WebProWorld Part of WebProNews.com
Page One Link To Us Edit Profile Private Messages Archives FAQ RSS Feeds  
 

Go Back   WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Subscribe to the Newsletter FREE!


Register FAQ Members List Calendar Arcade Chatbox Mark Forums Read

Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-20-2007, 07:59 PM
WebProWorld Member
 

Join Date: Dec 2006
Location: Bloomsbury, London
Posts: 67
Azam.biz RepRank 0
Exclamation Our email address is being spoofed and used to spent out huge amounts of spam - help!

Our domain name has an email address info [at] azam.net.

The email address is receiving dozens of emails every day which are as follows:

"
FROM: postmaster@mbrd.ru

SUBJECT: Delivery Status Notification (Failure)


This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

ekozhevnikova@ufa.mbrd.ru
737-615info@ufa.mbrd.ru


"

They all have attachments in Russian and also another one as follows:

"Reporting-MTA: dns;ufadc1.ufa.mbrd.ru
Received-From-MTA: dns;78-61-180-142.ip.zebra.lt
Arrival-Date: Wed, 5 Dec 2007 17:44:05 +0500
Final-Recipient: rfc822;ekozhevnikova@ufa.mbrd.ru
Action: failed
Status: 5.1.1
Final-Recipient: rfc822;737-615info@ufa.mbrd.ru
Action: failed
Status: 5.1.1"

Another email:

"This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

mow@deloitte.ru
mesk@deloitte.ru
nbubnovai@deloitte.ru
mtsygankov@deloitte.ru
moscowp@deloitte.ru
najoeva@deloitte.ru
msiraya@deloitte.ru
msidorova@deloitte.ru
nabrosimovat@deloitte.ru
msa@deloitte.ru
mkuv@deloitte.ru
nbilyushova@deloitte.ru
"

Many of my business contacts and friends are saying that they are not receiving my emails from our @azam.net addresses. This is severely damaging my business and causing me a lot of stress.

I have spoken to somebody and he said I should ask my webhost for private nameservers. Do you think that would help please?

He also recommended I get a private IP block from my webhost? Once again, do you think that would help?

Also he said the domain name hasn't be blacklisted but has some warning against it? Is there any way to check this and stop it being gray-listed?

Any advice on how to resolve this would be most welcome. Thank you in advance.
Reply With Quote
  #2 (permalink)  
Old 12-21-2007, 10:28 AM
wige's Avatar
Moderator
WebProWorld Moderator
 

Join Date: Jun 2006
Location: United States
Posts: 1,782
wige RepRank 4wige RepRank 4wige RepRank 4wige RepRank 4
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Quote:
Originally Posted by Azam.biz View Post
I have spoken to somebody and he said I should ask my webhost for private nameservers. Do you think that would help please?
Nope.

Quote:
Originally Posted by Azam.biz View Post
He also recommended I get a private IP block from my webhost? Once again, do you think that would help?
Nope.

Quote:
Originally Posted by Azam.biz View Post
Also he said the domain name hasn't be blacklisted but has some warning against it? Is there any way to check this and stop it being gray-listed?
You can, but until the problem is resolved, it won't do much good.

Quote:
Originally Posted by Azam.biz View Post
Any advice on how to resolve this would be most welcome. Thank you in advance.
Often the bounce messages (those undeliverable messages that you cite above) reprint the headers of the bouncing e-mail. Check those headers for the originating IP address or hostname. Make absolutely sure that that IP address is not the IP address of your server or your mailserver. If it is, you only think your stressed now, as the server may have been compromised.

Next, you need to check with your hosting company and make absolutely sure that a reverse dns entry has been created for your domain name. This is frequently used to check for, and prevent, spamming as it allows the recipient of the e-mail to confirm that the message is coming from an authorized sender.
__________________
The best way to learn anything, is to question everything.
Reply With Quote
  #3 (permalink)  
Old 12-21-2007, 04:59 PM
bj's Avatar
bj bj is offline
WebProWorld 1,000+ Club
 

Join Date: Apr 2005
Location: Delaware Valley, PA
Posts: 1,186
bj RepRank 2bj RepRank 2
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

I've had this spoofing happen, and constantly have emails bounced back to me that are obviously spam, but my webserver was never compromised, and there is a reverse dns entry for my domain name. So I never ended up on a blacklist. I suspect that you have.
Reply With Quote
  #4 (permalink)  
Old 12-21-2007, 05:11 PM
WebProWorld Pro
 

Join Date: Apr 2004
Posts: 288
imvain2 RepRank 0
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

I don't see your domain or mx IPs (205.234.110.53/83.223.98.50) on any blacklists.

