cancel
Showing results for 
Search instead for 
Did you mean: 

Sudden Surge of rogue email bouncebacks

hillfort
Grafter
Posts: 26
Thanks: 5
Registered: ‎12-08-2007

Sudden Surge of rogue email bouncebacks

I have lately been receiving rogue email bouncebacks, example below. Needless to say I didnt send any emails to triggered these and there are none in my 'sent' mailbox on either my mail client nor on webmail.

I've also done an anti virus scan which came up clean.

Advice appreciated.

 

Example bounceback:

 

 
Subject:   Mail delivery failed: returning message to sender
From:   Unknown sender
Date:   Tue, May 26, 2026 2:10 pm
To:   [Removed]
Priority:   Normal
Options:    
 

      This is an automatically generated Delivery Status Notification.      

Delivery to the following recipients failed permanently:

   * sales@normanmusa.com

Reason: A message that you sent to the following recipient could not be delivered
due to a permanent error. ** The remote server ?? responded with: **
sales@normanmusa.com ??:?? This message was created automatically by mail delivery
software on the server .

 
 

 

 

 

 

Moderators Note: Personal information removed

13 REPLIES 13
PhilipHeyes
Seasoned Pro
Posts: 639
Thanks: 226
Fixes: 7
Registered: ‎10-11-2021

Re: Sudden Surge of rogue email bouncebacks

Historically these spam messages have been sent from the Plusnet email platform and often from an IP of a Plusnet Internet connection.  Could be rogue customer, could also be a compromised PC or Fire TV Stick loaded with special needs software.

The spam sending is a matter that Plusnet totally failed to address over the last 12 months, and despite repeated warning about the open relay vulnerability of relay.plus.net still have taken zero securing action. 

Champnet
Hero
Posts: 3,213
Thanks: 1,258
Fixes: 18
Registered: ‎25-07-2007

Re: Sudden Surge of rogue email bouncebacks

It's more than possible, until the bounce back message, the email has been nowhere the Plusnet systems.......

PhilipHeyes
Seasoned Pro
Posts: 639
Thanks: 226
Fixes: 7
Registered: ‎10-11-2021

Re: Sudden Surge of rogue email bouncebacks

Every Boots scam email that we have seen in the last year was sent via relay.plus.net and the Plusnet hosted avssout outbound email server farm.  This is how the sender gets SPF / DMARC / DKIM to PASS.

Here are email header examples from a recent Boots message that it was so convincingly real ( it is real ) it was accepted as not being spam by the 123reg email platform :

Received: from avasout-ptp-001.plus.net ([84.93.230.227])     

Authentication-Results: sxplibsmtp04-20.prod.sxb1.secureserver.net;
    dkim=pass header.d=plus.com header.b=qtL2afFb;
    dmarc=pass header.from=<account>.plus.com


DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=plus.com; s=042019;


That I can send messages from my VM internet connection using relay.plus.com without credentials points to lack of effort to secure the platform & is why having migrated to Greenby we have abandoned SMTP server relay.plus.com and the IP.

There is a wall of silence on this open relay issue, so I assume that folks are well aware of  the fact the front door to the SMTP service is wide open much as it was in 2004.  If it was other the questions would come on the matter.

Are there are Boots spam messages that show a different originating source ?
That would be new and interesting to see.

Champnet
Hero
Posts: 3,213
Thanks: 1,258
Fixes: 18
Registered: ‎25-07-2007

Re: Sudden Surge of rogue email bouncebacks

I see no mention in the original post to Boots specifically that's why my reply was more general............

pvmb
Seasoned Pro
Posts: 1,379
Thanks: 252
Fixes: 12
Registered: ‎12-02-2014

Re: Sudden Surge of rogue email bouncebacks


@PhilipHeyes wrote:

Every Boots scam email that we have seen in the last year was sent via relay.plus.net and the Plusnet hosted avssout outbound email server farm.  This is how the sender gets SPF / DMARC / DKIM to PASS.

