Link to home
Start Free TrialLog in
Avatar of handsun123
handsun123

asked on

are my clients spamming

I am a web designer who offers hosting to my clients, all the accounts are on a shared server at hosygator. Recently some of my clients cannot receive my emails, and I am not spamming. Could the problem be related to  the domains on my shared account (I host about 20 domains with email addresses, and my domain is in the same account.) This is all getting so complicated, I just wanted to help out my clients and only charge them $5 a month to host their small business sites with very little traffic.
Avatar of handsun123
handsun123

ASKER

saw the typo - hostgator!
Avatar of Jon Scriven
Hi handsun123,

Unfortunately if one of your clients was spamming, then it is possible that your whole mail server could be blacklisted.

However, if it is not set-up properly (using an SPF record for instance) it could also be greylisted.

You could use a tool to see if you are on blacklists:-

http://www.mxtoolbox.com/blacklists.aspx

Is there a particular domain that these users are on?  For instance Yahoo is quite quick to Greylist if not set-up properly....
Might be worth talking to the IT people at places where your mail is not getting through to see why.

There are also diagnostics on the site I linked to to look at the set-up and identify problems:-

http://www.mxtoolbox.com/diagnostic.aspx
http://www.mxtoolbox.com/spf.aspx

You should have an SPF record and reverse DNS configured for instance.....
I had already run the first check and did the ping email and got this response, (Unknown)   was your outbound IP address.

but then I checked your second comment, on the first link the list for my domain is all "ok" with 3 timeouts,

and the spf lookup
      a            Pass      Match if IP has a DNS 'A' record in given domain
+      mx            Pass      Match if IP is one of the MX hosts for given domain name
+      include      websitewelcome.com      Pass      The specified other domain is searched for an 'allow'.
~      all            SoftFail      Always matches. It goes at the end of your record.

The IT person at the business who cannot get my emails has not returned my call for over two weeks, so I am trying to take matters into my own hands because I saw a second email bounce back from another client a few days ago, first time ever: this was the message: (strange thing this had nothing to do with gmail?) (I put the XXXX in)

Hi. This is the qmail-send program at gateway16.websitewelcome.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<XXXXXX@deccahomes.com>:
72.47.228.252 failed after I sent the message.
Remote host said: 550-Possible email abuse detected.  Please see
550 http://kb.mediatemple.net/questions/1685 for details.

qmail, not gmail!  This is an MTA (Mail Transport Agent) used for delivering Emails.  Nothing to do with Google!

Did you check the blacklist link I put in the first Email?

Although from looking at the link included in that response, it could just be mail that LOOKS suspicious.

I would follow the instructions included in the response to see if you can get the mail included.

http://kb.mediatemple.net/questions/1685

If you have Gmail (or similar) yourself, it might be worth sending yourself a message and then checking the header which will have information about what happened when it was SPAM checked.

If you post the mail header here, we can have a look at it.....
  First of all THANK you so much for your honest and sincere help, second, I xxx'd out the first names just for security issues, probably already showing everything anyway with the numbers but what the heck, if I can clear this problem up here is the header in my gmail account (silly of me q for g!)                                                                                                                                                                                                                                                            
Delivered-To: xxxxxa@gmail.com
Received: by 10.231.19.4 with SMTP id y4cs26688iba;
        Fri, 11 Mar 2011 04:50:44 -0800 (PST)
Received: by 10.52.100.70 with SMTP id ew6mr6777558vdb.95.1299847844330;
        Fri, 11 Mar 2011 04:50:44 -0800 (PST)
Return-Path: <xxxxx@iwebresults.com>
Received: from gateway12.websitewelcome.com ([69.93.82.6])
        by mx.google.com with SMTP id dw3si5444769vbb.9.2011.03.11.04.50.42;
        Fri, 11 Mar 2011 04:50:43 -0800 (PST)
Received-SPF: pass (google.com: domain of xxxxx@iwebresults.com designates 69.93.82.6 as permitted sender) client-ip=69.93.82.6;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of xxxxx@iwebresults.com designates 69.93.82.6 as permitted sender) smtp.mail=xxxxx@iwebresults.com
Received: (qmail 26614 invoked from network); 11 Mar 2011 12:49:14 -0000
Received: from gator793.hostgator.com (174.120.1.2)
  by gateway12.websitewelcome.com with SMTP; 11 Mar 2011 12:49:14 -0000
Received: from [75.91.89.212] (port=51950 helo=[192.168.254.102])
      by gator793.hostgator.com with esmtpsa (TLSv1:AES256-SHA:256)
      (Exim 4.69)
      (envelope-from <xxxxx@iwebresults.com>)
      id 1Py1nm-00008J-8E
      for xxxxxxx@gmail.com; Fri, 11 Mar 2011 06:50:42 -0600
Message-ID: <4D7A1A9F.1060304@iwebresults.com>
Date: Fri, 11 Mar 2011 07:50:39 -0500
From:xxxxxxn <xxxxx@iwebresults.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.15) Gecko/20110303 Lightning/1.0b2 Thunderbird/3.1.9
MIME-Version: 1.0
To: xxxxxa@gmail.com
Subject: checking
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator793.hostgator.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - iwebresults.com
X-Source:
X-Source-Args:
X-Source-Dir:

OK - I got the IP address from that header and ran it through the Blacklist checker and it shows as being on a couple of blacklists.

http://www.mxtoolbox.com/SuperTool.aspx?action=blacklist%3a69.93.82.6

Here are the blacklist positives:-

http://www.sorbs.net/lookup.shtml?69.93.82.6
http://www.spamcannibal.org/cannibal.cgi?page=lookup&lookup=69.93.82.6

If you follow those links, they should give you information about getting them removed, however, if the source of the problem is not identified / resolved, you will find that you just get blacklisted again.

I would talk to Hostgator about how to identify which domains the Spam is originating from.  I would probably start with a letter to all your clients though outlining the problem and informing them that this affects all your clients and that you are investigating the problem.  This might be enough to scare them into stopping.
ASKER CERTIFIED SOLUTION
Avatar of Jon Scriven
Jon Scriven
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks again so much I will look into the complaints, I do not recognize anything in the email, but I might need to host my own domain in a separate account just to be sure my clients actions do not affect me. Oh more trouble that I would like to deal with at this point in time!
If you don't recognise anything in those headers, I would definitely run it past Hostgator, it might be another one of their users or something they are able to help you with.  Once the problem is identified / resolved you can ask to be removed from blacklists.  I would exhaust those options before doing anything drastic as it looks like the Spam in question was quite old (9 months ago) and so it might be worth asking to be removed anyway as this is quite old and might be something historic.
I will call hostgator, thanks again!