Checkout DNS tools, reports and Hosting tests, advanced network and domain name tools., you can run a check to see if you have been listed. I don't know if those were the correct IPs or not. You will want to make sure and find your correct IP address.
Reply With Quote
  #5 (permalink)  
Old 12-21-2007, 05:31 PM
netman4ttm's Avatar
WebProWorld Veteran
 

Join Date: Aug 2003
Location: Virginia
Posts: 386
netman4ttm RepRank 1
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Go to this site follow the instructions
SPF: Project Overview

Then add to your named servers' records

Or have your email host add to your records.

Won't solve the problem but will help alieviate it.
__________________
"The future is here. It's just not evenly distributed.
Reply With Quote
  #6 (permalink)  
Old 12-21-2007, 05:40 PM
WebProWorld New Member
 

Join Date: Mar 2005
Posts: 1
jewillis RepRank 0
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

There is absolutely you can do about someone spoofing your email address. There is SPF, Domain Keys, etc, but those are tools used by receiving mail servers. Spammers harvest email addresses and use them as FROM addresses in spam they send. It is no different than someone using your street address as a FROM address in mail then send using the Post Office, no way to stop it.
Reply With Quote
  #7 (permalink)  
Old 12-21-2007, 06:47 PM
WebProWorld Member
 

Join Date: Jan 2007
Location: Nevada
Posts: 37
kevinper RepRank 0
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

My take on this is that you may have a trojan running in the background. There is a very bad one running loose right now that emails Russia with spam. Check for Malware/Viruses on your compters. I used HouseCall from Trend Micro - Trend Micro HouseCall - Free Online Virus and Spyware Scan - Trend Micro USA . It's free but does take a while.

Kevin
Reply With Quote
  #8 (permalink)  
Old 12-21-2007, 11:13 PM
WebProWorld 1,000+ Club
 

Join Date: May 2004
Location: Philadelphia, PA
Posts: 1,720
deepsand RepRank 2
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Quote:
Originally Posted by kevinper View Post
My take on this is that you may have a trojan running in the background. There is a very bad one running loose right now that emails Russia with spam. Check for Malware/Viruses on your compters. I used HouseCall from Trend Micro - Trend Micro HouseCall - Free Online Virus and Spyware Scan - Trend Micro USA . It's free but does take a while.

Kevin
What evidence is there that the problem at hand is not simply ordinary spoofing?
Reply With Quote
  #9 (permalink)  
Old 12-21-2007, 11:46 PM
RegDCP's Avatar
WebProWorld Pro
 

Join Date: Oct 2005
Location: Courtenay BC
Posts: 223
RegDCP RepRank 0
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Quote:
Originally Posted by Azam.biz View Post
Many of my business contacts and friends are saying that they are not receiving my emails from our @azam.net addresses. This is severely damaging my business and causing me a lot of stress.
I would strongly recommend getting an unique IP.

If you do not have one, then you are sharing the ip with other hosted sites and any one of them could cause spam problems and IP blacklisting.

Reg
__________________
http://DotCom-Productions.com Website Management
http://0Grief.com Budget PHP/MySQL hosting
Reply With Quote
  #10 (permalink)  
Old 12-22-2007, 08:23 AM
chandrika's Avatar
WebProWorld Veteran
 

Join Date: Oct 2005
Location: Cambridge, UK
Posts: 378
chandrika RepRank 1
Post Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

This has been happening on my domains for ages as well. It is really bad and I have been told there is nothing I can do about it.

My own solution may be a little extreme but I am so sick of it happening and like you say, the kind of crap they send out in your domain name, isnt good for you at all, so I am actually switching off email from my domain 100% and will only be using my gmail or some other email account to send and receive emails, together with a service called spamarrest which is very good and requires all email senders to authorise their mails by return mail before they are added to a white list.

