    Rackshack and Spam

    Hi everyone,

    I had an experience with Rackshack that I need some advice on.

    For the past several days, I have been getting 200-300 emails from AOL that looked like they were spam attempts from my formmail. So I updated to the latest NMS-Formmail script, but they didn't stop. Here is what happened:

    I used to own a Rackshack server at I was amazed to see that my site for was still up at that site, even though I left that server behind last March. That server still had the old Matt Wright formmail script 1.6, and spammers were using it relentlessly. AOL was returning email to me, thinking it had come from my site.

    At this point, I want to know how I can find out if I have been spamdexed due to Rackshack's making my old site accessible, and if so what steps to take from there. My domain is my main email, and very important to me.

    Here is a typical letter from AOL. Again, I would receive hundreds of these a day:

    The original message was received at Mon, 7 Oct 2002 08:32:23 -0400 (EDT)
    from []

    *** ATTENTION ***

    Your e-mail is being returned to you because there was a problem with its
    delivery. The address which was undeliverable is listed in the section
    labeled: "----- The following addresses had permanent fatal errors -----".

    The reason your mail is being returned to you is listed in the section
    labeled: "----- Transcript of Session Follows -----".

    The line beginning with "<<<" describes the specific reason your e-mail could
    not be delivered. The next line contains a second error message which is a
    general translation for other e-mail servers.

    Please direct further questions regarding this message to your e-mail

    --AOL Postmaster

    ----- The following addresses had permanent fatal errors -----
    <[email protected]>
    <[email protected]>

    ----- Transcript of session follows -----
    ... while talking to
    >>> RCPT To:<[email protected]>
    550 <[email protected]>... User unknown
    >>> RCPT To:<[email protected]>
    550 <[email protected]>... User unknown

    I'd request a copy of the current and past maillog from the machine, so you can review it. If you have low or no logging, too bad.
    Just a quick note, but it sounds more like its due to your domain being used in spam rather than the actual box... if your receiving hundreds per day that you didn't send...

    If you sent them and there bounced back, it does sound likely your blacklisted...

    No, if you read the message from AOL, it says those AOL boxes are

    So, I would assume they are connecting to your old box via the IP, taking advantage of that bugged script, and all mailer daemon messages are coming back to your main domain address.

    maybe troubleticket rackshack and have them kill the old server? Weird that that happened, I thought they killed servers like same week?


    Yeah, it appears that I am relatively safe from being blacklisted, as the emails were being forwarded to me from the old box, and not direct from AOL. But I am still a little concerned, not sure where I would check. Any ideas?

    And I am disappointed in Rackshack for leaving my old box online. Even aside from formmail problems, I don't think anyone wants unupdated "ghosts" up of their various sites at their former IP address.

    One thought I had after this was to be extra cautious in using certain scripts for domains that are crucial to you for email. At first I thought that spammers had cracked NMS Formmail, which could have had me blacklisted even though I was up to date with the right version.

    This whole business of using other people's servers for spam is really, really low.

