<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spam tsunami in Email</title>
    <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045041#M60561</link>
    <description>&lt;P&gt;An inbound server would be on a blacklist if they allow SPAM to be send i.e. they do not control their customers sending spam despite complains.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Markus&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 May 2026 13:57:43 GMT</pubDate>
    <dc:creator>M-M</dc:creator>
    <dc:date>2026-05-04T13:57:43Z</dc:date>
    <item>
      <title>Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044892#M60525</link>
      <description>It seems to me strange to converse in a Plusnet forum when discussing Greenby email, but here goes.&lt;BR /&gt;What's the point of the Blacklist feature?&lt;BR /&gt;&lt;BR /&gt;My mailbox, is also setup as 2 separate forwarders.&lt;BR /&gt;The mailbox receives about 10 emails a day in addition to about 100 SPAM - the Blacklist seems totally ineffective.&lt;BR /&gt;Forwarder #1 forwards via a Cloudflare redirect to a Gmail account, Cloudflare is not delivering (is blocking) the SPAM.&lt;BR /&gt;Forwarder #2 is direct to the Gmail account that successfully identifies about 90% of the SPAM.&lt;BR /&gt;The 2 forwarded emails are not duplicated, as I suspect Gmail is treating identical message IDs as one message.</description>
      <pubDate>Sat, 02 May 2026 08:05:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044892#M60525</guid>
      <dc:creator>jkg</dc:creator>
      <dc:date>2026-05-02T08:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044893#M60526</link>
      <description>&lt;P&gt;I'm having success with an MS Outlook filter to detect spam based on the message header contents.&lt;BR /&gt;&lt;BR /&gt;I move the new message to Junk if the email header contains any of : &lt;BR /&gt;&lt;BR /&gt;dkim=fail&lt;BR /&gt;dmark=fail&lt;BR /&gt;spf=fail&lt;BR /&gt;spf=softfail&lt;BR /&gt;( unknown[&lt;BR /&gt;BAYES_SPAM(5.&lt;BR /&gt;HFILTER_HOSTNAME_UNKNOWN&lt;BR /&gt;RDNS_NONE&lt;BR /&gt;.shop&lt;BR /&gt;.click&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2026 08:28:24 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044893#M60526</guid>
      <dc:creator>PhilipHeyes</dc:creator>
      <dc:date>2026-05-02T08:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044923#M60535</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see also a lot of SPAM lately on my Plusnet email mailboxes.&amp;nbsp; When I check the IPs sendong it they are all listed in spamhaus as bad senders.&amp;nbsp; Why is Plusnet not blocking bad senders which I thought was the default setting ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The default setting description says:&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;With spam filtering turned on, emails sent from mailservers with a bad SenderBase reputation will be rejected and bounced back to the sender. Emails that pass this first check are scanned and given a spam rating. What happens then depends on the settings which follow.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I would be curious what "block obvious spam" means I would hope any email from known spam mailservers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone from Plusnet on these forums to explain this ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also Plusnet's mail servers are on the blacklists &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;# nslookup 212.159.14.26&lt;BR /&gt;26.14.159.212.in-addr.arpa name = avasin-peh-006.plus.net.&lt;/P&gt;
&lt;P&gt;Authoritative answers can be found from:&lt;/P&gt;
&lt;P&gt;#./dnsblcheck 212.159.14.26&lt;BR /&gt;Checking: 212.159.14.26&lt;BR /&gt;-------------------------&lt;BR /&gt;[LISTED] 212.159.14.26 on zen.spamhaus.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on bl.spamcop.net&lt;BR /&gt;[OK] 212.159.14.26 not listed on b.barracudacentral.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on dnsbl.sorbs.net&lt;BR /&gt;[LISTED] 212.159.14.26 on cbl.abuseat.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on psbl.surriel.com&lt;BR /&gt;[OK] 212.159.14.26 not listed on dnsbl-1.uceprotect.net&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Markus&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2026 16:23:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044923#M60535</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-02T16:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044943#M60541</link>