Here are email header examples from a recent Boots message that it was so convincingly real ( it is real ) it was accepted as not being spam by the 123reg email platform :
Received: from avasout-ptp-001.plus.net ([84.93.230.227])     

Authentication-Results: sxplibsmtp04-20.prod.sxb1.secureserver.net;
    dkim=pass header.d=plus.com header.b=qtL2afFb;
    dmarc=pass header.from=<account>.plus.com

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=plus.com; s=042019;

That I can send messages from my VM internet connection using relay.plus.com without credentials points to lack of effort to secure the platform & is why having migrated to Greenby we have abandoned SMTP server relay.plus.com and the IP.


As avasout-ptp-001.plus.net [84.93.230.227] is listed as a BT IP address, has this matter been reported to BT?

% Abuse contact for '84.92.0.0 - 84.93.255.255' is 'email@bt.com'

https://www.whois.com/whois/84.93.230.227

 

sxplibsmtp04-20.prod.sxb1.secureserver.net [92.204.86.193] belongs to Go Daddy

https://www.whois.com/whois/92.204.86.193

hillfort
Grafter
Posts: 26
Thanks: 5
Registered: ‎12-08-2007

Re: Sudden Surge of rogue email bouncebacks

I did get a boots spam email in amongst it all.  I assume the header doesn't show the full trail from the initial email, just that from the bounce back. 

PhilipHeyes
Seasoned Pro
Posts: 639
Thanks: 226
Fixes: 7
Registered: ‎10-11-2021

Re: Sudden Surge of rogue email bouncebacks

avasout-ptp-001.plus.net is one of about 13 similar hosts operated by PN/BT  you can see them in your SPF list.

pvmb
Seasoned Pro
Posts: 1,379
Thanks: 252
Fixes: 12
Registered: ‎12-02-2014

Re: Sudden Surge of rogue email bouncebacks

...And?

tangodoll
Dabbler
Posts: 13
Thanks: 2
Registered: ‎05-01-2026

Re: Sudden Surge of rogue email bouncebacks

I've just got a new position with a company. I receive their emails just fine and was able to respond until Saturday evening of last week. I tried to respond about 9 times from plusnet email addresses and then my yahoo one - all of the emails came back and didn't send.?!

I have tried just now to receive the same issue. 

As you can imagine, a new job and I need to be able to respond to emails - granted my emails are not 'rogue', but still bouncebacks all the same.

Apologies IF my issue requires a new post.

I need some help with this please quite urgently. Next stop, greenby (un)help(ful) system.

mavison
Pro
Posts: 258
Thanks: 98
Fixes: 3
Registered: ‎20-10-2017

Re: Sudden Surge of rogue email bouncebacks

@tangodoll 

What was a detailed error report from the bounced messages?

Take care to obscure your email address!

Champnet
Hero
Posts: 3,213
Thanks: 1,258
Fixes: 18
Registered: ‎25-07-2007

Re: Sudden Surge of rogue email bouncebacks

@tangodoll wrote: "I've just got a new position with a company."

Does the Company not supply you with an email address ?

 

 

 

tangodoll
Dabbler
Posts: 13
Thanks: 2
Registered: ‎05-01-2026

Re: Sudden Surge of rogue email bouncebacks

Hello @mavison and @Champnet - thank you for your responses. I spoke with the company today it looks like they made a change to their email addresses, so on this occasion - greenby might not be at fault. I used the 'greenby bot' thing and it said the same, but it also stated that there are issues which they're trying to fix. Sorry for MY false alarm.

They're a small company and today was our first training day. We have been issued with 'work' email addresses.

Thanks again, be well everyone. 

part error: Final-recipient: rfc822; ***@********.co.uk
Diagnostic-Code: smtp; 550 5.1.1 User does not exist - 

BUT I'm happily receiving her emails?

Champnet
Hero
Posts: 3,213
Thanks: 1,258
Fixes: 18
Registered: ‎25-07-2007

Re: Sudden Surge of rogue email bouncebacks

@tangodoll  Thanks for the update and good luck for the future..............