cancel
Showing results for 
Search instead for 
Did you mean: 

Spam tsunami

pvmb
All Star
Posts: 1,476
Thanks: 287
Fixes: 12
Registered: ‎12-02-2014

Re: Spam tsunami


@M-M wrote:

Yes and enmail.co should have blocked it as a it comes from a blacklisted mailserver instead it forwards to plusnet.  Plusnet should blacklist enmail.co servers, which I did i.e. reported to spamhaus. 


But who says it is coming from a blacklisted "mailserver"? It's apparently coming from an IP address, in a domain belonging to Uzbektelecom. It is for them to deal with spammers originating within their control. You could try contacting them directly.

% Abuse contact for '198.163.193.0 - 198.163.193.255' is 'email@bkm.uz'

Also note the sender is using a spoofed, possibly valid, Plusnet email address. It seems impractical for a mailer to block every single IP address spam has ever been sent from - even if practicable it could end up with very many individuals unable to send out any emails! This is surely done on a domain basis. Which brings us back to the topic of people on Plusnet accounts unable to send messages to other people.

Received: from [198.163.193.190] (unknown [198.163.193.190])
by mail.enmail.co (Postfix) with ESMTP id DC570C0049
for <user@lastname.plus.com>; Sun, 3 May 2026 07:51:17 +0000 (UTC)
Authentication-Results: mail.enmail.co;
dkim=none;
spf=softfail (mail.enmail.co: 198.163.193.190 is neither permitted nor denied by domain of user@lastname.plus.com) smtp.mailfrom=user@lastname.plus.com;
dmarc=fail reason="No valid SPF, No valid DKIM" header.from=plus.com (policy=none)
Received: from wurggqe ([60.220.73.164]) by 15751.com with MailEnable ESMTP; Sun, 3 May 2026 12:51:27 +0500
Received: (qmail 54451 invoked by uid 544); 3 May 2026 12:51:25 +0500
From: user@lastname.plus.com
To: user@lastname.plus.com

I assume it is being correctly identified as "Spam" by the Greenby system?

M-M
Grafter
Posts: 29
Registered: ‎07-05-2022

Re: Spam tsunami

If you do a DNS blacklist check against the mailserver IP you will see it is listed in the XBL and CSS blacklist as well assome other lists as a server distributing SPAM and exploits.   

 

Checking: 198.163.193.190 []
-------------------------
[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.11 (PBL (Policy Block List))
[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.4 (XBL (Exploits Block List))
[LISTED] 198.163.193.190 on zen.spamhaus.org → 127.0.0.3 (CSS (Spamhaus CSS))
[OK] 198.163.193.190 not listed on bl.spamcop.net
[OK] 198.163.193.190 not listed on b.barracudacentral.org
[OK] 198.163.193.190 not listed on dnsbl.sorbs.net
[LISTED] 198.163.193.190 on cbl.abuseat.org → 127.0.0.2
[OK] 198.163.193.190 not listed on psbl.surriel.com
[LISTED] 198.163.193.190 on dnsbl-1.uceprotect.net → 127.0.0.2

 

Most ISPs rely on such blacklist to stop the distribution of SPAM. enmail.co i.e. Greenby does not.

 

Markus

Townman
Superuser
Superuser
Posts: 28,745
Thanks: 12,949
Fixes: 241
Registered: ‎22-08-2007

Re: Spam tsunami

Images awaiting approval for this thread disclose personal information (email addresses).  Personally I am not inclined to release them - one for @James_B 

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

James_B
Community Gaffer
Community Gaffer
Posts: 541
Thanks: 1,056
Fixes: 14
Registered: ‎10-09-2024

Re: Spam tsunami

That's absolutely the right thing to do, @Townman 

Please remember not to share personal information in this public forum folks.

James

john_chandler
Rising Star
Posts: 55
Thanks: 23
Fixes: 1
Registered: ‎09-06-2020

Re: Spam tsunami

I've started getting the exact same spam message as of today - deleted 12 so far this morning, but they keep coming in.

