We are running Zimbra 6.01 OSE. Since yesterday we have huge amounts of outbound email that is sent by
info@ups.com to bogus email accounts at yahoo, gmail and hotmail. We have now subsequently been blacklisted by these companies.
I have checked that the server is not a relay server as it has successfully passed the relay tests done by popular sites. I keep on deleting the emails in the queues on active and deferred, but they keep on adding up more and more. Is there any way for me to know how the spammer does this and to stop this from happening? Please help as this is causing us to be blacklisted everywhere.
Thank you.
Hennie
See below the header of one of the spam emails:
Return-Path:
info@ups.com
Received: from zmail01.ourdomain.com (LHLO
zmail01.ourdomain.com) (10.0.0.18) by zmail01.ourdomain.com
with LMTP; Mon, 1 Mar 2010 14:47:42 +0200 (SAST)
Received: from localhost (localhost.localdomain [127.0.0.1])
by zmail01.ourdomain.com (Postfix) with ESMTP id 1E6A82FDE16C
for <xxxx@ourdomain.com>; Mon, 1 Mar 2010 14:47:42 +0200 (SAST)
X-Virus-Scanned: amavisd-new at zmail01.ourdomain.com
X-Spam-Flag: YES
X-Spam-Score: 11.369
X-Spam-Level: ***********
X-Spam-Status: Yes, score=11.369 tagged_above=-10 required=6.6
tests=[ADVANCE_FEE_2=1.234, ADVANCE_FEE_3=1.432, ALL_TRUSTED=-1.8,
AWL=-0.121, BAYES_99=3.5, FH_DATE_PAST_20XX=3.188,
FORGED_MUA_OUTLOOK=3.116, MSOE_MID_WRONG_CASE=0.82] autolearn=no
Received: from zmail01.ourdomain.com ([127.0.0.1])
by localhost (zmail01.ourdomain.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id ThUpEvun+3qL; Mon, 1 Mar 2010 14:47:41 +0200 (SAST)
Received: from User (unknown [195.245.108.36])
by zmail01.ourdomain.com (Postfix) with ESMTPA id 610E72FDE05A;
Mon, 1 Mar 2010 14:45:47 +0200 (SAST)
Reply-To: <ups.agent.ng1@gmail.com>
From: "UPS COURIER SERVICES."<info@ups.com>
Subject: Confirm Your Parcel With Us ASAP.
Date: Mon, 1 Mar 2010 12:50:18 -0000
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <20100301124550.610E72FDE05A@zmail01.ourdomain.com >
To: undisclosed-recipients:;
Subject: Confirm Your Parcel With Us ASAP.
From: Universal Parcel Service <info@ups.com.ng>