+ Reply to Thread
Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Forged Email Headers

  1. #1
    carl6969's Avatar
    carl6969 is offline Community Support Team carl6969 has a brilliant futurecarl6969 has a brilliant futurecarl6969 has a brilliant future
    Join Date
    May 2009
    Location
    Calf Creek TX
    Posts
    6,862

    Forged Email Headers

    I have been having a lot of problems with forged email lately. Email that, (based on the return address and most of the headers), appears to come from one or more of the domains on my VPS. I have Spam Assassin set up and it is catching most of the normal spam, but the forged email's are getting by. I can set up filters on my personal email program to take care of this on my end, but I do not want these emails going out in the first place. Other people are going to think they are really coming from my domains and some of them have malware / virus attachments. Not good for business.

    So, I have been wondering if there is ANY way at all to deal with this on the server side.
    I am using Centos 5.3, BIND, Procmail filter, SpamAssassin.
    I have done some research and cannot find any obvious errors with my configurations.


  2. #2
    Mr. DOS is offline x10 Sophmore Mr. DOS is an unknown quantity at this point
    Join Date
    Oct 2009
    Location
    Nova Scotia, Canada
    Posts
    228

    Re: Forged Email Headers

    I think http://www.robsworld.org/forgery.html is probably relevant to you.
    I've written a couple articles on automatic application of AlphaImageLoader in IE6 using nothing but IE6-specific CSS rules.

  3. #3
    lemon-tree's Avatar
    lemon-tree is offline x10 Minion lemon-tree has a spectacular aura about
    Join Date
    Nov 2007
    Posts
    1,420

    Re: Forged Email Headers

    It is almost certain that the emails are not actually originating from your server, but as you said the headers are just being manipulated to tell the end user they are coming from your server. I would recommend looking at the headers of the email and look for a mailed-by header; this may give you an impression as to the origin of the email but it will still be very difficult to stop it unless the spammer is stupid enough to be sending from a server that has web content on it too.
    Basically, as that document says, it is very difficult to stop the spammers, but you could use a few techniques to assist your users. Firstly, I would recommend sending an email to all your users describing the situation and perhaps changing your email address. I would also use an email obfuscater to hide your email address from web bots, as this is likely where they got your address from.

  4. #4
    carl6969's Avatar
    carl6969 is offline Community Support Team carl6969 has a brilliant futurecarl6969 has a brilliant futurecarl6969 has a brilliant future
    Join Date
    May 2009
    Location
    Calf Creek TX
    Posts
    6,862

    Re: Forged Email Headers

    Quote Originally Posted by Mr. DOS View Post
    I think http://www.robsworld.org/forgery.html is probably relevant to you.
    Thanks for the link. Good article.


  5. #5
    carl6969's Avatar
    carl6969 is offline Community Support Team carl6969 has a brilliant futurecarl6969 has a brilliant futurecarl6969 has a brilliant future
    Join Date
    May 2009
    Location
    Calf Creek TX
    Posts
    6,862

    Re: Forged Email Headers

    @lemon-tree
    Thanks for the reply and the advice.
    Even though I receive a lot of spam with obviously forged headers, the spam that seemed to be coming from my own server was puzzling me. I started wondering if I had a vulnerability somewhere that the spammers were exploiting, or, perhaps, more experienced server operators had found a way to prevent this problem. Based on some reading, including the article referenced by Mr. DOS, the only point I may have failed at is obfuscated email addresses. Ironically, I have recently started changing all that, but I fear I am closing the barn door after the cows have already left. But perhaps this thread will be useful to new VPS users just getting started in the future.
    Thanks again.
    Last edited by carl6969; 03-19-2010 at 03:12 PM. Reason: Grammar errors due to caffiene deprivation.


  6. #6
    The Real Rebel's Avatar
    The Real Rebel is offline x10 Lieutenant The Real Rebel is an unknown quantity at this point
    Join Date
    Dec 2009
    Location
    Ireland
    Posts
    336

    Re: Forged Email Headers

    Ouch, sorry to see you have this problem Carl, Hope everything is getting better now

  7. #7
    carl6969's Avatar
    carl6969 is offline Community Support Team carl6969 has a brilliant futurecarl6969 has a brilliant futurecarl6969 has a brilliant future
    Join Date
    May 2009
    Location
    Calf Creek TX
    Posts
    6,862

    Re: Forged Email Headers

    Quote Originally Posted by The Real Rebel View Post
    Ouch, sorry to see you have this problem Carl, Hope everything is getting better now
    Thanks. Currently working to correct both the forged email problem and the caffeine deprivation. Mr. Coffee assisting with second one.


  8. #8
    The Real Rebel's Avatar
    The Real Rebel is offline x10 Lieutenant The Real Rebel is an unknown quantity at this point
    Join Date
    Dec 2009
    Location
    Ireland
    Posts
    336

    Re: Forged Email Headers

    Lol, I have mr coca cola to sort that :P

  9. #9
    lemon-tree's Avatar
    lemon-tree is offline x10 Minion lemon-tree has a spectacular aura about
    Join Date
    Nov 2007
    Posts
    1,420

    Re: Forged Email Headers

    Ironically, I have recently started changing all that, but I fear I am closing the barn door after the cows have already left
    Don't worry, I did a similar thing once and my spam levels in my inbox was hundreds per week. On the same address now I get a couple a month. It seems that the spam crawlers will drop your email address after a while of not being able to find it anywhere, it's like they refresh their database of known emails once a month or so. So eventually those cows you let loose will come back eventually.

  10. #10
    masshuu's Avatar
    masshuu is offline Head of the Geese masshuu has a spectacular aura about
    Join Date
    Oct 2007
    Location
    Las Colinas, Tx
    Posts
    2,262

    Re: Forged Email Headers

    i set a spf record on my domain. Any mailserver worth its salt obeys spf records.
    Just leading the flock.
    Livewire
    Masshuu ------ carl6969
    descalzo ------------------- Smith6612
    Bryon--------------------------------- Corey
    If you find any post helpful or useful, duck
    \ / This for that post and rep it up.

+ Reply to Thread
Page 1 of 2 12 LastLast

Similar Threads

  1. Headers already sent
    By firila in forum Free Hosting
    Replies: 7
    Last Post: 03-08-2010, 03:08 PM
  2. Headers
    By Macaws in forum Graphics & Webdesign
    Replies: 5
    Last Post: 09-18-2008, 06:08 PM
  3. Error headers with php.
    By Tarzan in forum Programming Help
    Replies: 5
    Last Post: 08-06-2008, 11:07 AM
  4. page headers
    By SyncViews in forum Scripts & 3rd Party Apps
    Replies: 2
    Last Post: 11-27-2007, 10:09 AM
  5. Php codes headers
    By nexhunter in forum Scripts & 3rd Party Apps
    Replies: 4
    Last Post: 11-22-2007, 04:25 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
x10hosting free hosting for the masses
dedicated servers