M-M
Grafter
Posts: 29
Registered: ‎07-05-2022

Re: Spam tsunami

As "proof" other ISPs, mail service providers like hotmail block e.g. Plusnet when on block list ( see other forum posts). 

 

Diagnostic-Code: smtp; 550 5.7.1 Unfortunately, messages from [84.93.230.227] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3150)

Diagnostic-Code: smtp; 550 5.7.1 Unfortunately, messages from [212.159.14.20] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3150)

 

Greenby/Plusnet should do the same for the Spammers open mail gateway

Markus

pvmb
All Star
Posts: 1,476
Thanks: 287
Fixes: 12
Registered: ‎12-02-2014

Re: Spam tsunami

"As "proof" other ISPs, mail service providers like hotmail block e.g. Plusnet when on block list ( see other forum posts). "

I suspect you may be confusing two different things here. I have seen no convincing evidence to date that Plusnet is on any spam "block list". However, issues with sending emails to particular destinations, e.g. Gmail recipients, are to do with Plusnet originated emails coming from sources that do not conform with up to date DNS email domain settings for SMTP messages.

That's what many of those Diagnostic Codes usually mean - they are suspect as possible 'unwanted mail' or 'possible spam'.

"The error code 550 5.7.1 indicates that your email was rejected due to security or policy-related issues, often because the recipient's server considers it spam or lacks proper authentication."

Incoming spam is another matter. For instance, I don't get any - despite having a Plusnet email address now transferred to Greenby. According to some here I should be knee deep in spam. Why aren't I?

OriginalBigBri
Dabbler
Posts: 23
Thanks: 14
Registered: ‎10-10-2018

Re: Spam tsunami


@M-M wrote:

Yes and enmail.co should have blocked it as a it comes from a blacklisted mailserver instead it forwards to plusnet.  Plusnet should blacklist enmail.co servers, which I did i.e. reported to spamhaus. 





Can I ask, what is "enmail.co" ?? I'm having massive problems with email at the moment.
I have a personal email address with Plusnet since forever, and I have a number of domains hosted by Enix.

When I try and send an email to an address or mailing list on one of those domains, I am getting a rejection (presumably from the Enix server), saying "junk mail rejected". In the header info that is attached, it has this:

Reporting-MTA: dns; avasout-ptp-002 [84.93.230.235]
Received-From-MTA: dns; mail.enmail.co [91.204.208.8]

I have absolutely no idea what this means. I understand Plusnet are trying to get out of hosting email - has it already moved to someone else? I'm sending through relay.free-online.net

I am worried I may have lost a job I was offered due to them not receiving my email. Is it just Enix blocking one of the servers? I checked and neither appears to be blacklisted, but I have no idea what "enmail" is.

Seriously confused.
TIA

MisterW
Superuser
Superuser
Posts: 19,585
Thanks: 8,640
Fixes: 562
Registered: ‎30-07-2007

Re: Spam tsunami

Can I ask, what is "enmail.co" ?? I

As part of the email migration plan to Greenby, connections to the mail server are routed via a 'proxy'. This has knowledge of whether an account has migrated or not and either routes the connection to the Greenby server or the Plusnet server.

I believe mail.enmail.co is the Greenby mail server

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

M-M
Grafter
Posts: 29
Registered: ‎07-05-2022

Re: Spam tsunami

Now Plusnet blocks my email because someone is using my address.

 

The message could not be sent because the server rejected the sender's email address. The sender's email address was 'UU@XX.plus.com'.

Subject 'SUBJECT'
Server Error: 550
Server Response: 550 <UU@XX.plus.com> sender rejected (blacklisted by local policy)
Server: 'relay.plus.net'
Windows Live Mail Error ID: 0x800CCC78
Protocol: SMTP
Port: 465
Secure(SSL): Yes

 

What a terrible email management.

