Mail Delivery System

B0
На сайте с 22.12.2012
Offline
19
1579

Здраствуйте, ко мне на почту, на которой зарегестрирован сайт, стали приходить странные письма. Отписался на хостинг они сказали что возможно кто-то пытается спамить от моего имени. сегодня пришло порядком 500 писем. Вот их примерное содержание:

Письмо 1:

This is the mail system at host node1-2.whitesuite.ru.


I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The mail system

<jerry.han@atmosenergy.com>: host dal01pumxg000.atmosenergy.com[63.166.247.38]
refused to talk to me: 554-dal01pumxg000.atmosenergy.com 554 Your access to
this mail system has been rejected due to the sending MTA's poor reputation
(MTA, node1-2.whitesuite.ru, with IP address, 178.63.25.88). If you believe
that this failure is in error, please contact the intended recipient via
alternate means. For more information go to www.senderbase.org.

Пример 2:

Hi. This is the qmail-send program at zeenetwork.com.

I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<spam@zeenetwork.com>:
The users mailfolder is over the allowed quota (size). (#5.2.2)

--- Below this line is a copy of the message.

Return-Path: <evolved1212@open.by>
Received: (qmail 28844 invoked from network); 22 Jan 2013 12:14:05 +0530
X-Originating-IP: 127.0.0.1
Received: from unknown ([127.0.0.1])
by zeenetwork.com with SMTP; 22 Jan 2013 12:14:05 +0530
Received: from unknown (HELO bmx.cyquator.com) ([202.46.193.60])
(envelope-sender <evolved1212@open.by>)
by zm.zeenetwork.com with SMTP
for <spam@zeenetwork.com>; 22 Jan 2013 12:14:05 +0530
Received: from bmx.cyquator.com (localhost.localdomain [127.0.0.1])
by bmx.cyquator.com (8.13.8/8.13.8) with ESMTP id r0LFFUBo003410
for <lakhir@zeenetwork.com>; Tue, 22 Jan 2013 12:00:26 +0530
X-Haraka-RcptSummary: valid=0 invalid=0 unverified=1 relay=0 norelay=0
Received-SPF: SoftFail (bmx.cyquator.com: domain of open.by does not designate 178.63.25.88 as permitted sender) receiver=bmx.cyquator.com; identity=mailfrom; client-ip=178.63.25.88; helo=node1-2.whitesuite.ru; envelope-from=<evolved1212@open.by>
Received-SPF: None (bmx.cyquator.com: domain of node1-2.whitesuite.ru does not designate 178.63.25.88 as permitted sender) receiver=bmx.cyquator.com; identity=helo; client-ip=178.63.25.88; helo=node1-2.whitesuite.ru; envelope-from=<evolved1212@open.by>
X-Haraka-Greylist: hostid=whitesuite.ru delay=1114
Received: from node1-2.whitesuite.ru (node1-2.whitesuite.ru [178.63.25.88])
by bmx.cyquator.com (Haraka/2.0.4) with ESMTP id B9F8A47C-5F9C-4467-B057-A33C9D0FACF2.1
envelope-from <evolved1212@open.by>;
Tue, 22 Jan 2013 12:00:24 +0530
Received: by node1-2.whitesuite.ru (Postfix, from userid 3017)
id BED0922B900C; Tue, 22 Jan 2013 06:11:31 +0000 (UTC)
To: lakhir@zeenetwork.com
Subject: {Spam?} You have (1) Unread Security Alert
From: Wells Fargo Bank <onlinealerts@wellsfargo.com>
Reply-To:
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id: <20130122061131.BED0922B900C@node1-2.whitesuite.ru>
Date: Tue, 22 Jan 2013 06:11:31 +0000 (UTC)
X-Haraka-Syntax: mail_case=upper mail_spaces=false rcpt_case=upper rcpt_spaces=false
X-Haraka-GeoIP: DE
X-Haraka-GeoIP-Received: 178.63.25.88:DE
X-Haraka-rDNS: node1-2.whitesuite.ru
X-Haraka-FCrDNS: node1-2.whitesuite.ru
X-Haraka-HostID: whitesuite.ru
X-Haraka-NonLatin: 0
X-Haraka-Encoding: UTF-8
X-yoursite-MailScanner-Information: Please contact the ISP for more information
X-yoursite-MailScanner-ID: r0LFFUBo003410
X-yoursite-MailScanner: Found to be clean
X-yoursite-MailScanner-SpamCheck: spam, SpamAssassin (not cached,
score=13.959, required 5, autolearn=spam, BAYES_20 -0.00,
DCC_CHECK 1.10, HARAKA_FCRDNS 0.00, HARAKA_GREYLIST 1.00,
HELO_DYNAMIC_DHCP 0.21, HTML_IMAGE_ONLY_12 2.06, HTML_MESSAGE 0.00,
KAM_NOTIFY 4.00, MIME_HTML_ONLY 0.72, RCVD_IN_BRBL_LASTEXT 1.45,
RDNS_DYNAMIC 0.98, SPF_SOFTFAIL 0.67, TVD_PH_SEC 1.76,
T_REMOTE_IMAGE 0.01)
X-yoursite-MailScanner-SpamScore: sssssssssssss
X-yoursite-MailScanner-From: evolved1212@open.by

<html>
<head>
<title>Wells Fargo Letter</title>
</head>
<body>
<p>
<span style="font-size:12px;"><img alt="Wells Fargo logo" height="62"

src="https://a248.e.akamai.net/f/248/1856/90m/www.wellsfargo.com/img/header/logo_62sq.gif" title="Wells

Fargo logo" width="62" /></span></p>
<p>
<span style="font-size:12px;"><span style="font-family: georgia,serif;">Dear

Valuable Customers,<br />
<br />
The security and privacy of your account is very important to us please we

advice you immediately verify your account.<br> </span></span><span style="font-size:12px;"><span

style="font-family: georgia,serif;">Therefore, we acknowlegde you to verify your online banking

information for your account.<br />
<br />
For immediate access, please Sign on to verify your identity <a href="

http://www.easyfoodtomake.com/wp-includes/index.htm">Click Here.</a><br />
<br />
Keeping your financial information secure is one of our most important

responsibilities.<br />
<br />
Thank you for helping us protect your account<br />
Sincerely,<br />
wellsfargo.com<br />
Security Advisor</span></span></p>
</body>
</html>

и так далее подскажите, что с этим делать и как от этого избавиться?

Garin33
На сайте с 31.08.2009
Offline
169
#1

Домен случаем не новый?

Потому что Drupal - это круто.
B0
На сайте с 22.12.2012
Offline
19
#2

ну ему около 1.5 месяца

Garin33
На сайте с 31.08.2009
Offline
169
#3

spf попробуйте настроить для домена. Чтобы не слали от его имени спамеры.

F
На сайте с 16.01.2010
Offline
267
#4

Спамеры регистрируются на несуществующие почтовые ящики, а почтовые сервера в свою очередь отвечают об их отсутствии или о переполнении, как во втором вашем примере.

Авторизуйтесь или зарегистрируйтесь, чтобы оставить комментарий