<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: What to do about someone spoofing my email?</title>
	<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email/</link>
	<description>Comments on Ask MetaFilter post What to do about someone spoofing my email?</description>
	<pubDate>Tue, 18 Apr 2006 10:05:25 -0800</pubDate>
	<lastBuildDate>Tue, 18 Apr 2006 10:05:25 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: What to do about someone spoofing my email?</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email</link>	
		<description>Recently I have been getting emails from my domain bounced back to me from other peoples&apos; automated anti-spam catchers. The problem is that I am not sending these emails... &lt;br /&gt;&lt;br /&gt; I own my own domain but use gmail as my main email. As such I have a catchall that delivers any email from my domain to my gmail account.  Lately i&apos;ve been getting emails bounced back that say they were sent from salesATuntuckedshirts.com which I don&apos;t use.  The email headers look like this:&lt;br&gt;
&lt;br&gt;
From: Servage Antispam System &lt;antispam @servage.net&gt;	&lt;br&gt;
Reply-To: antispam@servage.net&lt;br&gt;
To: salesATuntuckedshirts.com&lt;br&gt;
Date: Apr 4, 2006 3:21 PM&lt;br&gt;
Subject: Autoreply: Ever tried that?&lt;br&gt;
&lt;br&gt;
I don&apos;t think anyone actually has access to my dreamhost account so could this just but somone &quot;spoofing&quot; my address? I don&apos;t know exactly how that works but i&apos;ve heard it&apos;s possible.&lt;/antispam&gt;</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2006:site.36563</guid>
		<pubDate>Tue, 18 Apr 2006 10:02:48 -0800</pubDate>
		<dc:creator>untuckedshirts</dc:creator>
		
