cancel
Showing results for 
Search instead for 
Did you mean: 

Anti-Spam Broke?

David_W
Rising Star
Posts: 2,305
Thanks: 33
Registered: ‎19-07-2007

Re: Anti-Spam Broke?

It's more spam, phishing emails are identified and classed as viruses for some reason, I won't ask for them to be taken out of quarantine but they seem generic PayPal phising emails from the title.
spraxyt
Resting Legend
Posts: 10,063
Thanks: 674
Fixes: 75
Registered: ‎06-04-2007

Re: Anti-Spam Broke?

They might be phishing emails but probably have a virus payload attached with the aim of compromising your PC if it gets that far. Definitely messages to stay clear of.
David
Oldjim
Resting Legend
Posts: 38,460
Thanks: 787
Fixes: 63
Registered: ‎15-06-2007

Re: Anti-Spam Broke?

Another one and given the details I wonder why it hasn't been picked up
Quote
Return-path: <ylowvtcruzer@yahoo.com>
Envelope-to: me@username.plus.com
Delivery-date: Wed, 02 Mar 2011 01:19:32 +0000
Received: from [212.159.7.33] (helo=mx.ptn-ipin01.plus.net)
  by inmx12.plus.net with esmtp (PlusNet MXCore v2.00) id 1Puaiy-0003H4-28
  for me@username.plus.com; Wed, 02 Mar 2011 01:19:32 +0000
Received-SPF: None identity=pra; client-ip=89.200.172.58;
  receiver=mx.ptn-ipin01.plus.net;
  envelope-from="ylowvtcruzer@yahoo.com";
  x-sender="";
  x-conformance=sidf_compatible
Received-SPF: None identity=mailfrom; client-ip=89.200.172.58;
  receiver=mx.ptn-ipin01.plus.net;
  envelope-from="ylowvtcruzer@yahoo.com";
  x-sender="ylowvtcruzer@yahoo.com";
  x-conformance=sidf_compatible
Received-SPF: None identity=helo; client-ip=89.200.172.58;
  receiver=mx.ptn-ipin01.plus.net;
  envelope-from="ylowvtcruzer@yahoo.com";
  x-sender="postmaster@server23";
  x-conformance=sidf_compatible
X-SBRS: -2.1
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AmI5AFIqbU1ZyKw6T2dsb2JhbAA4giaBSoJrkSgBhluGXgUEYQEBFQwHBxQgBK0rkHGBJ4NEdgQ
X-IronPort-AV: E=McAfee;i="5400,1158,6272"; a="451448486"
X-IronPort-AV: E=Sophos;i="4.62,250,1297036800";
  d="scan'208";a="451448486"
Received: from server23.campusspeicher.de (HELO server23) ([89.200.172.58])
  by mx.ptn-ipin01.plus.net with SMTP; 02 Mar 2011 01:19:22 +0000
Received: (from apache@localhost)
by registration.acronis.com (8.13.1/8.13.1/Submit) id n63Bux5n019850;
Fri, 3 Jul 2010 07:56:59 -0400
Message-Id: <201007032256.n63BuT5n019850@registration.acronis.com>
Date: Fri, 3 Jul 2009 07:56:59 -0400
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
To:
X-PN-Virus-Filtered: by PlusNet MXCore (v5.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v5.00)
Subject:
X-SpamFlt-Status: Spam
X-KASFlt-Status: Profiles 19650 [Mar 02 2011]
X-KASFlt-Status: Version: 4.4.2 (May 26 2010 17:02:10)
X-KASFlt-Status: Envelope from:
X-KASFlt-Status: {TO: header missing}
X-KASFlt-Status: {FROM: missing}
X-KASFlt-Status: Rate: 100
X-KASFlt-Status: Status: spam
X-KASFlt-Status: Method: headers
ChrisL
Rising Star
Posts: 760
Thanks: 4
Fixes: 1
Registered: ‎13-12-2007

Re: Anti-Spam Broke?

Jim, is it your Kaspersky spam solution that is adding the last of those headers?  I seem to remember a problem from some time back where the presence of a Kaspersky filter may have been confusing the Ironports.....  I'll try and find it.
Best wishes
Chris
edit:  may be relevant?  http://community.plus.net/forum/index.php/topic,87511.0.html
          or even this? http://community.plus.net/forum/index.php/topic,86703.0.html
Oldjim
Resting Legend
Posts: 38,460
Thanks: 787
Fixes: 63
Registered: ‎15-06-2007

Re: Anti-Spam Broke?

