cancel
Showing results for 
Search instead for 
Did you mean: 

Spam

jab1
Legend
Posts: 17,095
Thanks: 5,482
Fixes: 255
Registered: ‎24-02-2012

Re: Spam

@ginnym They (spammers) are obviously upping their game by attempting to send virus, but the PN filters are usually good at catching those.

John
Richard-261
Grafter
Posts: 34
Thanks: 4
Registered: ‎03-01-2017

Re: Spam

A side issue is that I'm now getting swamped with "Alert: An email addressed to you has been quarantined" messages.

I assume these are genuine and generated by PN as a response to spam, but these messages take just as long to remove from the inbox as the spam ones.

Is there a way of switching off this alert please?

Richard

2 strokes good - 4 strokes bad : George Orwell.
ginnym
Grafter
Posts: 42
Thanks: 7
Registered: ‎13-04-2008

Re: Spam

I'm getting a lot of these now too - the spam has reduced but the warning emails have increased.
GioC
Grafter
Posts: 29
Thanks: 3
Registered: ‎14-09-2017

Re: Spam

Things do seem to have changed on their system. I too am not getting all those delivery failures but just a few email quarantined. I could do with those falling into the "black hole" as the address is correct after the @ sign, but just random names before it.

On the positive side, at least it is an improvement.

Cerberos
Rising Star
Posts: 62
Thanks: 20
Registered: ‎16-10-2007

Re: Spam

I am getting 50 to 100 a day from email alert service "An Email addressed to you has been Quarantined". Obviously the plusnet antivirus scanners are picking them up but my domain is still being bombarded. All sent to random-person@mydomain.co.uk. I am going to turn my catch-all off for a few days and hope by that time the email storm will have passed. I will switch it on again in a few days.

spraxyt
Resting Legend
Posts: 10,063
Thanks: 674
Fixes: 75
Registered: ‎06-04-2007

Re: Spam


@Richard-261 wrote:

A side issue is that I'm now getting swamped with "Alert: An email addressed to you has been quarantined" messages.

I assume these are genuine and generated by PN as a response to spam, but these messages take just as long to remove from the inbox as the spam ones.

Is there a way of switching off this alert please?


@Richard-261The only setting in the spam management panel available to us is to switch virus checking on or off and we wouldn't want the latter.

Whilst the system is clearly coping with the virus onslaught I expect the secondary effect from a deluge of alerts was not expected. Sad

David
GioC
Grafter
Posts: 29
Thanks: 3
Registered: ‎14-09-2017

Re: Spam

Looking at just this section of problems alone, it does seem like PlusNet require one or more options for emails (extra filter options), server based but controlled at a user level. It would be good if there was a text filter for us. I know the logistics of implementing such a thing but by god, it would so cut down support calls within this area (and save them money also 😉 )

 

At one point I was getting so many "Mail Delivery Failures", I was tempted to set up a on plusnet total mail redirect to my gmail account and let that filter out all the delivery failures and forward the rest back. A bit crazy I know but it would eliminate all those report failures.

If it keeps happening and they don't get it sorted, it could be a temp option/workaround

Gandalf
Community Gaffer
Community Gaffer
Posts: 26,574
Thanks: 10,294
Fixes: 1,600
Registered: ‎21-04-2017

Re: Spam

Hi guys

 

I am sorry to hear you're getting a lot of mail classified as spam

 

For those of you that are seeing these messages where the spam filter isn't picking them up, if you could PM @Chris with a couple of examples of the full headers please, it'll really help us to investigate further 

 
Thanks

From 31st October 2022, I no longer have a regular presence here as I’ve moved on to a new role.
Anoush Mortazavi
Plusnet
Richard-261
Grafter
Posts: 34
Thanks: 4
Registered: ‎03-01-2017

Re: Spam

Thanks David

And thanks GioC.

I should've thought of filtering mail with Thunderbird. I can send all the alerts straight to the bin.

Excellent!

