﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Ipswitch Forums / IMail Server / Ipswitch Products  / I get tons of message failure notices.... am i spamming ? / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Ipswitch Forums</description><link>http://forums.ipswitch.com/</link><webMaster>forums@ipswitch.com</webMaster><lastBuildDate>Sun, 07 Sep 2008 01:06:29 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>[quote][b]snarf0101 (4/21/2008)[/b][hr]Does the rejecting SMTP server send the NDR based on actual header data or the spoofed from address?[/quote]&lt;P&gt;NO, the rejecting server rejects it, meaning door slammed go away.&lt;/P&gt;&lt;P&gt;[quote][b]snarf0101 (4/21/2008)[/b][hr]With the nobody alias resolved to root-NUL, the invalid messages are just dropped.  No dictionary attacks or backscatter.[/quote]&lt;/P&gt;&lt;P&gt;But that means your server will now spend time and resources accepting, processing AND THEN deleting the junk mail to non-existant users. Why do you want your server to do all that extra work? And believe me, the volume of incoming email will only increase.&lt;/P&gt;&lt;P&gt;[quote][b]snarf0101 (4/23/2008)[/b][hr]So, you are fully correct that its really not my problem if my server sends the NDRs. [/quote]&lt;/P&gt;&lt;P&gt;NO, your server is NOT sending the NDRs.&lt;/P&gt;&lt;P&gt;[quote][b]snarf0101 (4/23/2008)[/b][hr]We are getting more and more clients on our servers who are getting their email address spoofed.[/quote]&lt;/P&gt;&lt;P&gt;You can not stop that, but you can use SPF records to lessen it.</description><pubDate>Fri, 25 Apr 2008 21:34:35 GMT</pubDate><dc:creator>John T</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>Add a TEXT line in your DNS entries to enable SPF.  The line should look like this:&lt;/P&gt;&lt;P&gt;DNS implementation of SPF (v=spf1 a mx ?all)&lt;/P&gt;&lt;P&gt;A really good link on this issue:&lt;/P&gt;&lt;P&gt;&lt;A href="http://spamnation.info/notes/guides/BackscatterFAQ.html"&gt;http://spamnation.info/notes/guides/BackscatterFAQ.html&lt;/A&gt;</description><pubDate>Thu, 24 Apr 2008 08:36:35 GMT</pubDate><dc:creator>skikayaker</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>The NDRs generated at the SMTP level are, sometimes, the actual goal of the spammer.  They know that most hosts will send out a Reverse NDR attack for them.  So, you are fully correct that its really not my problem if my server sends the NDRs.  However, eventually all of us sys admins (or one of our clients) will be on the receiving end of all of those messages.  We are getting more and more clients on our servers who are getting their email address spoofed.  BTW, the questions were rhetorical. </description><pubDate>Wed, 23 Apr 2008 17:47:37 GMT</pubDate><dc:creator>snarf0101</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>Correct the victem will receive the backscatter from the offending server. Which is not technically your problem.  Enabling the nobody alias, will accept all incoming email.  I suppose, if you really want all the messages you are welcome to them, but for example, if someone mistypes an email account. The sender, will never know you didnt get that clandestine wedding proposal via email that was sent to the wrong address.</description><pubDate>Tue, 22 Apr 2008 16:12:37 GMT</pubDate><dc:creator>tripodal</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>I actually just went back to review a few of my domains.  It looks as though I don't actually have a nobody alias defined for any of them.  It will reject at the SMTP RCPT level.  Not sure why I thought they were there.  &lt;/P&gt;&lt;P&gt;However, wouldn't allowing the SMTP to reject the mail result in an NDR being sent to the spoofing victim as backscatter?  Does the rejecting SMTP server send the NDR based on actual header data or the spoofed from address?  With the nobody alias resolved to root-NUL, the invalid messages are just dropped.  No dictionary attacks or backscatter.  The intention of this thread is to prevent mail from being sent BACK to the spoofing victim.  I'm not sure I follow on exactly how the nobody alias produces the OPPOSITE results.</description><pubDate>Mon, 21 Apr 2008 09:25:13 GMT</pubDate><dc:creator>snarf0101</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>[quote][b]snarf0101 (4/18/2008)[/b][hr]The bigger problem is the backscatter from clueless mail hosts who bounce the spam and generate an NDR back to your from address.  