It is adding them but that is after I receive it so it shouldn't muddle Ironport
bobpullen
Community Gaffer
Community Gaffer
Posts: 16,889
Thanks: 4,983
Fixes: 316
Registered: ‎04-04-2007

Re: Anti-Spam Broke?

With IronPort being largely proprietary, I'm not sure there's a great deal we can do to at our side to ensure those emails are caught Jim.

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

David_W
Rising Star
Posts: 2,305
Thanks: 33
Registered: ‎19-07-2007

Re: Anti-Spam Broke?

I use Kaspersky too and am not seeing those headers in my emails, spam or not.  I guess the best way to check is to use webmail and look at the headers there before collection?
ChrisL
Rising Star
Posts: 760
Thanks: 4
Fixes: 1
Registered: ‎13-12-2007

Re: Anti-Spam Broke?

Quote from: Oldjim
It is adding them but that is after I receive it so it shouldn't muddle Ironport

I take your point, Jim.  But it's just possible that something is stripping headers after arrival, as here:
http://community.plus.net/forum/index.php/topic,87511.msg726802.html#msg726802
How have you got MMM set to dispose of spam? Ie. what would you expect to have happened to the email if it had been correctly identified as spam?
Chris
Oldjim
Resting Legend
Posts: 38,460
Thanks: 787
Fixes: 63
Registered: ‎15-06-2007

Re: Anti-Spam Broke?

Spam goes to the spam folder on webmail
Just found one in the Spam folder
Quote
Return-path: <yearofthetrill@masterdomainbrokers.com>
Envelope-to: me@username.plus.com
Delivery-date: Wed, 16 Feb 2011 04:28:21 +0000
Received: from [212.159.7.102] (helo=mx.pcl-ipin03.plus.net)
    by inmx06.plus.net with esmtp (PlusNet MXCore v2.00) id 1PpZ00-0005MC-TR
    for me@username.plus.com; Wed, 16 Feb 2011 04:28:20 +0000
Received-SPF: None identity=pra; client-ip=89.200.172.58;
    receiver=mx.pcl-ipin03.plus.net;
    envelope-from="yearofthetrill@masterdomainbrokers.com";
    x-sender="";
    x-conformance=sidf_compatible
Received-SPF: Neutral identity=mailfrom; client-ip=89.200.172.58;
    receiver=mx.pcl-ipin03.plus.net;
    envelope-from="yearofthetrill@masterdomainbrokers.com";
    x-sender="yearofthetrill@masterdomainbrokers.com";
    x-conformance=sidf_compatible;
    x-record-type="v=spf2.0"
Received-SPF: None identity=helo; client-ip=89.200.172.58;
    receiver=mx.pcl-ipin03.plus.net;
    envelope-from="yearofthetrill@masterdomainbrokers.com";
    x-sender="postmaster@server23";
    x-conformance=sidf_compatible
X-SBRS: 0.0
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AnXwAFrhWk1ZyKw6ZGdsb2JhbAA3gU5VgUOCa5A8AYZahlwFBGYaExYoHQEBE6w0kG6BJ4NBdgQ
X-IPAS: BSBLevel1
X-IronPort-AV: E=McAfee;i="5400,1158,6258"; a="479342470"
X-IronPort-AV: E=Sophos;i="4.60,478,1291593600";
    d="scan'208";a="479342470"
Received: from server23.campusspeicher.de (HELO server23) ([89.200.172.58])
    by mx.pcl-ipin03.plus.net with SMTP; 16 Feb 2011 04:28:20 +0000
Received: (from apache@localhost)
    by registration.acronis.com (8.13.1/8.13.1/Submit) id n63Bux5n019850;
    Fri, 3 Jul 2010 07:56:59 -0400
Message-Id: <201007032256.n63BuT5n019850@registration.acronis.com>
Date: Fri, 3 Jul 2009 07:56:59 -0400
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
To:
X-pn-pstn: Spam 1
X-PN-Virus-Filtered: by PlusNet MXCore (v5.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v5.00)
Subject: [-SPAM-]
Looks as though Ironport is now picking them up.
Note the Acronis part is still there
zubel
Community Veteran
Posts: 3,793
Thanks: 4
Registered: ‎08-06-2007

Re: Anti-Spam Broke?

These mails are being sent from a compromised web form on the Acronis server, which is giving the mails a small air of legitimacy when it comes to spam filtering.
B.
spraxyt
Resting Legend
Posts: 10,063
Thanks: 674
Fixes: 75
Registered: ‎06-04-2007

Re: Anti-Spam Broke?

That particular server now has a senderbase reputation of "poor" whereas previously I think it was "neutral" like the others in the family. That does suggest SenderBase has reacted to spam reports.
David