Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-14-2011, 01:18 AM
Loyal Member
 
Posts: 81
Default spam problems - from spoofed address

I'm having a lot of problems with excessive spam (to our president)... It's basically a DOS... What's happening is that some spammers are sending out tons of spam and they're using our president's email address in the "From" field. Many thousands of emails "bounce-back" to his address hourly/daily...

I'm trying to figure out how to block these bounce-backs... Technically, these "bounces" are not spam themselves, they are legitimate messages from legitimate servers, bouncing back a message to our pres telling him the message he "sent" is not being delivered... Of course HE NEVER SENT THEM, - I can see the originating server's ip address, and the one who originally sent the email is some server in Africa and some server in China or east asia.

Anyway, the thing is; is there a good way to block these messages? I have to somehow block them based on the "original message", not the current message header... I've attached a sample message. They set the reply-to field to their email address to receive any actual replies, but by using agan@xxx.com in the "From" field, they send all the bounce-backs to me..



Maybe there's a different approach I should be looking into..
Attached Files
File Type: txt bounce.txt (2.1 KB, 9 views)
Reply With Quote
  #2 (permalink)  
Old 03-14-2011, 04:33 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by mickier View Post
I'm having a lot of problems with excessive spam (to our president)... It's basically a DOS... What's happening is that some spammers are sending out tons of spam and they're using our president's email address in the "From" field. Many thousands of emails "bounce-back" to his address hourly/daily...
It's called 'backscatter' or 'NDR' spam, search the forums for those words and you'll find some information on how to reduce it.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 03-14-2011, 05:23 PM
Loyal Member
 
Posts: 81
Default

thanks for the suggestion, but unlike most of the other posters who describe backscatter/ndr, these are bouncing [only] to one of my [real] addresses. A spammer is using my president's email address as the "from" field... these are not a type of scatter email, these are all bounces back to our president's addr. Apparently a direct DOS attack on his account. Ignoring or rejecting non-real addresses wouldn't help in this specific case since all the bounces are addressed to him.

The link you provided for another person's post do describe the exact problem we're experiencing, and there's a link there to some ideas of how to block them on postfix (http://www.postfix.org/BACKSCATTER_README.html) but unfortunately these are a bit beyond my current technical level, and appear a little outdated...

It has helped answer the first question though - there doesn't seem to be a zimbra-implemented solution at this time, so I'll start looking into direct postfix solutions realizing zimbra will probably often undo my manual edits...

Last edited by mickier; 03-14-2011 at 05:41 PM..
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.