 

PhilipHeyes
Seasoned Pro
Posts: 716
Thanks: 249
Fixes: 8
Registered: ‎10-11-2021

Re: Spam tsunami

@M-M 

Try replacing Plusnet hosted SMTP relay.plus.net with Greenby hosted SMTP mail.enmail.co

Note Greenby mail servers require the Username to be the email address of the mailbox, not <account>+<name> or an alias.


M-M
Grafter
Posts: 29
Registered: ‎07-05-2022

Re: Spam tsunami

I am not with Greenby. Still waiting to be moved.

 

 

PhilipHeyes
Seasoned Pro
Posts: 716
Thanks: 249
Fixes: 8
Registered: ‎10-11-2021

Re: Spam tsunami

Check that by trying to login in at : https://greenby.com/
using the same credentials as are used for the Plusnet Members Centre

M-M
Grafter
Posts: 29
Registered: ‎07-05-2022

Re: Spam tsunami

I tried and it did not work. I also was not informed about a move. 

 

I get a lot of Spam with my account as the source like below which plusnet does not stop instead they stop me sending !   

I can't even send to their abuse account.

Service abuse | Help | Plusnet

To report a service abuse please email abuse@plus.net or contact our Support Team on 0330 1239 123.

We provide a safe and confidential method of reporting cases of abuse or potential vulnerability. Your report will be treated in the strictest confidence.

Please provide all information you report as clearly and concisely as possible, including appropriate URLs, firewall logs etc. This will help us complete our investigations much more quickly. We've also set out below some guidance on reporting certain types of service abuse.

Reporting email abuse and spamming

In order to investigate your report we must have the full headers of the spam email. Please send header information as plain text, in the body of your email, rather than as an attachment.

 

 

