Link to home
Start Free TrialLog in
Avatar of toddh1
toddh1

asked on

Customer receiving emails fromt heir personal gmail account.

I have been getting emails from my gmail account to one of my personal work addresses. My IT looked into the headers and said it looks like it is coming from gmail and does not appear to be being spoofed.

I have gone through the steps to making sure my Gmail and Google account are secured. I have changed my password. I have enabled 2 step verification. I have changed my recovery email address. I have verified no forwarding. I have disabled Pop and Imap as I am not accessing the account any way other than through the browser. I have had my IT verify my computer is clean. I have verified that only my work computer is on the trusted list. And yet I am still getting emails to my work address that appear to be from the gmail account. I am also getting emails in my Gmail spam folder that appear like this.

Hello, this is the mail server on successrite.org.

I am sending you this message to inform you on the delivery status of a message you previously sent. Immediately below you will find a list of the affected recipients; also attached is a Delivery Status Notification (DSN) report in standard format, as well as the headers of the original message.

*Removed Email address* delivery failed; will not continue trying

Final-Recipient: rfc822;*Removed Email address* Action: failed Status: 5.0.0 (undefined status) Remote-MTA: dns;asp.reflexion.net (69.84.129.233) Diagnostic-Code: smtp;553 Your IP [69.50.210.114] is on one or more DNS blacklists. ulc: 9223368036794792238, rcp: 0001. (#5.1.1) X-PowerMTA-BounceCategory: spam-related

I am not seeing anything in my deleted or sent folders. I'm looking for ways to resolve this. Any help would be appreciated.

Header:
Received: from asp.reflexion.net (69.84.129.233) by
 SBS2008.PestbanOfGeorgia.local (192.168.16.11) with Microsoft SMTP Server id
 8.1.436.0; Wed, 16 Sep 2015 04:19:45 -0400
Received: (qmail 4979 invoked from network); 16 Sep 2015 08:19:45 -0000
Received: from unknown (HELO rtc-sm-05.app.dca.reflexion.local) (10.81.150.5)
  by 0 (rfx-qmail) with SMTP; 16 Sep 2015 08:19:45 -0000
Received: by rtc-sm-05.app.dca.reflexion.local        (Reflexion email
 security v7.70.0) with SMTP;        Wed, 16 Sep 2015 04:19:45 -0400 (EDT)
Received: (qmail 27190 invoked from network); 16 Sep 2015 08:19:45 -0000
Received: from unknown (HELO successrite.org) (69.50.192.130)  by 0
 (rfx-qmail) with SMTP; 16 Sep 2015 08:19:45 -0000
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=mail; d=successrite.org;
 h=From:To:Subject:Date:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding; i=postmaster@successrite.org;
 bh=T0GcgvEAw9y/It+8+CyVX9V9i28=;
 b=IBe8pE9q8Ab7r3OVQVnpxp+9AAh66rAF2KHc1RAN/89neDeKrZuK/DujZc4GjinHtE/DshqxjFiw
   mdTdXszYWo88TTSnxhyUDQee738LGeH5SEC4s5TMaj+TbRw6QwEotMvzbu2Bge5UOM9n5p7SlJ5Z
   ++Cly6pwGkwo3yiA5w8=
Received: from gmail.com (85.17.28.83) by successrite.org id hv4j6e0001g0 for
 <alforrette@pestbanofgeorgia.com>; Wed, 16 Sep 2015 01:20:50 -0700
 (envelope-from <alforrette@gmail.com>)
From: <alforrette@gmail.com>
To: <al@pestban.com>
Subject: Ivy-League Doctor JAILED For Revealing Diabetes Curing Secret
Date: Wed, 16 Sep 2015 10:19:40 +0200
Message-ID: <20150916101940.B439E7A971BC8467@gmail.com>
MIME-Version: 1.0
Content-Type: text/html; charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
X-Rfx-Message-Id: 12485517438/21737148979/0001
X-Rfx-Recipient-Address: alforrette@pestbanofgeorgia.com
Return-Path: alforrette@gmail.com
ASKER CERTIFIED SOLUTION
Avatar of David Sankovsky
David Sankovsky
Flag of Israel image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of toddh1
toddh1

ASKER

I didn't think to do a whois on the IP.  I have submitted to both Google and that abuse email listed above.   Thank you very much for your help.