Web Hosting Talk


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Spammers ruining my server
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)

 
Thread Tools Search this Thread Display Modes
  #1  
Old 08-09-2007, 03:35 PM
servitium servitium is offline
View Beta Profile
New Member
 
Join Date: Jun 2006
Posts: 2
Exclamation Spammers ruining my server

I just opened my "catch-all" email pop account that sends me everything addressed to my server that doesn't have an assigned email address. I check it every few days.

Over 4,500 undeliverables. Someone is using mydomain as a phony return address in different forms (gleskit@mydomain.com, peterepred@mydomain.com etc.) If I got over 4,500 undeliverables, these lowlife creeps must have sent innumerable thousands or tens of thousands using my domain as a return address.

What really stinks is that I've had a bunch of users complain that they're not getting usual auto-messages from my forum software. Come to find out that my domain is now banned from at least one major ISP, I'm guessing probably more by now.

The website I run depends heavily on VOLUNTARY auto-communications and updates. For example, one mailing list I maintain have over 4,800 members who've signed up for updates. It uses other feeds and email functions as well.

Am I to understand that any jackass spammer can hose a server this way, with no redress on the part of the innocent party? Also, how am I going to get back in the good graces of the ISPs and personal anti-spam programs that have now blacklisted my server for no reason?

Besides contacting all of the larger ones personally, I wouldn't even know where to begin addressing this.

Is it possible that some nasty geek with a spam program can just ruin a server in this fashion?

Just checked the account again.

In the ten minutes it took me to write the above post, I just got 54 more undeliverables.

This is insane.


Last edited by sirius; 08-09-2007 at 03:43 PM.
Reply With Quote
Sponsored Links
  #2  
Old 08-09-2007, 03:43 PM
sirius sirius is online now
View Beta Profile
Community Liaison 2.0
 
Join Date: Nov 2002
Location: WebHostingTalk
Posts: 7,231
* Moved to Technical and Security Issues....

Sirius

__________________
I support the Human Rights Campaign and kiva.org - Loans that change lives!
Together, we can make a difference. Hosting For Haiti - 100% of donations go to the American Red Cross Haiti Relief and Development Fund.

Reply With Quote
  #3  
Old 08-09-2007, 03:52 PM
HellFear HellFear is offline
View Beta Profile
Newbie
 
Join Date: May 2004
Posts: 11
This same problem happened to me also one time. It's because people were registering on my website with wrong e-mail addresses, and the confirmation e-mails kept getting sent back to me. I guess it's a different problem with yours. Someone is using your domain e-mails to spam right? This really sucks. I would wait a day or two and see if it stops. Maybe the IP address of the sender is in the headers??

Reply With Quote
Sponsored Links
  #4  
Old 08-09-2007, 05:02 PM
Website Rob Website Rob is offline
View Beta Profile
learning is in the doing
 
Join Date: Sep 2000
Location: Alberta, Canada
Posts: 3,108
Don't use the 'catch-all' settings!

Your default address should be: :fail: no such address here
That will return any/all eMail not sent to an address you have created. Also prevents you from receiving eMail sent to phony addresses using your Domain name.

Setup Mailboxes for the addresses you will actually be using. After all, why receive eMail to an address you have not setup / don't use?

__________________
PotentProducts.com - for all your Hosting needs
Helping people Host, Create and Maintain their Web Site
ServerAdmin Services also available

Reply With Quote
  #5  
Old 08-09-2007, 05:11 PM
ballin ballin is offline
View Beta Profile
New Member
 
Join Date: Aug 2007
Posts: 4
Sounds like your domain is being "spoofed'

Start by removing your "catch-all" like Website Rob said

Then, for the ISP blocks, most the major companies have a place to contact them to request to be removed from their blacklist. Explain to them that your domain has been 'spoofed' and you removed the 'catch-all'.

Reply With Quote
  #6  
Old 08-09-2007, 07:10 PM
SmartTux SmartTux is offline
View Beta Profile
Junior Guru
 
Join Date: Dec 2004
Posts: 223
Add SPF record for your domain.. It can be used to check if an email received with your domain in From field is a forged mail or not.
Some mail servers accept emails from your domain only if it has SPF record.

Reply With Quote
  #7  
Old 08-09-2007, 07:37 PM
servitium servitium is offline
View Beta Profile
New Member
 
Join Date: Jun 2006
Posts: 2
I guess it was naive of me to have that "catchall" address instead of just booting everything back. The reason I had it was in case someone mis-typed an email address.

I'm looking into SPF right now.

You guys have been a great help.

Blessings

Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement: