Discussion:
Spam from .us domains
Philip Parsons
2014-05-02 14:57:06 UTC
Permalink
Is anyone else getting hammered by spam saying it is from .us domains ? If have you figured a way to stop it yet ?

Thank you
P Parsons
Terry Hulen Jr
2014-05-02 15:32:01 UTC
Permalink
We are not getting hammered at the moment. What are your spam
assassin results? What are the sizes of the messages? Do you have
RBLs set?
Post by Philip Parsons
Is anyone else getting hammered by spam saying it is from .us domains ? If have you figured a way to stop it yet ?
Thank you
P Parsons
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
Philip Parsons
2014-05-02 16:38:08 UTC
Permalink
There is only one rule that is triggerd KAM_INFOUSMEBIZ Yes I have RBLs set and they are not on any lists and the size of the message ? it is small just txt.. example below..

From: Checking Account [mailto:CheckingAccount at try-somewonderfuldealz.us]
Sent: Friday, May 02, 2014 4:12 AM
Subject: Been-denied for a checking account? We will approve-you


Second Chance Checking Account
----------------------------------

Have you been denied for a bank account because of credit issues?

Everyone needs a checking account...We accepts all applicants!


Go here to find out more: http://host.try-somewonderfuldealz.us




-----Original Message-----
From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Terry Hulen Jr
Sent: May-02-14 8:32 AM
To: MailScanner discussion
Subject: Re: Spam from .us domains

We are not getting hammered at the moment. What are your spam
assassin results? What are the sizes of the messages? Do you have
RBLs set?
Post by Philip Parsons
Is anyone else getting hammered by spam saying it is from .us domains ? If have you figured a way to stop it yet ?
Thank you
P Parsons
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.
Jerry Benton
2014-05-02 16:15:26 UTC
Permalink
Got a sample header?
Post by Philip Parsons
Is anyone else getting hammered by spam saying it is from .us domains ?
If have you figured a way to stop it yet ?
Thank you
P Parsons
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
--
--
Jerry Benton
Mailborder Systems
www.mailborder.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140502/566fc9e1/attachment.html
Paul A Sand
2014-05-02 16:42:30 UTC
Permalink
Post by Philip Parsons
Is anyone else getting hammered by spam saying it is from .us domains ?
If have you figured a way to stop it yet ?
I?ve noticed an uptick, but the IPs seem to get listed by SpamHaus
pretty quickly, so the damage here is minor.
There?s (of course) a lot of valid mail ending in .us.

For those of us who are easily amused, a random sample of domains:

buildyournew-shednow.us
getmoney-whenyouneedto.us
trythisnew-kindoftubnow.us
younewrate-drop-info.us
yourecentpolicy-notice.us
yourmustsee-autodealz.us
yournewvision-healthinfo.us

We?re also seeing the same sort of thing from the .me TLD (Montenegro), but
the naming algorithm differs. Some hostnames:

algal.futureexplain.me
allseed.wrongwisdom.me
fumingly.wetpicture.me
interwarring.warmrake.me
otoneurasthenia.cleandustpan.me
polyploidy.amongstalk.me
resought.bentwasher.me
toyless.hangingexperience.me

A toyless hanging experience? Does not sound like fun.
--
-- Paul A Sand <pas at unh.edu>
-- Information Technology / University of New Hampshire
-- http://pubpages.unh.edu/~pas
-- Get medical attention if symptoms persist.
Stef Morrell
2014-05-02 16:52:15 UTC
Permalink
Post by Paul A Sand
We?re also seeing the same sort of thing from the .me TLD (Montenegro),
That's exactly what I've been seeing. I'm seriously considering a custom rule to add 2-3 points to all .me domains, draconic as it sounds, I don't think that will seriously impact my users with FPs.
Philip Parsons
2014-05-02 17:14:57 UTC
Permalink
Return-Path: <?g>
Received: from try-somewonderfuldealz.us ([31.192.241.106])
by mx1.danada.ca (8.14.4/8.14.4) with ESMTP id s42BGSn5023606
for <jim at danada.ca>; Fri, 2 May 2014 04:17:37 -0700
Date: Fri, 02 May 2014 04:11:38 -0700
Content-Type: text/plain
Message-ID: <18291106.13013233 at try-somewonderfuldealz.us>
From: "Checking Account" <CheckingAccount at try-somewonderfuldealz.us>
Subject: Been-denied for a checking account? We will approve-you
Mime-Version: 1.0

From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Jerry Benton
Sent: May-02-14 9:15 AM
To: MailScanner discussion
Subject: Re: Spam from .us domains

Got a sample header?

