<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

      <title>Comments on: How can we stop spammers from using our domain?</title>
      <link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain/</link>
      <description>Comments on Ask MetaFilter post How can we stop spammers from using our domain?</description>
	  	  <pubDate>Sun, 06 Nov 2005 07:46:55 -0800</pubDate>
      <lastBuildDate>Sun, 06 Nov 2005 07:46:55 -0800</lastBuildDate>
      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>

<item>
  	<title>Question: How can we stop spammers from using our domain?</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain</link>	
  	<description>I think someone is using our domain name to send spam from. What can I do about this? Our catch-all email account has been getting hundreds of &quot;mail delivery failed&quot; messages, which appear to have been sent from non-existant email addresses on our domain to all sorts of regular email addresses (like &lt;a href=&quot;http://www.thefudgesaidno.com/ugh.txt&quot;&gt;this&lt;/a&gt;). The emails are regular spam: MBAs, rolexes, viagra, etc. &lt;br&gt;
&lt;br&gt;
I don&apos;t really want our domain blacklisted as spam. What can we do about it?</description>
  	<guid isPermaLink="false">post:ask.metafilter.com,2008:site.26725</guid>
  	<pubDate>Sun, 06 Nov 2005 07:36:53 -0800</pubDate>
  	<dc:creator>Count Ziggurat</dc:creator>
	