      <description>&lt;P&gt;Small correction the SPAM listing for&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;212.159.14.26 is wrong i.e. I used cloudflare's 1.1.1.1 DNS server which gets worng responses. Using unbound I get&amp;nbsp; a clean response.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;/dnsblcheck 212.159.14.26&lt;BR /&gt;Checking: 212.159.14.26&lt;BR /&gt;-------------------------&lt;BR /&gt;[OK] 212.159.14.26 not listed on zen.spamhaus.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on bl.spamcop.net&lt;BR /&gt;[OK] 212.159.14.26 not listed on b.barracudacentral.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on dnsbl.sorbs.net&lt;BR /&gt;[OK] 212.159.14.26 not listed on cbl.abuseat.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on psbl.surriel.com&lt;BR /&gt;[OK] 212.159.14.26 not listed on dnsbl-1.uceprotect.net&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Markus&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 May 2026 11:50:31 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044943#M60541</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-03T11:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044998#M60544</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/111765"&gt;@M-M&lt;/a&gt; we found the Plusnet spam filter controls stopped working during the tail end of 2025, you may recall spam emails used to be marked as [-SPAM-] in the Subject: field.&lt;BR /&gt;&lt;BR /&gt;Once email migrates to &lt;A href="http://www.greenby.com" target="_blank" rel="noopener"&gt;www.greenby.com&lt;/A&gt; there are Spam settings in the Greenby Portal ( i.e. not webmail ), if enabled this will divert spam to a Junk / Spam folder on the email server. That folder needs to be checked for false positives, or disabled if you prefer to deal with spam in a mail client like MS Outlook or Thunderbird etc. &lt;BR /&gt;&lt;BR /&gt;I am suspecting your email is not be migrated to Greenby as host : &lt;STRONG&gt;avasin-peh-006.plus.net 212.159.14.26&lt;/STRONG&gt;&amp;nbsp; is a Plusnet hosted in-bound email server.&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 07:33:32 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2044998#M60544</guid>
      <dc:creator>PhilipHeyes</dc:creator>
      <dc:date>2026-05-04T07:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045003#M60547</link>
      <description>&lt;P&gt;Why would an inbound server be on a blacklist?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 09:09:24 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045003#M60547</guid>
      <dc:creator>abitpedantic</dc:creator>
      <dc:date>2026-05-04T09:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045034#M60557</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Trying to complain to abuse@plus.net I get blocked. I complaint to OFCOM as they must accept these emails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Plusnet-Block.png"&gt;&lt;img src="https://community.plus.net/skins/images/95B68FA8CA7035662035F4DD80B308B7/responsive_peak/images/image_unmoderated.gif" alt="Plusnet-Block.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 13:37:08 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045034#M60557</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-04T13:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045040#M60560</link>
      <description>&lt;P&gt;It seems also my postings get blocked.&amp;nbsp; I had posted this:&lt;/P&gt;
&lt;P&gt;Which did not appear anywhere.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Postiing-Evidence.png"&gt;&lt;img src="https://community.plus.net/skins/images/95B68FA8CA7035662035F4DD80B308B7/responsive_peak/images/image_unmoderated.gif" alt="Postiing-Evidence.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 13:46:52 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045040#M60560</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-04T13:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045041#M60561</link>