This IS fully preventable.  Everyone who is reading this:  Please do not set up your mail server to bounce spam.  Delete it or forward it to a spam account/folder and use the nobody alias to stop bounces for nonexistent accounts.  If you don't, you can get you listed on backscatterer.org.  I'll get down off my soap box now...[/quote]&lt;P&gt;&amp;lt;SHAKING HEAD IN DISGUST&amp;gt;&lt;/P&gt;&lt;P&gt;Your intention is good, but your method is hypocritical. Sorry! :w00t: :crying:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NEVER EVER EVER NEVER USE THE NOBODY ALIAS FOR ANTI-SPAM PURPOSES!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You are completely misunderstanding something, which if you would read the link you provided will show you what you stated above is OPPISATE of what you need to do.&lt;/P&gt;&lt;P&gt;If the recipient email address DOES NOT EXIST on your server, your server will REJECT the incoming email, which is the correct and proper action. By using the NOBODY alias, your server will ACCEPT it. &lt;/P&gt;&lt;P&gt;Rejecting an incoming email during the SMTP session is rejecting it, which is different than bouncing it. Bouncing is an action that is taken AFTER your server has accepted and recieved the incoming email in its entirety.</description><pubDate>Sat, 19 Apr 2008 19:27:17 GMT</pubDate><dc:creator>John T</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>I hope that no one who runs a blacklist would be moronic enough to add a domain based on the from address of the email.  This is always a spoofed email address and it just looks like its your turn to be spoofed.  There isn't a single thing you can do to prevent spammers from spoofing your address.  You can add some countermeasures such as SPF records in the DNS.  They will define what servers are allowed to send mail using your domain name.  The bigger problem is the backscatter from clueless mail hosts who bounce the spam and generate an NDR back to your from address.  This IS fully preventable.  Everyone who is reading this:  Please do not set up your mail server to bounce spam.  Delete it or forward it to a spam account/folder and use the nobody alias to stop bounces for nonexistent accounts.  If you don't, you can get you listed on backscatterer.org.  I'll get down off my soap box now...&lt;/P&gt;&lt;P&gt;&lt;A href="http://spamlinks.net/prevent-secure-backscatter.htm"&gt;http://spamlinks.net/prevent-secure-backscatter.htm&lt;/A&gt;</description><pubDate>Fri, 18 Apr 2008 20:00:08 GMT</pubDate><dc:creator>snarf0101</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>Hmm so basically theres nothing i can do about it then... ? they can just keep spoofing ?&lt;br&gt;&lt;br&gt;Does this run the risk of me getting put on URL blacklists ?</description><pubDate>Fri, 18 Apr 2008 19:19:08 GMT</pubDate><dc:creator>Ronaldr</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>Yeah, that's the behavior we see when someone spoofs one of our client's accounts. If there isn't an SPF record on the domain, we add one. But that doesn't mean that the varmints will stop spoofing the accounts.</description><pubDate>Thu, 10 Apr 2008 18:08:42 GMT</pubDate><dc:creator>lmpbhs</dc:creator></item><item><title>RE: I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>We have experienced the same issue with 3 different accounts over the last few months. Someone seems to use a persons email address&lt;BR&gt;for a day or a few days and then it's over.</description><pubDate>Wed, 09 Apr 2008 18:24:41 GMT</pubDate><dc:creator>Kimo</dc:creator></item><item><title>I get tons of message failure notices.... am i spamming ?</title><link>http://forums.ipswitch.com/Topic42694-10-1.aspx</link><description>So today i was looking through my spam account, where i forward all the spam, and i noticed ton of failure notices coming from one of our e-mail address. I know that that user did'nt send these e-mails...as theres all kinds of spam HTML and ADs on the e-mails..... and the contact details are different from e-mail to email....also the from server doesnt appear to be mine....so whats going on ?&lt;br&gt;&lt;br&gt;Is someone spoofing or changing the form ? and the replies get forwarded back to us ? or ?&lt;br&gt;&lt;br&gt;any ideas ?&lt;br&gt;&lt;br&gt;</description><pubDate>Wed, 09 Apr 2008 17:46:36 GMT</pubDate><dc:creator>Ronaldr</dc:creator></item></channel></rss>