	<category>spam</category>
	
	<category>ugh</category>
	
</item>
<item>
  	<title>By: tyllwin</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421339</link>	
  	<description>Do you have the headers from a couple of the bounced messages? If they&apos;re simply forging your domain name into the &amp;quot;from&amp;quot; field there&apos;s not much you can do about it. Tale a look at &lt;a href=&quot;http://members.cox.net/joejob/&quot;&gt;http://members.cox.net/joejob/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
The real worry is that they may also be using your org&apos;s mail SERVERS as an open relay. THAT you can stop.</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421339</guid>
  	<pubDate>Sun, 06 Nov 2005 07:46:55 -0800</pubDate>
  	<dc:creator>tyllwin</dc:creator>
</item>
<item>
  	<title>By: andrew cooke</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421342</link>	
  	<description>see &lt;a href=&quot;http://ask.metafilter.com/mefi/17335&quot;&gt;here&lt;/a&gt; (it appears to be slightly different, but the answers cover this case too)</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421342</guid>
  	<pubDate>Sun, 06 Nov 2005 07:49:24 -0800</pubDate>
  	<dc:creator>andrew cooke</dc:creator>
</item>
<item>
  	<title>By: Sharcho</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421345</link>	
  	<description>Catch-all accounts==a lot of spam&lt;br&gt;
You shouldn&apos;t be using them.</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421345</guid>
  	<pubDate>Sun, 06 Nov 2005 07:57:49 -0800</pubDate>
  	<dc:creator>Sharcho</dc:creator>
</item>
<item>
  	<title>By: cillit bang</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421357</link>	
  	<description>Spammers can put any text they like in the from field and there&apos;s nothing you can do about it.</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421357</guid>
  	<pubDate>Sun, 06 Nov 2005 08:19:44 -0800</pubDate>
  	<dc:creator>cillit bang</dc:creator>
</item>
<item>
  	<title>By: WestCoaster</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421375</link>	
  	<description>&lt;em&gt;Spammers can put any text they like in the from field and there&apos;s nothing you can do about it.&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
Correct, but the domain won&apos;t be blacklisted because of that.  Blacklisting occurs because mail truly originates from the domain, as shown in the headers.&lt;br&gt;
&lt;br&gt;
(Think of &amp;quot;from&amp;quot; addresses as what someone could put as a return address on the outside of a envelope being sent via the U.S. Postal Service.  If someone else decides to write your name and address as the return address, there isn&apos;t much that you can do about it.  But the post office isn&apos;t going to stop accepting your outgoing mail if someone in (say) Alaska is writing your address on their outgoing mail.)</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421375</guid>
  	<pubDate>Sun, 06 Nov 2005 08:45:32 -0800</pubDate>
  	<dc:creator>WestCoaster</dc:creator>
</item>
<item>
  	<title>By: Count Ziggurat</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421428</link>	
  	<description>&lt;blockquote&gt;&lt;i&gt;Hi. This is the qmail-send program at smp.voyagerco.com.&lt;br&gt;
I&apos;m afraid I wasn&apos;t able to deliver your message to the following addresses.&lt;br&gt;
This is a permanent error; I&apos;ve given up. Sorry it didn&apos;t work out.&lt;br&gt;
&lt;br&gt;
&lt;weaver @voyagerco.com&gt;:&lt;br&gt;
Sorry, no mailbox here by that name. vpopmail (#5.1.1)&lt;br&gt;
&lt;br&gt;
--- Below this line is a copy of the message.&lt;br&gt;
&lt;br&gt;
Return-Path: &lt;dbeltranyj @thefudgesaidno.com&gt;&lt;br&gt;
Received: (qmail 16319 invoked from network); 6 Nov 2005 16:48:34 -0000&lt;br&gt;
Received: from 201-1-39-233.dsl.telesp.net.br (HELO mmm2.com) (201.1.39.233)&lt;br&gt;
 by smp.voyagerco.com with SMTP; 6 Nov 2005 16:48:34 -0000&lt;br&gt;
Message-ID: &lt;dopjnomhmfjplmfmmjlacmdhdcaa .dbeltranyj@thefudgesaidno.com&gt;&lt;br&gt;
From: &amp;quot;Dennis Beltran&amp;quot; &lt;dbeltranyj @thefudgesaidno.com&gt;&lt;br&gt;
Subject: =?ISO-8859-1?b?UGFzc2VkIHVwLCBhZ2Fpbj8=?=&lt;br&gt;
Date: Sun, 06 Nov 2005 16:44:10 +0000&lt;br&gt;
MIME-Version: 1.0&lt;br&gt;
X-Sender: &lt;dbeltranyj @thefudgesaidno.com&gt;&lt;br&gt;
In-Reply-To: &lt;e7 5201c5df30$6d858865$264c134f@asnhgcr&gt;&lt;br&gt;
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2800.1106&lt;br&gt;
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)&lt;br&gt;
Content-Type: text/plain;&lt;br&gt;
       charset=&amp;quot;us-ascii&amp;quot;&lt;br&gt;
Content-Transfer-Encoding: 8bit&lt;br&gt;
&lt;br&gt;
Hey there,&lt;br&gt;
UNIVERSITY DIPLOMAS&lt;br&gt;
Receive a successful future, money-earning power, and the prestige that comes with having the position and career you have always dreamed of!&lt;br&gt;
Diplomas from universities based on your present knowledge and life experience.&lt;br&gt;
If you qualify, no classes, books, examinations or tests!&lt;br&gt;
Degrees available.&lt;br&gt;
Bachelors&lt;br&gt;
Masters&lt;br&gt;
MBAs&lt;br&gt;
Doctorate&lt;br&gt;
PhD.&lt;br&gt;
Confidentiality assured!&lt;br&gt;
CALL RIGHT N0W to receive your diploma within two weeks!&lt;br&gt;
(313)772.7099&lt;/e7&gt;&lt;/dbeltranyj&gt;&lt;/dbeltranyj&gt;&lt;/dopjnomhmfjplmfmmjlacmdhdcaa&gt;&lt;/dbeltranyj&gt;&lt;/weaver&gt;&lt;/i&gt;&lt;/blockquote&gt;&lt;br&gt;
Whois from mmm2.com:&lt;br&gt;
&lt;blockquote&gt;&lt;i&gt;Domain Name.......... mmm2.com&lt;br&gt;