      <description>&lt;P&gt;An inbound server would be on a blacklist if they allow SPAM to be send i.e. they do not control their customers sending spam despite complains.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Markus&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 13:57:43 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045041#M60561</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-04T13:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045045#M60563</link>
      <description>&lt;P&gt;I need to post as image as it gets removed. ( this was message 10 under this subject as you can see on the bottom of the image )&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Message-10.png"&gt;&lt;img src="https://community.plus.net/skins/images/95B68FA8CA7035662035F4DD80B308B7/responsive_peak/images/image_unmoderated.gif" alt="Message-10.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 14:05:09 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045045#M60563</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-04T14:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045048#M60564</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/111765"&gt;@M-M&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I see also a lot of SPAM lately on my Plusnet email mailboxes.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I see no spam.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/111765"&gt;@M-M&lt;/a&gt;&amp;nbsp;wrote:
&lt;P&gt;Also Plusnet's mail servers are on the blacklists &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;# nslookup 212.159.14.26&lt;BR /&gt;26.14.159.212.in-addr.arpa name = avasin-peh-006.plus.net.&lt;/P&gt;
&lt;P&gt;Authoritative answers can be found from:&lt;/P&gt;
&lt;P&gt;#./dnsblcheck 212.159.14.26&lt;BR /&gt;Checking: 212.159.14.26&lt;BR /&gt;-------------------------&lt;BR /&gt;[LISTED] 212.159.14.26 on zen.spamhaus.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on bl.spamcop.net&lt;BR /&gt;[OK] 212.159.14.26 not listed on b.barracudacentral.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on dnsbl.sorbs.net&lt;BR /&gt;[LISTED] 212.159.14.26 on cbl.abuseat.org&lt;BR /&gt;[OK] 212.159.14.26 not listed on psbl.surriel.com&lt;BR /&gt;[OK] 212.159.14.26 not listed on dnsbl-1.uceprotect.net&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Not what I'm seeing.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.whois.com/whois/212.159.14.26" target="_blank" rel="noopener"&gt;https://www.whois.com/whois/212.159.14.26&lt;/A&gt;&lt;/P&gt;
&lt;PRE&gt;inetnum: 212.159.14.0 - 212.159.14.127&lt;BR /&gt;netname: PLUSNET-PORTAL-SERVERS&lt;BR /&gt;descr: Plusnet Portal Servers&lt;BR /&gt;descr: PlusNet Technologies Ltd&lt;BR /&gt;remarks: INFRA-AW&lt;BR /&gt;country: GB&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;A href="https://check.spamhaus.org/212.159.14.26" target="_blank" rel="noopener"&gt;https://check.spamhaus.org/212.159.14.26&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;212.159.14.26 has no issues&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://check.spamhaus.org/results?query=avasin-peh-006.plus.net" target="_blank" rel="noopener"&gt;https://check.spamhaus.org/results?query=avasin-peh-006.plus.net&lt;/A&gt;&lt;/STRONG&gt;&lt;BR /&gt;"&lt;EM&gt;avasin-peh-006.plus.net has no issues&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;Again - where is this spam?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 14:20:33 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045048#M60564</guid>
      <dc:creator>pvmb</dc:creator>
      <dc:date>2026-05-04T14:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045053#M60565</link>
      <description>&lt;P&gt;The Spam is in many people's Plusnet mailboxes.&lt;/P&gt;