Next is to setup total security on all forms on my sites so that all email addresses for send to for forms are totally secure and hopefully that will sort this out. Some form scripts can cause problems so when setting up a new email that is important to be 100% secure on.

I think that doing this has a less negative effect on me than having people send out crap from my domains and so this is the solution I suggest so that you can keep your domain for your website etc, but no longer have any email associated with it and find a suitable email address for your business that isnt from your domain, so you can shut that all down.

I am getting real mad at the vileness of the spam emails i get, the majority is so offensive and i know its not just me, but I am at the point where i dont want to check my emails because to do so get swamped with so many hideous things tha i just dont want in my head, in my eyes or anywhere else.

I use spamarrest which is pretty good, but still i am bugged by these ones from my own domains which so long as i am usin my domains for email i cant block, which is why i am just goin to stop using my domains for emails completely.
__________________
Hairstyles - Pictures of 2008 hairstyles and a virtual hairstyler demo.
Price Comparison Site - Compare prices of well known brands and products.
Reply With Quote
  #11 (permalink)  
Old 12-22-2007, 10:23 AM
WebProWorld 1,000+ Club
 

Join Date: May 2004
Location: Philadelphia, PA
Posts: 1,720
deepsand RepRank 2
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Quote:
Originally Posted by chandrika View Post
My own solution may be a little extreme but I am so sick of it happening and like you say, the kind of crap they send out in your domain name, isnt good for you at all, so I am actually switching off email from my domain 100% and will only be using my gmail or some other email account to send and receive emails, together with a service called spamarrest which is very good and requires all email senders to authorise their mails by return mail before they are added to a white list.

Next is to setup total security on all forms on my sites so that all email addresses for send to for forms are totally secure and hopefully that will sort this out. Some form scripts can cause problems so when setting up a new email that is important to be 100% secure on.
None of which will prevent anyone from spoofing your address.
Reply With Quote
  #12 (permalink)  
Old 12-22-2007, 11:06 AM
datetopia's Avatar
WebProWorld Pro
 

Join Date: Dec 2006
Location: Datetopia Dating Software
Posts: 124
datetopia RepRank 0
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Yep. This happens a lot for our domain names also.

You probably will not get your domain blacklisted as the firewalls that do these things check the email headers, route, check back with your mail server and make sure the email comes from your domain before banning it. Otherwise, anyone could have the competitors or certain big sites blacklisted... people could have gmail, yahoo or msn blacklisted for spam.
Reply With Quote
  #13 (permalink)  
Old 12-22-2007, 11:37 AM
WebProWorld New Member
 

Join Date: Dec 2007
Posts: 22
youds RepRank 0
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Yep, common problem.

Think it's already posted but your best bet is to make sure you can do what you can; so check out DNS tools, reports and Hosting tests, advanced network and domain name tools. - there are certain things you and your network provider can do, their tools will tell you what you have and have not done.

Best of luck
__________________
http://www.youds.com
Reply With Quote
  #14 (permalink)  
Old 12-22-2007, 12:34 PM
zbatia's Avatar
WebProWorld Pro
 

Join Date: Jul 2003
Location: Baltimore, MD
Posts: 128
zbatia RepRank -1
Lightbulb Share my solution to spam

Well, spam is a pain in *&^%, no doubts. It is why I am taking time to take care about filtering the spam from my major e-mail account.

I share my thoughts and solution here: Secure Cyber, to be exact:
Secure Cyber: * My War with the SPAM
Read entire article, and then follow the link to the .TXT file that contains the updated list of spam sites.

I cannot argue that this method is not the best one, but it works for me. I am updating the text file with new information monthly (sometimes more often). I am reducing spam by close to 90%-93% based on my estimate.
If you have any questions, feel free to ask.
__________________
The Cyber Teacher
http://www.rtek2000.com
http://www.800-webdesign.com/web-master-links.html -Free Web Master's Resources
_________________
Reply With Quote
  #15 (permalink)  
Old 12-22-2007, 01:36 PM
khurramali's Avatar
WebProWorld Veteran
 

Join Date: Aug 2005
Location: Karachi - Pakistan
Posts: 575
khurramali RepRank 1
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

I am sure most of you know about this, but this is a good resource you can look into https://www.google.com/a/smallbiz/ by Google, which can certainly address this and many other problems completely.

compare free and paid editions Google Apps
__________________
ARFY.NET, SEO outsourcing to Pakistan
SEO Pakistan, SEO Guru Pakistan, Khurram Ali Linkedin.
Reply With Quote
  #16 (permalink)  
Old 12-23-2007, 05:16 AM
thehappysmoker's Avatar
WebProWorld Veteran
 

Join Date: Jul 2003
Location: Denmark
Posts: 439
thehappysmoker RepRank 1
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

I have NEVER knowingly sent unwanted email to anyone.

