|
|
Question : Bogus emails
|
|
I get the following email in veryday to my administrator account, I would like to know where it is ocming from and is there a way of stopping it?: Sender: [email protected] Subject: failure notice Attachments: "You have successfully updated your password" Body: Hi. This is the qmail-send program at eircom.net. I'm afraid I wasn't able to deliver your message to the following addresses. This is a permanent error; I've given up. Sorry it didn't work out.
: xx.xx.xx.xx does not like recipient. Remote host said: 550 5.1.1 User unknown Giving up on xx.xx.xx.xx.
--- Enclosed is a copy of the message.
|
Answer : Bogus emails
|
|
SPF/Sender ID are 2 things that are very easy to do, and do help cut down on things like NDR spam. Sender Policy Framework is here: http://www.openspf.org/ Basicall, you add a txt record to your DNS zone, and it lets other domains know what servers are authorized to send email for your domain. If those servers have enabled SPF checks, the will classify the mail as possible spam if it doesn't come from your domains allowed servers. Cuts down on spoofed email getting bounced to your domain, when it never came from domain. Google uses it, I think AOL does. A US Financial industry consortium has reccomended SPF be used by all financial companies, especially since it can help reduce other problems as well, like email identity forgery and phishing. They also reccomend Sender ID.
Sender ID from Micrsoft setup is detailed here. You need to have service pack 2 installed. http://www.microsoft.com/technet/prodtechnol/exchange/2003/sp2security.mspx Basically, it checks incoming mail to see if it maybe spam. It can use the SPF records of other domains to check the message as it arrives. It uses some same ideas as pure SPF, but acts a little differently. Hotmail uses Sender ID.
Take the time to read up on both. The do both. I cut spam processing by an easy 20% just using SPF checks, and cut out a lot of spam bounce-back junk just by adding an SPF record. And as more servers/providers/hosters/ISPs start doing this, things will slowly get better.
|
|
|
|
|