&lt;P&gt;You seem to be lucky.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is hundreds a day like the attached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Markus&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Return-path: &amp;lt;user@lastname.plus.com&amp;gt;&lt;BR /&gt;Envelope-to: user@lastname.plus.com&lt;BR /&gt;Delivery-date: Sun, 03 May 2026 08:51:56 +0100&lt;BR /&gt;Received: from [84.93.230.243] (helo=avasin-ptp-007.plus.net)&lt;BR /&gt;by inmx-peh-010.plus.net with esmtp (PlusNet MXCore v2.00) id 1wJRcK-00083o-Gt &lt;BR /&gt;for user@lastname.plus.com; Sun, 03 May 2026 08:51:56 +0100&lt;BR /&gt;Received: from mail.enmail.co ([91.204.208.8])&lt;BR /&gt;by Plusnet Cloudmark Gateway with ESMTP&lt;BR /&gt;id JRbkw4jgEl3NFJRbkw7kHa; Sun, 03 May 2026 08:51:20 +0100&lt;BR /&gt;X-CM-Score: 100.00&lt;BR /&gt;X-CNFS-Analysis: v=2.4 cv=O4iavw9W c=1 sm=1 tr=0 ts=69f6fe78&lt;BR /&gt;p=cldSXMTIpfOU4Y6ndKLFjA==:17 p=xuSakxmQ/AEa0MmB+nwSGURWKu8=:19&lt;BR /&gt;p=PTyU9qhKzLH6fPggfxA3TfOAniY=:19 p=jCbGUyW4jJGoy8l3dHf0DG8VQv0=:19&lt;BR /&gt;p=NX+gl+Xpg2tz9MSno0cNtH3+2FI=:19 p=bU8HyK+u2KSFcGbJwLAM7afV7Pw=:19&lt;BR /&gt;p=1VCpbxcMXNoKQD3_8Deh:22 a=/50HAxhVri9f9h8qkinWjQ==:117 a=NGcC8JguVDcA:10&lt;BR /&gt;a=tQgp67HcAAAA:8 a=lxoXj2O9AAAA:8 a=5TAOmqheAAAA:8 a=es68Ls6DAAAA:8&lt;BR /&gt;a=7LJQYQ5cGpOTLzKPqbUA:9 a=7zbRnxVGAaKOODsWIkmG:22&lt;BR /&gt;Received: from [198.163.193.190] (unknown [198.163.193.190])&lt;BR /&gt;by mail.enmail.co (Postfix) with ESMTP id DC570C0049&lt;BR /&gt;for &amp;lt;user@lastname.plus.com&amp;gt;; Sun, 3 May 2026 07:51:17 +0000 (UTC)&lt;BR /&gt;Authentication-Results: mail.enmail.co;&lt;BR /&gt;dkim=none;&lt;BR /&gt;spf=softfail (mail.enmail.co: 198.163.193.190 is neither permitted nor denied by domain of user@lastname.plus.com) smtp.mailfrom=user@lastname.plus.com;&lt;BR /&gt;dmarc=fail reason="No valid SPF, No valid DKIM" header.from=plus.com (policy=none)&lt;BR /&gt;Received: from wurggqe ([60.220.73.164]) by 15751.com with MailEnable ESMTP; Sun, 3 May 2026 12:51:27 +0500&lt;BR /&gt;Received: (qmail 54451 invoked by uid 544); 3 May 2026 12:51:25 +0500&lt;BR /&gt;From: user@lastname.plus.com&lt;BR /&gt;To: user@lastname.plus.com&lt;BR /&gt;Date: Sun, 3 May 2026 12:51:27 +0500&lt;BR /&gt;Message-ID: &amp;lt;544510.544510@15751.com&amp;gt;&lt;BR /&gt;Mime-Version: 1.0&lt;BR /&gt;Content-type: text/plain;&lt;BR /&gt;X-Spamd-Result: default: False [9.70 / 4.00];&lt;BR /&gt;BAYES_SPAM(5.10)[100.00%];&lt;BR /&gt;SUBJ_ALL_CAPS(2.10)[28];&lt;BR /&gt;RDNS_NONE(2.00)[];&lt;BR /&gt;MV_CASE(0.50)[];&lt;BR /&gt;MIME_GOOD(-0.10)[text/plain];&lt;BR /&gt;DMARC_POLICY_SOFTFAIL(0.10)[plus.com : No valid SPF, No valid DKIM,none];&lt;BR /&gt;ASN(0.00)[asn:8193, ipnet:198.163.193.0/24, country:UZ];&lt;BR /&gt;FROM_NO_DN(0.00)[];&lt;BR /&gt;RCVD_COUNT_ONE(0.00)[1];&lt;BR /&gt;MIME_TRACE(0.00)[0:+];&lt;BR /&gt;RCPT_COUNT_ONE(0.00)[1];&lt;BR /&gt;ARC_NA(0.00)[];&lt;BR /&gt;R_DKIM_NA(0.00)[];&lt;BR /&gt;TO_EQ_FROM(0.00)[];&lt;BR /&gt;FROM_EQ_ENVFROM(0.00)[];&lt;BR /&gt;FUZZY_RATELIMITED(0.00)[rspamd.com];&lt;BR /&gt;R_SPF_SOFTFAIL(0.00)[~all:c];&lt;BR /&gt;TO_MATCH_ENVRCPT_ALL(0.00)[];&lt;BR /&gt;TO_DN_NONE(0.00)[];&lt;BR /&gt;NEURAL_SPAM(0.00)[1.000]&lt;BR /&gt;X-Spam: Yes&lt;BR /&gt;X-Original-Recipient: user@lastname.plus.com&lt;BR /&gt;X-CMAE-Envelope: MS4xfG04MJaV1IMERR9BtDs79CH3KUWx2YjRO3GWJJXcblnEymzeGktrgkEEzIsEt9inxVKyuFcSt53rkoCqE3zSI3gGhWWMPr5ZphdlWKvorrm65gJRwO2Z&lt;BR /&gt;7E0RADvYrixQTibfmY9QUYTg8EKoLifhDCJCsgGXwlHXUopSHVV1usdOCWiQA807Q9Hg/ezGkm6RRiEzESqb/gXHaDNItCpPAAM=&lt;BR /&gt;X-pn-pstn-db:" Spam 99&lt;BR /&gt;X-PN-Spam-Filtered: by PlusNet MXCore (v5.00)&lt;BR /&gt;Subject: YOU PERVERT, I RECORDED YOU!&lt;/P&gt;
&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;Unfortunately, there is some bad news for you.&lt;/P&gt;
&lt;P&gt;Some time ago, your device was infected with my private Trojan, R.A.T (Remote Administration Tool).&lt;/P&gt;
&lt;P&gt;If you want to find out more about it, simply use Google.&lt;/P&gt;
&lt;P&gt;My Trojan allowed me to access your files, accounts, and your camera.&lt;/P&gt;
&lt;P&gt;Check the sender of this email, I have sent it from your email account.&lt;/P&gt;
&lt;P&gt;To ensure you read this email, you will receive it multiple times.&lt;/P&gt;
&lt;P&gt;I RECORDED YOU (through your camera) MASTURBATING!&lt;/P&gt;
&lt;P&gt;After that, I removed my malware to leave no traces.&lt;/P&gt;
&lt;P&gt;If you still doubt my serious intentions, it only takes a couple of mouse clicks to share the video of you masturbating with your family, friends, relatives, all email contacts, on social networks and the darknet.&lt;/P&gt;
&lt;P&gt;All you need is $800 USD in Bitcoin (BTC), transferred to my wallet address.&lt;/P&gt;
&lt;P&gt;After the transaction is successful, I will proceed to delete everything.&lt;/P&gt;
&lt;P&gt;I keep my promises!&lt;/P&gt;