 

2 strokes good - 4 strokes bad : George Orwell.
Discobolus
Dabbler
Posts: 11
Thanks: 1
Registered: ‎29-11-2013

Re: Spam

I have had a sudden surge of spam over the past two weeks when previously I have had none. I turned up the filter to 5, but it is still coming. I use my own domain name and Fasthosts forward the mail to my Plusnet address.

I have pasted the headers from two spam e-mails below after removing my own e-mail address to give you examples

Return-path: <srs0=r+8i=dc=prophet.alaetz.club=clone.nintendo.system@clustered-mail-forwarding-02.uk>
Envelope-to: MY EMAIL ADDRESS deleted
Delivery-date: Wed, 06 Dec 2017 11:28:35 +0000
Received: from [212.159.9.108] (helo=avasin04.plus.net)
      by inmx02.plus.net with esmtp (PlusNet MXCore v2.00) id 1eMXsR-0007Jg-FU
      for MY EMAIL ADDRESS deleted; Wed, 06 Dec 2017 11:28:35 +0000
Received: from forwarder.cmp.livemail.co.uk ([213.171.216.220])
    by Plusnet Cloudmark Gateway with ESMTP
    id MXsPeBm7sLsm3MXsReWx8M; Wed, 06 Dec 2017 11:28:35 +0000
X-CM-Score: 0.00
X-CNFS-Analysis: v=2.2 cv=QcQWhoTv c=1 sm=1 tr=0
 a=Uch8kxAQ0sextObN6lOAWw==:117 a=Rs7mNeL+eotrQ637DzaAiQ==:17
 a=IkcTkHD0fZMA:10 a=MKtGQD3n3ToA:10 a=1oJP67jkp3AA:10 a=ocR9PWop10UA:10
 a=fTd48MM7V3EA:10 a=ZZnuYtJkoWoA:10 a=xgJSL0JuAAAA:8 a=eHSPOuGhwZ35qhWMP84A:9
 a=n_oPYQJBPd5N-8fB:21 a=_W_S_7VecoQA:10 a=QEXdDO2ut3YA:10 a=-FEs8UIgK8oA:10
 a=NWVoK91CQyQA:10 a=R2gxJEnYVCpGOJqfUaG9:22
Received: from localhost (unknown [127.0.0.1])
    by forwarder.cmp.livemail.co.uk (Postfix) with ESMTP id 5208A320549
    for <MY EMAIL ADDRESS deleted>; Wed,  6 Dec 2017 11:28:33 +0000 (UTC)
X-Virus-Scanned: amavisd-new at smtp-forwarder-out-07.cmp.livemail.co.uk
X-Spam-Flag: NO
X-Spam-Score: 2.64
X-Spam-Level: **
X-Spam-Status: No, score=2.64 tagged_above=2 required=6.3
    tests=[HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001,
    MIME_HTML_ONLY=1.105, RDNS_NONE=1.274, SPF_HELO_PASS=-0.001,
    SURBL_BLOCKED=0.001, T_REMOTE_IMAGE=0.01, URIBL_BLOCKED=0.001]
    autolearn=disabled
Received: from forwarder.cmp.livemail.co.uk ([127.0.0.1])
    by localhost (smtp-forwarder-out-07.cmp.livemail.co.uk [127.0.0.1]) (amavisd-new, port 10024)
    with ESMTP id QBIaKW-X7W3w for <MY EMAIL ADDRESS deleted>;
    Wed,  6 Dec 2017 11:28:32 +0000 (GMT)
Received: from mailserver.cmp.livemail.co.uk (unknown [10.44.166.78])
    by forwarder.cmp.livemail.co.uk (Postfix) with ESMTPS id 7E65232097F
    for <MY EMAIL ADDRESS deleted>; Wed,  6 Dec 2017 11:28:32 +0000 (GMT)
Received: from prophet.alaetz.club (unknown [192.151.155.139])
    by mailserver.cmp.livemail.co.uk (Postfix) with ESMTP id 4CBC81042DE
    for <MY EMAIL ADDRESS deleted>; Wed,  6 Dec 2017 11:28:32 +0000 (GMT)
Date: Wed, 06 Dec 2017 04:29:41 -0700
Content-Type: text/html; charset="utf-8"
From: Vintage NES Games <clone.nintendo.system@prophet.alaetz.club>
Message-ID: <953d79ed3736b225eb317d9e35d94b23.Pocket.Exequatur@prophet.alaetz.club>
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
Nacho: 1830572-953d79ed3736b225eb317d9e35d94b23_5510828
To: <jMY EMAIL ADDRESS deleted>
X-CMAE-Envelope: MS4wfBuOsYQag8V5h5bSrQwhwh44gBB5DGqYWhfGnxdVfYvwBesdiqqlW4U/4CjBpCtZ1mgpU7Q473TjezRtgOhuRt9nQi198ee96qc9Xu0hY4eMz/ZYoqhr
 9S6WEiz8hlCGqb3u5BVTmkV5FST8UL3TsnUr3d1iDPiFfuAtN1Sill5Py0MEaNPIhiR2XF8DWWW5jmRzN2lPqEfGQpe3hBm0x/unzZa1U+jv/HPyw9AmlUfZ
 aBas+d4nErmhgHdzuAOVbMjBlIjXJubgQEnVjVUEni/TS2J1A3UaDmFOj6Jc47hD4nYwrs+HxvAg3WbHh/nttA==
X-PN-Virus-Filtered: by PlusNet MXCore (v5.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v5.00)
Subject: A Massive 500+ classic Nintendo games in a tiny retro console. Holiday Special

