1

Topic: Spammer sent email with FOR meta

==== Required information ====
- iRedMail version (check /etc/iredmail-release): 0.84
- Linux/BSD distribution name and version: debian 8 jessie
- Store mail accounts in which backend (LDAP/MySQL/PGSQL):  mysql
- Web server (Apache or Nginx): nginx
- Manage mail accounts with iRedAdmin-Pro? no
- Related log if you're reporting an issue:
====
spammer have send email with
for <my@mail.com>

how to block this kind of email because it keep change TO and FROM meta header.
Have no idea how to block this.

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Spammer sent email with FOR meta

You have to find out the same info on those spams, then block them based on that info. Also, show us full headers of sample spams, and related log in Postfix log file so that others can help troubleshoot.

3 (edited by jackavin 2016-10-24 02:03:44)

Re: Spammer sent email with FOR meta

FROM and TO not my email but FOR is my email. It keep coming with spam mail and changing TO and FROM.
I have try to block but not success.


Return-Path: <srs0=3/j/=wi=wave3.com=its@mail.com>
Delivered-To: xx@domain.com
Received: from mx.mail.com (mx.mail.com [127.0.0.1])
    by mx.mail.com (Postfix) with ESMTP id 7C64080682
    for <my@mail.com>; Sat, 22 Oct 2016 21:39:35 +0700 (ICT)
X-Virus-Scanned: Debian amavisd-new at mx.mail.com
X-Spam-Flag: NO
X-Spam-Score: 2.288
X-Spam-Level: **
X-Spam-Status: No, score=2.288 tagged_above=2 required=6.31
    tests=[HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_IMAGE_RATIO_02=0.805,
    HTML_MESSAGE=0.001, MPART_ALT_DIFF_COUNT=1.483, NO_RECEIVED=-0.001,
    NO_RELAYS=-0.001] autolearn=no autolearn_force=no
     with ESMTP id fQb4IZk-cqPf for <xx@mail.com>;
    Sat, 22 Oct 2016 21:39:34 +0700 (ICT)
Message-Id: <e3a3bf$326bob@irp3.truemail.co.th>
X-IronPort-AV: E=Sophos;i="5.31,531,1473094800";
   d="scan'208,217,145";a="102969102"
MIME-Version: 1.0
From: xxxx <its@wave3.com>
To: xxx <gekkobooks@outlook.com>
Date: 22 Oct 2016 21:39:07 +0700
Subject: =?utf-8?B?4Lij4Liw4Lia4Lia4LiV4Li04LiU4LiV4Liy4Lih4Lij4LiW?=
=?utf-8?B?4Lii4LiZ4LiV4LmMLi4uLi4uLi4u?=
Content-Type: multipart/alternative;
boundary=--boundary_1680_52152e13-75cf-4125-a5b7-b33bdc3f381c
X-Filter-ID: s0sct1PQhAABKnZB5plbIe/YBiEW6yJiBLck0zYZHI4SdA5x5+AgddSdYuGJ5wGJdSEL8jpgBc0Z
xVDxUTE6LWHILft9ZyczRXO19dCvPHPrcxAODBZO2BOkcGk4nUta1kRfjUIXXRtn1C7eNCFAUPEq
BDt6gb1KSD/Bd9DwRwv9zB1CUT/a1/4HfoOJKuztW/wD3DTFWlPrrcxmH9mNrRX+LuYG36MnHRFl
K+seGMoOO0eRbwW+kSd8XoLnre/WGeMgWCdl7uwTw7fvNEG3U9tCvzXBCjJasjmgC+Bdtk093SsS
4aMXJmiJ2G0eb5ah2vHRM39ZQYz9pCrPMM7yuV0qx0/ZIJiFqkEcQ/ZGSAP1H/aAwarQpYDOYx/6
JtUOKjc2Vz3GZZyKLpjnAgLX/VVzBIhFm//bT/bm1rqsy3oaKXvNWrRcSD72jROfhu6vZJ0Q4x+0
GOxZvoENDONKwSqNTfLyEMhnFf5Orvq5y8rC4lHsl2KbChvi6ydukv38kVWClPVvbW5lVyQanRxw
5mrHkqPnkzTuxv61DBvgFsph9LwoigOOnc8saAtVwpuc9sEL5wg+jiVSaARb8MZzQg==
X-Report-Abuse-To: spam@mx99.antispamcloud.com
X-SpamExperts-Class: unsure
X-SpamExperts-Evidence: Combined (0.15)
X-Recommended-Action: accept

4

Re: Spammer sent email with FOR meta

reject_sender_login_mismatch
fix the problem