&lt;P&gt;You can purchase Bitcoin (BTC) from reputable exchanges here:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://binance.com" target="_blank"&gt;http://binance.com&lt;/A&gt; - Payment options: Credit/debit cards, bank transfers, P2P trading, third-party payment providers, and gift cards.&lt;BR /&gt;&lt;A href="http://bitrefill.com" target="_blank"&gt;http://bitrefill.com&lt;/A&gt; - Payment options: Paysafecard, credit/debit cards, crypto, bank transfer, and other gift card options.&lt;BR /&gt;&lt;A href="http://crypto.com" target="_blank"&gt;http://crypto.com&lt;/A&gt; - Payment options: Credit/debit cards, bank transfers, Apple Pay, Google Pay, and more.&lt;BR /&gt;&lt;A href="http://kucoin.com" target="_blank"&gt;http://kucoin.com&lt;/A&gt; - Payment options: Credit/debit cards, bank transfer, third-party payment providers, and peer-to-peer.&lt;/P&gt;
&lt;P&gt;Alternatively, simply Google for other exchanges.&lt;/P&gt;
&lt;P&gt;Once purchased, you can send the Bitcoin directly to my wallet address or use a wallet application such as Atomic Wallet or Exodus Wallet to manage your transactions.&lt;/P&gt;
&lt;P&gt;My Bitcoin (BTC) wallet address is: 1LK753UYyYXPcUthYTrxgnaGC8qxXN8ZUK&lt;/P&gt;
&lt;P&gt;Yes, that's how the wallet address looks like. Copy and paste my wallet address, it's (case-sensitive).&lt;/P&gt;
&lt;P&gt;A piece of advice from me: regularly change all your passwords and update your device with the latest security patches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 15:00:03 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045053#M60565</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-04T15:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045060#M60566</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/111765"&gt;@M-M&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This seems significant:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Received: from [198.163.193.190] (unknown [198.163.193.190])&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;by mail.enmail.co (Postfix) with ESMTP id DC570C0049&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://check.spamhaus.org/results?query=198.163.193.190" target="_blank" rel="noopener"&gt;https://check.spamhaus.org/results?query=198.163.193.190&lt;/A&gt;&lt;BR /&gt;"&lt;EM&gt;198.163.193.190 has 3 listings&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Robot&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;Please don’t be alarmed! We understand finding your IP address, domain, URL or ASN on a blocklist can be worrying. This website will give you information about why you are listed and what you can do to ensure you don’t get listed again.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Where it is possible to request removal, we will help you through the process. However, if your IP is listed on the Spamhaus Blocklist (SBL), removal can only be requested by your Internet Service Provider (ISP).&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Close&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;1. eXploits Blocklist (XBL) &amp;amp; CSS Blocklist (CSS) - Why is this IP address listed?&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;The machine using this IP is infected with malware that is emitting spam, or is sharing a connection with an infected device.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;As a result, this IP is listed in the eXploits Blocklist (XBL) and the CSS Blocklist (CSS)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Click on More Info to see if you can request a delisting from this blocklist. This will also display any further information we have relating to this listing.Return-path: &amp;lt;user@lastname.plus.com&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;A href="https://www.whois.com/whois/198.163.193.190" target="_blank" rel="noopener"&gt;https://www.whois.com/whois/198.163.193.190&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;BR /&gt;% Information related to '198.163.193.0 - 198.163.193.255'&lt;BR /&gt;% Abuse contact for '198.163.193.0 - 198.163.193.255' is 'email@bkm.uz'&lt;BR /&gt;inetnum: 198.163.193.0 - 198.163.193.255&lt;BR /&gt;netname: UZTELECOM&lt;BR /&gt;country: UZ&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;Domain listed as in Uzbekistan.&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 15:33:44 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045060#M60566</guid>