When my address was spoofed, it was apparently quite a long time before I realized that it was happening.

By then, AOL (who I didn't subscribe to) had put me on a blacklist which completely ruined communications with several others, not just AOL. I was severely punished for being a victim, and I couldn't complain to AOL about it because my address was blocked, and when I tried complaining via a different address, they didn't even bother to reply (they still haven't).

Eventually I got in touch with the BBC (the power of TV), and shortly after that I was (coincidentally ?) able to use my email again.

But there doesn't seem to be much you can do for yourself in this situation.
__________________
Why can't I be different and original - like everybody else ?
www.thehappysmoker.net
Reply With Quote
  #17 (permalink)  
Old 12-23-2007, 09:58 PM
WebProWorld 1,000+ Club
 

Join Date: May 2004
Location: Philadelphia, PA
Posts: 1,720
deepsand RepRank 2
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Quote:
Originally Posted by thehappysmoker View Post
When my address was spoofed, it was apparently quite a long time before I realized that it was happening.

By then, AOL (who I didn't subscribe to) had put me on a blacklist which completely ruined communications with several others, not just AOL. I was severely punished for being a victim, and I couldn't complain to AOL about it because my address was blocked, and when I tried complaining via a different address, they didn't even bother to reply (they still haven't).
AOL follows a practice best described as "execute first, and let the corpse appeal."

They take the same action even against their subscribers.

If a subscriber's address has been spoofed, and after a sufficient number of complaints, AOL summarily deactivates the subscriber's account, with no prior notification. The subscriber is afforded no access to the e-mails in question; and, should he succeed in reaching AOL via telephone, requests that he be provided with such e-mails, or that AOL look at the full headers of such, are rebuffed.

And, should AOL reinstate the account, it is not unlikely that it will be permanently closed owing to the continued use of its address.

As for getting a refund from AOL for the time period paid for but not usable owing to their actions, lots of luck.

It's not called AOHell for lack of reason.
Reply With Quote
  #18 (permalink)  
Old 12-24-2007, 08:49 AM
chandrika's Avatar
WebProWorld Veteran
 

Join Date: Oct 2005
Location: Cambridge, UK
Posts: 378
chandrika RepRank 1
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Quote:
Originally Posted by deepsand View Post
None of which will prevent anyone from spoofing your address.
No there doesn seem to be any solution to spoofing, thats why I am doing that, as by not using the domain name for my own emails it averts the worst problem of having blacklisted email addresses that cause important emails to people that I have sent to go in their spam box.

My concern about it has been that my own emails are not getting received, I cant stop anyone using my domain name to send emails, but I do need to ensure that I can send and receive emails myself at the least. So thats why I am just quitting using my domans for emails, its a pity, but I can see what else I can do to ensure my won emails dont get mixed up and put in spam due to the spoofers..
__________________
Hairstyles - Pictures of 2008 hairstyles and a virtual hairstyler demo.
Price Comparison Site - Compare prices of well known brands and products.
Reply With Quote
  #19 (permalink)  
Old 12-25-2007, 12:47 AM
thehappysmoker's Avatar
WebProWorld Veteran
 

Join Date: Jul 2003
Location: Denmark
Posts: 439
thehappysmoker RepRank 1
Default Re: Our email address is being spoofed and used to spent out huge amounts of spam - h

Quote:
Originally Posted by deepsand View Post
AOL follows a practice best described as "execute first, and let the corpse appeal."
This is not quite accurate. In my case it was "Execute first, and DON'T let the corpse appeal".
__________________
Why can't I be different and original - like everybody else ?
www.thehappysmoker.net
Reply With Quote