On Fri, May 2, 2014 at 4:57 PM, Philip Parsons <pparsons at techeez.com<mailto:pparsons at techeez.com>> wrote:
Is anyone else getting hammered by spam saying it is from .us domains ? If have you figured a way to stop it yet ?

Thank you
P Parsons
--
MailScanner mailing list
mailscanner at lists.mailscanner.info<mailto:mailscanner at lists.mailscanner.info>
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!



--

--
Jerry Benton
Mailborder Systems
www.mailborder.com<http://www.mailborder.com>

--
This message has been scanned for viruses and
dangerous content by MailScanner<http://www.mailscanner.info/>, and is
believed to be clean.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140502/f99b0acc/attachment.html
Terry Hulen Jr
2014-05-02 17:48:57 UTC
Permalink
What MTA are you using? I use RBLs with my MTA instead of
Mailscanner. It stops the spammer from even sending any data. Also,
the MTA doesn't care the size of the message because in order to "see"
the size, the spammer has to successfully connect first. If he is
unable to connect due to being on an RBL, his message won't even be
transmitted.
Post by Philip Parsons
Return-Path: <?g>
Received: from try-somewonderfuldealz.us ([31.192.241.106])
by mx1.danada.ca (8.14.4/8.14.4) with ESMTP id s42BGSn5023606
for <jim at danada.ca>; Fri, 2 May 2014 04:17:37 -0700
Date: Fri, 02 May 2014 04:11:38 -0700
Content-Type: text/plain
Message-ID: <18291106.13013233 at try-somewonderfuldealz.us>
From: "Checking Account" <CheckingAccount at try-somewonderfuldealz.us>
Subject: Been-denied for a checking account? We will approve-you
Mime-Version: 1.0
From: mailscanner-bounces at lists.mailscanner.info
[mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Jerry
Benton
Sent: May-02-14 9:15 AM
To: MailScanner discussion
Subject: Re: Spam from .us domains
Got a sample header?
Is anyone else getting hammered by spam saying it is from .us domains ? If
have you figured a way to stop it yet ?
Thank you
P Parsons
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
--
--
Jerry Benton
Mailborder Systems
www.mailborder.com
--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
Stef Morrell
2014-05-02 20:19:50 UTC
Permalink
Post by Terry Hulen Jr
What MTA are you using? I use RBLs with my MTA instead of
Mailscanner. It stops the spammer from even sending any
data.
If it's the same stuff I am seeing, then the spam is getting sent out from fresh ips and newly (same day) registered domains. It's getting delivered prior to the RBLs becoming aware of the new sources.

For example, today I got spam from russianbrides-dating-great.me only 6-7 hours after the domain was registered. I won't get any tomorrow, because now it's in the RBLs and will be blocked.
Philip Parsons
2014-05-02 21:47:37 UTC
Permalink
Yeah that's the one's not certain if someone has written a SA rule or something to catch without having to rely on the RBLS as hundreds get through before the RBLS catchup...

-----Original Message-----
From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Stef Morrell
Sent: May-02-14 1:20 PM
To: 'MailScanner discussion'
Subject: RE: Spam from .us domains
Post by Terry Hulen Jr
What MTA are you using? I use RBLs with my MTA instead of
Mailscanner. It stops the spammer from even sending any
data.
If it's the same stuff I am seeing, then the spam is getting sent out from fresh ips and newly (same day) registered domains. It's getting delivered prior to the RBLs becoming aware of the new sources.