      <dc:creator>pvmb</dc:creator>
      <dc:date>2026-05-04T15:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045073#M60567</link>
      <description>&lt;P&gt;Yes and enmail.co should have blocked it as a it comes from a blacklisted mailserver instead it forwards to plusnet.&amp;nbsp; Plusnet should blacklist enmail.co servers, which I did i.e. reported to spamhaus.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checking: 198.163.193.190 []&lt;BR /&gt;-------------------------&lt;BR /&gt;[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.11 (PBL (Policy Block List))&lt;BR /&gt;[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.4 (XBL (Exploits Block List))&lt;BR /&gt;[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.3 (CSS (Spamhaus CSS))&lt;BR /&gt;[OK] 198.163.193.190 not listed on bl.spamcop.net&lt;BR /&gt;[OK] 198.163.193.190 not listed on b.barracudacentral.org&lt;BR /&gt;[OK] 198.163.193.190 not listed on dnsbl.sorbs.net&lt;BR /&gt;[LISTED] 198.163.193.190 on cbl.abuseat.org → 127.0.0.2&lt;BR /&gt;[OK] 198.163.193.190 not listed on psbl.surriel.com&lt;BR /&gt;[LISTED] 198.163.193.190 on dnsbl-1.uceprotect.net → 127.0.0.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 17:17:17 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045073#M60567</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-04T17:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045086#M60568</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp; think the whole SPAM problem started with plusnet changing the mail routing to enmail.co ( which I guess is Greenby ) and they do not perform blacklist enforcement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can test this with nslookup.&amp;nbsp; It does not point to the plusnet mail servers, but to enmail.co&lt;/P&gt;
&lt;P&gt;#nslookup -querytype=mx someone.plus.com &lt;BR /&gt;Server: 127.0.0.53&lt;BR /&gt;Address: 127.0.0.53#53&lt;/P&gt;
&lt;P&gt;Non-authoritative answer:&lt;BR /&gt;someone.plus.com mail exchanger = 10 &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;mx.enmail.co.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Plusnet itself uses Microsoft email.&lt;/P&gt;
&lt;P&gt;#nslookup -querytype=mx plus.net&lt;BR /&gt;Server: 127.0.0.53&lt;BR /&gt;Address: 127.0.0.53#53&lt;/P&gt;
&lt;P&gt;Non-authoritative answer:&lt;BR /&gt;plus.net mail exchanger = 10 btgroupcloud-mail-onmicrosoft-com.mail.protection.outlook.com.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Markus&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 07:04:35 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045086#M60568</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-05T07:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045092#M60572</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/111765"&gt;@M-M&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Yes and enmail.co should have blocked it as a it comes from a blacklisted mailserver instead it forwards to plusnet.&amp;nbsp; Plusnet should blacklist enmail.co servers, which I did i.e. reported to spamhaus.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;But who says it is coming from a blacklisted "&lt;EM&gt;mailserver&lt;/EM&gt;"? It's apparently coming from an IP address, in a domain belonging to Uzbektelecom. It is for them to deal with spammers originating within their control. You could try contacting them directly.&lt;/P&gt;
&lt;P&gt;% Abuse contact for '198.163.193.0 - 198.163.193.255' is 'email@bkm.uz'&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also note the sender is using a spoofed, possibly valid, Plusnet email address.&amp;nbsp;&lt;/SPAN&gt;It seems impractical for a mailer to block every single IP address spam has ever been sent from - even if practicable it could end up with very many individuals unable to send out any emails! This is surely done on a domain basis. Which brings us back to the topic of people on Plusnet accounts unable to send messages to other people.