			<category>email</category>
		
			<category>spam</category>
		
	</item> <item>
		<title>By: bhance</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567068</link>	
		<description>This is commonly referred to as a &apos;&lt;a href=&quot;http://en.wikipedia.org/wiki/Joe_job&quot;&gt;joe job&lt;/a&gt;&apos;. Little to nothing you can do about it, although posting full headers might help trace the real source.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567068</guid>
		<pubDate>Tue, 18 Apr 2006 10:05:25 -0800</pubDate>
		<dc:creator>bhance</dc:creator>
	</item><item>
		<title>By: unixrat</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567081</link>	
		<description>See also &lt;a href=&quot;http://ask.metafilter.com/mefi/13788&quot;&gt;previously&lt;/a&gt; and &lt;a href=&quot;http://ask.metafilter.com/mefi/30796&quot;&gt;previously&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
In short, nothing you can really do about it except hunker down and wait it out.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567081</guid>
		<pubDate>Tue, 18 Apr 2006 10:18:19 -0800</pubDate>
		<dc:creator>unixrat</dc:creator>
	</item><item>
		<title>By: unixrat</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567087</link>	
		<description>FWIW, I&apos;ve noticed that my domains hosted on DH seem to get jobbed slightly more than average.  My pet theory is that jobbers use DH domains because of the good reputation of DH and the less likely for one of their domains to be blacklisted.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567087</guid>
		<pubDate>Tue, 18 Apr 2006 10:20:44 -0800</pubDate>
		<dc:creator>unixrat</dc:creator>
	</item><item>
		<title>By: cribcage</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567091</link>	
		<description>Ditto, nothin&apos; you can do. But it might help you to know that you&apos;re not alone, toward which I&apos;ll offer that it happens to me a couple of times a year. You learn to treat the bounces just like regular spam.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567091</guid>
		<pubDate>Tue, 18 Apr 2006 10:28:38 -0800</pubDate>
		<dc:creator>cribcage</dc:creator>
	</item><item>
		<title>By: hattifattener</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567098</link>	
		<description>Minor terminology question: I thought a &quot;joe job&quot; was when the spammer is spoofing your address (or linking to your website in the spam, or whatever) specifically to get you in trouble. People who run anti-spammer sites tend to get joe-jobbed, for example. This sounds more like the spammer is spoofing untuckedshirts&apos; address  just because they needed a plausible source address and they randomly picked untuckedshirts --- they have no specific desire to draw attention there, as long as they draw attention away from the actual spam source. Do other people make this same distinction?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567098</guid>
		<pubDate>Tue, 18 Apr 2006 10:44:52 -0800</pubDate>
		<dc:creator>hattifattener</dc:creator>
	</item><item>
		<title>By: drstein</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567102</link>	
		<description>hattifattner: They&apos;re pretty much the same thing. Often times spammers aren&apos;t even aware that they&apos;re doing this, because the spam-software they&apos;re using is filling in the blanks for them.&lt;br&gt;
&lt;br&gt;
Sad but true fact. :-(</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567102</guid>
		<pubDate>Tue, 18 Apr 2006 10:50:08 -0800</pubDate>
		<dc:creator>drstein</dc:creator>
	</item><item>
		<title>By: COD</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567108</link>	
		<description>I would kill the catch all account and only forward the addresses that you actually use. Everything else should either bounce or drop at the server. This will at least minimize the number of bounces that you have to look at.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567108</guid>
		<pubDate>Tue, 18 Apr 2006 10:54:03 -0800</pubDate>
		<dc:creator>COD</dc:creator>
	</item><item>
		<title>By: kindall</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567114</link>	
		<description>It&apos;s pretty easy to filter out most of these bounces at the server level, assuming they are being sent to random e-mail addresses at your domain and you&apos;re getting them because you have a catch-all.&lt;br&gt;
&lt;br&gt;
Return-Path is &lt;&gt; (i.e. this is a bounce)&lt;br&gt;
Message-ID does not contain @ (i.e. no message ID)&lt;br&gt;
To is not your@real-email-address (i.e. it&apos;s to one of your catchalls)&lt;br&gt;
&lt;br&gt;
(If spammers would just send messages out with an empty return-path to begin with, nobody would have to deal with the bounces, because there wouldn&apos;t be any.)&lt;/&gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567114</guid>
		<pubDate>Tue, 18 Apr 2006 10:57:30 -0800</pubDate>
		<dc:creator>kindall</dc:creator>
	</item><item>
		<title>By: camworld</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567131</link>	
		<description>Agree about the catch-all; it should be disabled. It is also vulnerable to a dictionary spam attack where the spammer simply tries sending email to every word in the dictionary at your domain. I once received over 100,000 pieces of spam in a single day from some spammer who tried this and I had a catch-all in place.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567131</guid>
		<pubDate>Tue, 18 Apr 2006 11:11:48 -0800</pubDate>
		<dc:creator>camworld</dc:creator>
	</item><item>
		<title>By: mkultra</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567149</link>	
		<description>Another vote to ditch the catch-all. I had it in place (at DH) for years, and it was great for site-specific addresses (amazon@, mefi@), but joe-jobbing killed it for me.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567149</guid>
		<pubDate>Tue, 18 Apr 2006 11:36:07 -0800</pubDate>
		<dc:creator>mkultra</dc:creator>
	</item><item>
		<title>By: untuckedshirts</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567165</link>	
		<description>mkultra: yeah the site specific email addresses is why I have the catch-all in the first place. In theory it was meant to cut down on spam, the idea being that each website that requires a registration would get their own ****ATuntuckedshirts.com email address so that if I started to get spam from a site I registered for I could just have that address go to the trash.&lt;br&gt;
&lt;br&gt;
It made sense to me at the time but there are other ways to do it and it looks like now is the time.&lt;br&gt;
&lt;br&gt;
What I worry about is that if these companies have my end of the road gmail account and are spamming it directly there is little I can do as they generally switch up where the email is coming from, etc.&lt;br&gt;
&lt;br&gt;
Thanks for the prompt replies.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567165</guid>
		<pubDate>Tue, 18 Apr 2006 12:10:25 -0800</pubDate>
		<dc:creator>untuckedshirts</dc:creator>
	</item><item>
		<title>By: mkultra</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567190</link>	
		<description>As far as site-specific spam goes, I actually found that I got little or no spam from individual sites where I had registered. If I was getting any, it was certainly getting lost in the torrent of 200+ daily emails to &apos;randomname@greenlightgo.com&apos;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567190</guid>
		<pubDate>Tue, 18 Apr 2006 13:00:27 -0800</pubDate>
		<dc:creator>mkultra</dc:creator>
	</item><item>
		<title>By: tomble</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567588</link>	
		<description>This is happening to me too, right now.  I hate those spamming bastards.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567588</guid>
		<pubDate>Tue, 18 Apr 2006 22:04:26 -0800</pubDate>
		<dc:creator>tomble</dc:creator>
	</item><item>
		<title>By: freshgroundpepper</title>
		<link>http://ask.metafilter.com/36563/What-to-do-about-someone-spoofing-my-email#567611</link>	
		<description>Yeah, this really sucks.  It started about a week ago for me.  I&apos;ve had my own domain for about 5 years now and I&apos;ve been using it the same way as you (amazon@blah, mefi@blah, etc.).  This is the first time this has happened to me and it was very confusing at first.&lt;br&gt;
&lt;br&gt;
I use outlook to grab my catchall as well as a number of &quot;defined&quot; e-mail addresses from my domain.  I threw together this outlook rule and it seems to be taking care of the majority of bounced spam coming in.  I&apos;m just hoping my domain doesn&apos;t get blacklisted before this is over.&lt;br&gt;
&lt;br&gt;
Apply this rule after the message arrives with &quot;postmaster&quot; or &quot;Delivery&quot; or &quot;DAEMON&quot; or &quot;undeliverable&quot; in the sender&apos;s address&lt;br&gt;
delete it&lt;br&gt;
and mark it as read&lt;br&gt;
except with &quot;real name 1&quot; or &quot;realAddress2&quot; or ...&quot;realAddress5&quot; in the recipient&apos;s address.&lt;br&gt;
&lt;br&gt;
This seems to remove about 98% of the bad stuff so that I&apos;m back to only a couple sneaking through in a day.  I should also recieve any real bouncbacks with this in place as I&apos;m keeping any bouncebacks with my real name/address in them.&lt;br&gt;
&lt;br&gt;
Hopefully they&apos;ll move on to another address soon.  &lt;br&gt;
&lt;br&gt;
I&apos;m normally anti-death penalty, but I&apos;m reconsidering my stance when it comes to these bastards.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.36563-567611</guid>
		<pubDate>Tue, 18 Apr 2006 23:15:37 -0800</pubDate>
		<dc:creator>freshgroundpepper</dc:creator>
	</item>
	</channel>
</rss>