  Creation Date........ 2003-02-15&lt;br&gt;
  Registration Date.... 2003-02-15&lt;br&gt;
  Expiry Date.......... 2006-02-15&lt;br&gt;
  Organisation Name.... HARUNOBU YAMAMOTO&lt;br&gt;
  Organisation Address. Kamihukuoka-shi&lt;br&gt;
  Organisation Address. &lt;br&gt;
  Organisation Address. Saitama-ken&lt;br&gt;
  Organisation Address. 356-0005&lt;br&gt;
  Organisation Address. Saitama-ken&lt;br&gt;
  Organisation Address. JAPAN&lt;br&gt;
&lt;br&gt;
Admin Name........... HARUNOBU YAMAMOTO&lt;br&gt;
  Admin Address........ Kamihukuoka-shi&lt;br&gt;
  Admin Address........ &lt;br&gt;
  Admin Address........ Saitama-ken&lt;br&gt;
  Admin Address........ 356-0005&lt;br&gt;
  Admin Address........ Saitama-ken&lt;br&gt;
  Admin Address........ JAPAN&lt;br&gt;
  Admin Email.......... halhalha@rd6.so-net.ne.jp&lt;br&gt;
  Admin Phone.......... 049-264-1829&lt;br&gt;
  Admin Fax............ &lt;br&gt;
&lt;br&gt;
Tech Name............ HARUNOBU YAMAMOTO&lt;br&gt;
  Tech Address......... Kamihukuoka-shi&lt;br&gt;
  Tech Address......... &lt;br&gt;
  Tech Address......... Saitama-ken&lt;br&gt;
  Tech Address......... 356-0005&lt;br&gt;
  Tech Address......... Saitama-ken&lt;br&gt;
  Tech Address......... JAPAN&lt;br&gt;
  Tech Email........... halhalha@rd6.so-net.ne.jp&lt;br&gt;
  Tech Phone........... 049-264-1829&lt;br&gt;
  Tech Fax............. &lt;br&gt;
  Name Server.......... ns1.alphastyle.jp&lt;br&gt;
  Name Server.......... ns2.alphastyle.jp&lt;/i&gt;&lt;/blockquote&gt;Herm.</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421428</guid>
  	<pubDate>Sun, 06 Nov 2005 09:55:07 -0800</pubDate>
  	<dc:creator>Count Ziggurat</dc:creator>
</item>
<item>
  	<title>By: gemmy</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421501</link>	
  	<description>Pretty much anyone who uses email has had this happen to them, and there is not much you can do about it.&lt;br&gt;
&lt;br&gt;
Sometimes, if I keep getting consistent messages that are from the same IP address, I will contact the ISP that has control of that IP address and complain. Sometimes it works and it will stop, but most of the time it does not...</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421501</guid>
  	<pubDate>Sun, 06 Nov 2005 11:53:19 -0800</pubDate>
  	<dc:creator>gemmy</dc:creator>
</item>
<item>
  	<title>By: intermod</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421552</link>	
  	<description>In looking at mail headers, usually it&apos;s the very first (bottommost) &amp;quot;Received&amp;quot; header that tells you where the email originated:&lt;br&gt;
&lt;br&gt;
&lt;em&gt;Received: from 201-1-39-233.dsl.telesp.net.br&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
Came from a DSL connected computer in Brazil, probably a zombie, using MS Outlook.  I don&apos;t know enough about headers to say whether the mmm2.com is relevant.  You might be barking up the wrong tree with that one.&lt;br&gt;
&lt;br&gt;
Anyway, forged From headers are cake for spammers.  You just have to ignore it.  Usually your spam filter (or your ISPs) will catch on quick enough and you&apos;ll stop seeing the bounces.</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421552</guid>
  	<pubDate>Sun, 06 Nov 2005 13:18:55 -0800</pubDate>
  	<dc:creator>intermod</dc:creator>
</item>
<item>
  	<title>By: Malor</title>
  	<link>http://ask.metafilter.com/26725/How-can-we-stop-spammers-from-using-our-domain#421585</link>	
  	<description>When this happened to me, from my tiny vanity domain, I of course got a hurricane of bounces, and some complaints and unsubscribe requests... which of course I couldn&apos;t honor, since I wasn&apos;t actually sending the mail.  All I could do was apologize and explain, which got old. &lt;br&gt;
&lt;br&gt;
I&apos;ve implemented SPF(Sender Permitted From) on my domain now... that&apos;s a special record that goes into the DNS that says &amp;quot;mail is allowed to originate for this domain from these addresses.&amp;quot;   I haven&apos;t had the problem since... though of course correlation doesn&apos;t imply causation.&lt;br&gt;
&lt;br&gt;
It&apos;s not hard to do this at all, but you do have to have the ability to manually edit your own DNS files.  You need to add a TXT record for your domain.   The syntax for this TXT record is kind of complex, but there are websites out there that will ask you some questions about how you want your SPF configured, and then generate the right line for you.  &lt;br&gt;
&lt;br&gt;
The line I use is:&lt;br&gt;
&lt;br&gt;
example.com              IN      TXT     &amp;quot;v=spf1 mx&amp;quot;&lt;br&gt;
&lt;br&gt;
That means &apos;record type SPF1, allow mail from mailservers for this domain&apos;.   &lt;br&gt;
&lt;br&gt;
This means that by listing an MX record for your domain:&lt;br&gt;
&lt;br&gt;
example.com     IN      MX      10 mail.example.com.&lt;br&gt;
&lt;br&gt;
And listing an IP address for mail.example.com:&lt;br&gt;
&lt;br&gt;
mail.example.com    IN   A 127.0.0.1&lt;br&gt;
&lt;br&gt;
That will A) have incoming mail go to mail.example.com, and B) allow outgoing mail to be sent from that IP address.  &lt;br&gt;
&lt;br&gt;
This only works if the recipient domains do SPF checking, but the big guys mostly do this now.  So just by listing a valid SPF record, you make your domain a lot less interesting for joe jobs.</description>
  	<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.26725-421585</guid>
  	<pubDate>Sun, 06 Nov 2005 14:04:49 -0800</pubDate>
  	<dc:creator>Malor</dc:creator>
</item>

    </channel>
</rss>