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Received: from [198.163.193.190] (unknown [198.163.193.190])&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;by mail.enmail.co (Postfix) with ESMTP id DC570C0049&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;for &amp;lt;user@lastname.plus.com&amp;gt;; Sun, 3 May 2026 07:51:17 +0000 (UTC)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Authentication-Results: mail.enmail.co;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dkim=none;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;spf=softfail (mail.enmail.co: 198.163.193.190 is neither permitted nor denied by domain of user@lastname.plus.com) smtp.mailfrom=user@lastname.plus.com;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dmarc=fail reason="No valid SPF, No valid DKIM" header.from=plus.com (policy=none)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Received: from wurggqe ([60.220.73.164]) by 15751.com with MailEnable ESMTP; Sun, 3 May 2026 12:51:27 +0500&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Received: (qmail 54451 invoked by uid 544); 3 May 2026 12:51:25 +0500&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;From: user@lastname.plus.com&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;To: user@lastname.plus.com&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I assume it is being correctly identified as "Spam" by the Greenby system?&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 08:25:47 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045092#M60572</guid>
      <dc:creator>pvmb</dc:creator>
      <dc:date>2026-05-05T08:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045110#M60577</link>
      <description>&lt;P&gt;If you do a DNS blacklist check against the mailserver IP you will see it is listed in the XBL and CSS blacklist as well assome other lists as a server distributing SPAM and exploits.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Checking: 198.163.193.190 []&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.11 (PBL (Policy Block List))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.4 (XBL (Exploits Block List))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.3 (CSS (Spamhaus CSS))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[OK] 198.163.193.190 not listed on bl.spamcop.net&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[OK] 198.163.193.190 not listed on b.barracudacentral.org&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[OK] 198.163.193.190 not listed on dnsbl.sorbs.net&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[LISTED] 198.163.193.190 on cbl.abuseat.org → 127.0.0.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[OK] 198.163.193.190 not listed on psbl.surriel.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[LISTED] 198.163.193.190 on dnsbl-1.uceprotect.net → 127.0.0.2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Most ISPs rely on such blacklist to stop the distribution of SPAM. enmail.co i.e. Greenby does not.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Markus&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 11:27:07 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045110#M60577</guid>
      <dc:creator>M-M</dc:creator>
      <dc:date>2026-05-05T11:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045118#M60578</link>
      <description>&lt;P&gt;Images awaiting approval for this thread disclose personal information (email addresses).&amp;nbsp; Personally I am not inclined to release them - one for &lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/142611"&gt;@James_B&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 13:06:14 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045118#M60578</guid>
      <dc:creator>Townman</dc:creator>
      <dc:date>2026-05-05T13:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Spam tsunami</title>
      <link>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045124#M60580</link>
      <description>&lt;P&gt;That's absolutely the right thing to do,&amp;nbsp;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/5145"&gt;@Townman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please remember not to share personal information in this public forum folks.&lt;/P&gt;
&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 14:28:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Email/Spam-tsunami/m-p/2045124#M60580</guid>
      <dc:creator>James_B</dc:creator>
      <dc:date>2026-05-05T14:28:16Z</dc:date>
    </item>
  </channel>
</rss>

