest SPF records, but that is an advanced antispam procedure. If those operating the software cannot get the basis correct - such as recipient filtering, then they are hardly going to be able to setup a rejection on the SPF record.

Simon.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out the latest tech news, community articles, and expert highlights in August's newsletter.
A new hacking trick has emerged leveraging your own helpdesk or support ticketing tools as an easy way to distribute malware.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

661 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question