and another

Return-path: <srs0=5xcm=dd=resort.herelendinghand.club=lending.hand@clustered-mail-forwarding-02.uk>
Envelope-to: MY EMAIL ADDRESS deleted
Delivery-date: Thu, 07 Dec 2017 12:59:40 +0000
Received: from [212.159.8.109] (helo=avasin03.plus.net)
      by inmx17.plus.net with esmtp (PlusNet MXCore v2.00) id 1eMvm8-0002Zm-7r
      forMY EMAIL ADDRESS deleted; Thu, 07 Dec 2017 12:59:40 +0000
Received: from forwarder.cmp.livemail.co.uk ([213.171.216.220])
    by Plusnet Cloudmark Gateway with ESMTP
    id Mvm6ec0vMXNJNMvm8eNeJp; Thu, 07 Dec 2017 12:59:40 +0000
X-CM-Score: 0.00
X-CNFS-Analysis: v=2.2 cv=MM0QoIRl c=1 sm=1 tr=0
 a=Uch8kxAQ0sextObN6lOAWw==:117 a=TvAs8LBdiC1B8hbMh7C4rw==:17
 a=MKtGQD3n3ToA:10 a=1oJP67jkp3AA:10 a=ocR9PWop10UA:10 a=WwkMzZUXoAwA:10
 a=ZZnuYtJkoWoA:10 a=2RRglgtaAAAA:8 a=ZOG0yTfcAAAA:8 a=ot9asK4bzzMEmWwf5pwA:9
 a=-FEs8UIgK8oA:10 a=NWVoK91CQyQA:10 a=8flksMUux6I4HTtoAeat:22
 a=AxibtoJLmgwR-4DOBML8:22
Received: from localhost (unknown [127.0.0.1])
    by forwarder.cmp.livemail.co.uk (Postfix) with ESMTP id 06F2C602FB
    for <MY EMAIL ADDRESS deleted>; Thu,  7 Dec 2017 12:59:38 +0000 (UTC)
X-Virus-Scanned: amavisd-new at smtp-forwarder-out-02.cmp.livemail.co.uk
Received: from forwarder.cmp.livemail.co.uk ([127.0.0.1])
    by localhost (smtp-forwarder-out-02.cmp.livemail.co.uk [127.0.0.1]) (amavisd-new, port 10024)
    with ESMTP id 9j3HqSP6T2dP for <MY EMAIL ADDRESS deleted>;
    Thu,  7 Dec 2017 12:59:37 +0000 (GMT)
Received: from mailserver.cmp.livemail.co.uk (unknown [10.44.166.71])
    by forwarder.cmp.livemail.co.uk (Postfix) with ESMTPS id 5A0A5600D8
    for <MY EMAIL ADDRESS deleted>; Thu,  7 Dec 2017 12:59:37 +0000 (GMT)
Received: from resort.herelendinghand.club (unknown [162.251.165.149])
    by mailserver.cmp.livemail.co.uk (Postfix) with ESMTP id 11E2040D5D
    for <MY EMAIL ADDRESS deleted>; Thu,  7 Dec 2017 12:59:37 +0000 (GMT)
Date: Thu, 07 Dec 2017 05:50:12 -0700
Content-Type: text/plain
From: Lending Hand <Lending.Hand@resort.herelendinghand.club>
Message-ID: <299507517067283-953d79ed3736b225eb317d9e35d94b23@resort.herelendinghand.club>
To: <MY EMAIL ADDRESS deleted>
Mime-Version: 1.0
Earthtongue: 2995075-953d79ed3736b225eb317d9e35d94b23_17067283