For example, today I got spam from russianbrides-dating-great.me only 6-7 hours after the domain was registered. I won't get any tomorrow, because now it's in the RBLs and will be blocked.
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.
Terry Hulen Jr
2014-05-02 22:38:11 UTC
Permalink
I only mention because the RBLs are my best line of defense and I have
not seen any increase of spam from .us domains.
Post by Philip Parsons
Yeah that's the one's not certain if someone has written a SA rule or something to catch without having to rely on the RBLS as hundreds get through before the RBLS catchup...
-----Original Message-----
From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Stef Morrell
Sent: May-02-14 1:20 PM
To: 'MailScanner discussion'
Subject: RE: Spam from .us domains
Post by Terry Hulen Jr
What MTA are you using? I use RBLs with my MTA instead of
Mailscanner. It stops the spammer from even sending any
data.
If it's the same stuff I am seeing, then the spam is getting sent out from fresh ips and newly (same day) registered domains. It's getting delivered prior to the RBLs becoming aware of the new sources.
For example, today I got spam from russianbrides-dating-great.me only 6-7 hours after the domain was registered. I won't get any tomorrow, because now it's in the RBLs and will be blocked.
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
Richard Siddall
2014-05-03 23:37:44 UTC
Permalink
Look at greylisting. It may let you defer accepting email from new
domains or new IPs until the domains show up in the RBLs.
Post by Philip Parsons
Yeah that's the one's not certain if someone has written a SA rule or something to catch without having to rely on the RBLS as hundreds get through before the RBLS catchup...
-----Original Message-----
From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Stef Morrell
Sent: May-02-14 1:20 PM
To: 'MailScanner discussion'
Subject: RE: Spam from .us domains
Post by Terry Hulen Jr
What MTA are you using? I use RBLs with my MTA instead of
Mailscanner. It stops the spammer from even sending any
data.
If it's the same stuff I am seeing, then the spam is getting sent out from fresh ips and newly (same day) registered domains. It's getting delivered prior to the RBLs becoming aware of the new sources.
For example, today I got spam from russianbrides-dating-great.me only 6-7 hours after the domain was registered. I won't get any tomorrow, because now it's in the RBLs and will be blocked.
Terry Hulen Jr
2014-05-04 19:27:32 UTC
Permalink
I forgot to mention, I am using greyfix with postfix as well. That,
along with my postfix RBLs, I have not seen any increase in spam.

On Sat, May 3, 2014 at 7:37 PM, Richard Siddall
Post by Richard Siddall
Look at greylisting. It may let you defer accepting email from new
domains or new IPs until the domains show up in the RBLs.
Post by Philip Parsons
Yeah that's the one's not certain if someone has written a SA rule or something to catch without having to rely on the RBLS as hundreds get through before the RBLS catchup...
-----Original Message-----
From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Stef Morrell
Sent: May-02-14 1:20 PM
To: 'MailScanner discussion'
Subject: RE: Spam from .us domains
Post by Terry Hulen Jr
What MTA are you using? I use RBLs with my MTA instead of
Mailscanner. It stops the spammer from even sending any
data.
If it's the same stuff I am seeing, then the spam is getting sent out from fresh ips and newly (same day) registered domains. It's getting delivered prior to the RBLs becoming aware of the new sources.
For example, today I got spam from russianbrides-dating-great.me only 6-7 hours after the domain was registered. I won't get any tomorrow, because now it's in the RBLs and will be blocked.
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
Stef Morrell
2014-05-07 06:35:58 UTC
Permalink
I too use greylisting, I presume they are using RFC compliant MTA as it gets by greylisting.

Maybe I could increase the delay time, but I'm also conscious I don't want to delay legitimate mail too long.
Post by Philip Parsons
-----Original Message-----
From: mailscanner-bounces at lists.mailscanner.info
[mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf
Of Terry Hulen Jr
Sent: 04 May 2014 20:28
To: MailScanner discussion
Subject: Re: Spam from .us domains
I forgot to mention, I am using greyfix with postfix as well.
That, along with my postfix RBLs, I have not seen any
increase in spam.
On Sat, May 3, 2014 at 7:37 PM, Richard Siddall
Post by Richard Siddall
Look at greylisting. It may let you defer accepting email from new
domains or new IPs until the domains show up in the RBLs.
Loading...