<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Stopping Spoofing Spammers</title>
	<link>http://ask.metafilter.com/4708/Stopping-Spoofing-Spammers/</link>
	<description>Comments on Ask MetaFilter post Stopping Spoofing Spammers</description>
	<pubDate>Sat, 17 Jan 2004 13:10:32 -0800</pubDate>
	<lastBuildDate>Sat, 17 Jan 2004 13:10:32 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Stopping Spoofing Spammers</title>
		<link>http://ask.metafilter.com/4708/Stopping-Spoofing-Spammers</link>	
		<description>Anyone care to drop some knowledge about stopping spammers from spoofing your address? [more] &lt;br /&gt;&lt;br /&gt; So, a company I do consulting work for seems to have a problem with a spammer spoofing their email address in either the &quot;from&quot; or the &quot;reply to&quot; field of their spam, as evidenced by the large amount of bounced mail they seem to be receiving. I&apos;m pretty sure it&apos;s not a virus or trojan, as I spent a good amount of time scrubbing their computers for culprits, and have found nothing. What can you do in this situation? If we are able to track them down, could we file in small claims court?</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2004:site.4708</guid>
		<pubDate>Sat, 17 Jan 2004 13:00:33 -0800</pubDate>
		<dc:creator>Hackworth</dc:creator>
		
			<category>spam</category>
		
			<category>spammers</category>
		
			<category>firewalls</category>
		
			<category>security</category>
		
			<category>internetsecurity</category>
		
			<category>hacking</category>
		
			<category>spoofing</category>
		
			<category>phishing</category>
		
			<category>zombies</category>
		
	</item> <item>
		<title>By: fvw</title>
		<link>http://ask.metafilter.com/4708/Stopping-Spoofing-Spammers#106422</link>	
		<description>They&apos;re probably operating from some east asian country, or from a proxy there. Rather little you can do, but is it a big problem? They usually use addresses at your domain that don&apos;t exist, and even if they do, filtering out the spam bounces isn&apos;t that hard. Your ISP might get a few abuse reports from misguided people thinking the spam is coming from you, but any halfway competent ISP will see it&apos;s just a few spoof headers.&lt;br&gt;
&lt;br&gt;
In the long run, &lt;a href=&quot;http://spf.pobox.com/&quot;&gt;SPF&lt;/a&gt; might save us all.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.4708-106422</guid>
		<pubDate>Sat, 17 Jan 2004 13:10:32 -0800</pubDate>
		<dc:creator>fvw</dc:creator>
	</item><item>
		<title>By: adamrice</title>
		<link>http://ask.metafilter.com/4708/Stopping-Spoofing-Spammers#106424</link>	
		<description>It&apos;s worth mentioning that there are viruses that spoof your e-mail address from someone else&apos;s infected machine--if that machine has your address in its address book, you&apos;re fair game.&lt;br&gt;
&lt;br&gt;
Some of these virus do mashup addresses, such as bobsaccount@alicesdomain.com</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.4708-106424</guid>
		<pubDate>Sat, 17 Jan 2004 13:16:19 -0800</pubDate>
		<dc:creator>adamrice</dc:creator>
	</item><item>
		<title>By: Zonker</title>
		<link>http://ask.metafilter.com/4708/Stopping-Spoofing-Spammers#106454</link>	
		<description>Much of this spam is sent &lt;em&gt;through&lt;/em&gt; Asian relays, but that doesn&apos;t mean it&apos;s coming &lt;em&gt;from&lt;/em&gt; Asia.  The vast majority of it is originated by one of a fairly small number of U.S.-based spammers.  If your client and its problem are both big enough, it may be worth suing them here in the U.S.  Check out &lt;a href=&quot;http://www.spamhaus.org/rokso/index.lasso&quot; title=&quot;The Spamhaus Project&apos;s Register of Known Spam Operations&quot;&gt;ROSKO&lt;/a&gt; for a good source of leads, or search the news.admin.net-abuse.email forum (&quot;nanae&quot;) on Usenet  (&lt;a href=&quot;http://groups.google.com/groups?hl=en&amp;lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;group=news.admin.net-abuse.email&quot;&gt;Google Groups&lt;/a&gt; is a good place to search it) for names that appear in the spam.&lt;br&gt;
&lt;br&gt;
And like &lt;strong&gt;fvw&lt;/strong&gt; said, use SPF.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.4708-106454</guid>
		<pubDate>Sat, 17 Jan 2004 14:38:34 -0800</pubDate>
		<dc:creator>Zonker</dc:creator>
	</item><item>
		<title>By: wendell</title>
		<link>http://ask.metafilter.com/4708/Stopping-Spoofing-Spammers#106456</link>	
		<description>I was personally surprised to find somebody had done this to my Yahoo Mail account, dumping several hundred rejection notices in my regular inbox and bulk box over a couple days. I notified the authoritative Yahoos (just to make sure they didn&apos;t blame me for sending out Paris Hilton Porn Spam) more than a month ago, it went away, and then it has come back in small bunches of 10-25 every few days.  If the Yahoos can&apos;t (or won&apos;t) get a handle on the problem, who will?&lt;br&gt;
&lt;br&gt;
I&apos;ll take some SPF-400 in a cocoa butter base, please...</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.4708-106456</guid>
		<pubDate>Sat, 17 Jan 2004 14:43:43 -0800</pubDate>
		<dc:creator>wendell</dc:creator>
	</item><item>
		<title>By: Hackworth</title>
		<link>http://ask.metafilter.com/4708/Stopping-Spoofing-Spammers#106678</link>	
		<description>well, crap.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.4708-106678</guid>
		<pubDate>Sun, 18 Jan 2004 11:49:29 -0800</pubDate>
		<dc:creator>Hackworth</dc:creator>
	</item>
	</channel>
</rss>