Content-Transfer-Encoding: 8bit
X-CMAE-Envelope: MS4wfA2MU6766QpfkAjW5HyWfU0k23K9hC8NnHALk82ZowzYx/bqCFunr0zb3l2nVXGHLo18HlRYlmi2rIEXez5fGcnwoLAf/I3pcBFrCVsnauyW/iLpVpWF
 D7K+G71Uj+/3EFaqTFBdnNogdzmkO8a604/Gj+DRscCaMTHrXCnzJvDX//jKCYUhoJ4kms0ws/zUwwPBvD+StQ5BsxL7HgV4yyXci5o9HZXVh8y7ypdbbDh6
 5fsPFz1y1yxr4xnF487o+ewshhsDv1LM0NDfvsZDkNet/wbf25x+m8jQvODB7eZ/hduaaJK+dk6HWKfPEeDgmA==
X-PN-Virus-Filtered: by PlusNet MXCore (v5.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v5.00)
Subject: Approval Notice: Your loan has been approved

 

spraxyt
Resting Legend
Posts: 10,063
Thanks: 674
Fixes: 75
Registered: ‎06-04-2007

Re: Spam

Because you are using a mail forwarder whose servers will have a good reputation the Plusnet spam filtering appliances will have to rely on the content of the messages for spam scoring. Unfortunately it looks like the content of the messages is insufficiently spam-like to trigger marking as spam. Sad

David
Discobolus
Dabbler
Posts: 11
Thanks: 1
Registered: ‎29-11-2013

Re: Spam

I guess that the spam is identified for other users who do not use forwarding. Is it not possible to identify the origin when the spam is trapped for other users, and apply it to everyone's mail?

spraxyt
Resting Legend
Posts: 10,063
Thanks: 674
Fixes: 75
Registered: ‎06-04-2007

Re: Spam

Perhaps the technology will include those sorts of checks in time, especially if driven by unidentified spam. It's not an easy task for machine processes to satify everyone.

David
Townman
Superuser
Superuser
Posts: 23,039
Thanks: 9,623
Fixes: 160
Registered: ‎22-08-2007

Re: Spam

“Is it not possible to identify the origin when the spam is trapped for other users, and apply it to everyone's mail?

Therein lays one of the big issues with spam - it rarely all comes from one source. More often than not spammers get their payloads distributed by infected / from acquired email clients / servers.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Anonymous
Not applicable

Re: Spam


@Oldjim wrote:

a batch today inviting me to a dating site or similar


 

Are you sure that wasn't a seasonal health tip from your geriatric nurse ?  Cheesy

 

DatesAreGood.jpg