Return-path: <support@sportskeeda.com>
Envelope-to: UU@.plus.com
Delivery-date: Sun, 21 Jun 2026 19:45:23 +0100
Received: from [212.159.14.26] (helo=avasin-peh-006.plus.net)
by inmx-peh-001.plus.net with esmtp (PlusNet MXCore v2.00) id 1wbNAZ-000D6r-8z
for UU@XX.plus.com; Sun, 21 Jun 2026 19:45:23 +0100
Received: from mail.enmail.co ([91.204.208.8])
by Plusnet Cloudmark Gateway with ESMTP
id bNAZwBVoukqKsbNAZwsdtK; Sun, 21 Jun 2026 19:45:23 +0100
X-CM-Score: 100.00
X-CNFS-Analysis: v=2.4 cv=dcYj3mXe c=1 sm=1 tr=0 ts=6a383143
p=Ai7aDr63XA+LPeg5SyAl1A==:17 p=knHQbh3NTOg9A18OEVkA:9 p=Ng5CTUEjfFTb1yrw:21
p=DhJL1ryLo7EA:10 p=EbnfwBxM2C8A:10 p=BSNHCxRGnyVBECesg9U5:22
p=yYySuD-ScO7z7Sbk8gKz:22 a=/50HAxhVri9f9h8qkinWjQ==:117
a=/3+QBnMdMWoJIr/7ohBTCr1PyQg=:19 a=IkcTkHD0fZMA:10 a=FelO9ux0wxsA:10
a=g8TUdU_LZmEA:10 a=3g80flMcAAAA:8 a=SSmOFEACAAAA:8
a=BhMdqm2Wqc4Q2JL7t0yJfBCtM/Y=:19 a=_W_S_7VecoQA:10 a=3ZKOabzyN94A:10
a=QEXdDO2ut3YA:10 a=O23WzTs1fjcA:10 a=ouV8bqFNGZoA:10
a=LZtFMuD1p091OJ1dpCy4:22 a=3urWGuTZa-U-TZ_dHwj2:22 a=NWVoK91CQySWRX1oVYDe:22
a=lAIPu-TSoPCgWs-2gwLQ:22
Received: from sportskeeda.com (163.239.229.8.bc.googleusercontent.com [8.229.239.163])
by mail.enmail.co (Postfix) with SMTP id A7F23C0064
for <UU@XX.plus.com>; Sun, 21 Jun 2026 18:45:22 +0000 (UTC)
Authentication-Results: mail.enmail.co;
dkim=none;
dmarc=fail reason="No valid SPF, No valid DKIM" header.from=sportskeeda.com (policy=none);
spf=softfail (mail.enmail.co: 8.229.239.163 is neither permitted nor denied by domain of support@sportskeeda.com) smtp.mailfrom=support@sportskeeda.com
From: Cloud Storage <support@sportskeeda.com>
To: UU@XX.plus.com
Message-ID: <36438e2988be49ae948c5f92f1260b09@sportskeeda.com>
Date: Sun, 21 Jun 2026 18:45:21 +0000
MIME-Version: 1.0
Content-Type: text/html; charset=utf-8
X-Spamd-Result: default: False [14.41 / 4.00];
PHISHED_PHISHTANK(7.00)[hpq http://www.phishtank.com/phish_detail.php?phish_id=9458806];
VIOLATED_DIRECT_SPF(3.50)[];
BAYES_SPAM(2.46)[91.29%];
R_BAD_CTE_7BIT(1.05)[unknown,utf8];
MIME_HTML_ONLY(0.20)[];
DMARC_POLICY_SOFTFAIL(0.10)[sportskeeda.com : No valid SPF, No valid DKIM,none];
ONCE_RECEIVED(0.10)[];
R_SPF_SOFTFAIL(0.00)[~all];
ASN(0.00)[asn:396982, ipnet:8.229.0.0/16, country:US];
MIME_TRACE(0.00)[0:~];
FROM_EQ_ENVFROM(0.00)[];
MISSING_XM_UA(0.00)[];
ARC_NA(0.00)[];
TO_MATCH_ENVRCPT_ALL(0.00)[];
RCPT_COUNT_ONE(0.00)[1];
NEURAL_SPAM(0.00)[0.708];
R_DKIM_NA(0.00)[];
FUZZY_RATELIMITED(0.00)[rspamd.com];
MID_RHS_MATCH_FROM(0.00)[];
TO_DN_NONE(0.00)[];
RCVD_COUNT_ZERO(0.00)[0];
FROM_HAS_DN(0.00)[]
X-Spam: Yes
X-Original-Recipient: UU@XX.plus.com
X-CMAE-Envelope: MS4xfMA9yhQvw0wP2sXA2IzZrwMBlrNY269P/m+wuh5MrfrR1SlDk/e9RXbNrXYLk9Zc6XWLnA3qRYze9t6tLxYvdAygDkSDthA1RyeM864z6nF59fap6EsQ
7tQ6bHScYKRzQiB98DOmHZecD37yf4rhQvpDVkS3Tzi7PXC96JsMTYXgw/fjRgPkr1zu7THH82AqYzIsyaTe/OeUBC65lwEOQbk=
X-pn-pstn-db:" Spam 99
X-PN-Spam-Filtered: by PlusNet MXCore (v5.00)
Subject: Upgrade available: Increase your capacity
X-Antivirus: Norton (VPS 260620-4, 20/6/2026), Inbound message
X-Antivirus-Status: Clean

 

 

pvmb
All Star
Posts: 1,476
Thanks: 287
Fixes: 12
Registered: ‎12-02-2014

Re: Spam tsunami

"I get a lot of Spam with my account as the source like below which plusnet does not stop instead they stop me sending !

I can't even send to their abuse account."

So, to sum up...

You've published your email address on this public forum (on how many others?)
You've been complaining about receiving email spam
You've been complaining about Greenby not stopping spam (despite seemingly not having a Greenby account)
Now 'they' are stopping spam (from your email address) you are complaining 'they' are stopping your emails, from your spam generated email address