Menu

spam on my behalf to himself

Get Help
Anonymous
2016-05-20
2016-07-30
  • Anonymous

    Anonymous - 2016-05-20

    WTF)
    how could this happen

    *
    Received: from smtp.domain.ru () by cas.domain.ru ()
    with Microsoft SMTP Server id 14.3.279.2; Thu, 19 May 2016 19:28:30 +0300
    Received: by smtp.domain.ru (Postfix, from userid 65534) id 3r9c2848jlz13Mc;
    Thu, 19 May 2016 19:28:32 +0300 (MSK)
    Received: from localhost (localhost.localdomain [127.0.0.1]) by
    smtp.domain.ru (Postfix) with ESMTP id 3r9c283r7Yz13Dd; Thu, 19 May 2016
    19:28:32 +0300 (MSK)
    X-Amavis-Modified: Mail body modified (using disclaimer) - smtp.domain.ru
    X-Virus-Scanned: Scrollout F1 at domain.ru
    X-Spam-Flag: NO
    X-Spam-Score: 4.849
    X-Spam-Level:
    X-Spam-Status: No, score=4.849 taggedabove=-1000 required=5
    tests=[BAYES40=-1, HELOMISCIP=0.001, RDNSNONE=2, SOAKDNS=1.5,
    SOFROMRP=-0.4, SOLOCALFROM=-0.1, SOLOCALRETURNPATH=-0.1,
    SORDNSUNKNOWN=0.75, TVDSUBJACCNUM=2.198]

    autolearn=no autolearnforce=no
    Received: from smtp.domain.ru ([127.0.0.1]) by localhost (smtp.domain.ru
    [127.0.0.1]) (amavisd-new, port 10024) with LMTP id OTiUHVuxDmFw; Thu, 19 May
    2016 19:28:26 +0300 (MSK)
    Received: from [94.46.39.94] (unknown [94.46.39.94]) by smtp.domain.ru
    (Postfix) with ESMTP id 3r9c1z5sBQz13KS for user@mydomain.ru; Thu, 19
    May 2016 19:28:23 +0300 (MSK)
    MIME-Version: 1.0
    Message-ID: C60CF2C2CC.0527B584C3@mydomain.ru
    Date: Thu, 19 May 2016 19:27:37 +0300
    From: HP Scanjet1315 qwer7@mydomain.ru
    To: user@mydomain.ru
    Subject: Scan #9BB3217BDD889D2F2D2D
    Content-Type: multipart/mixed;
    boundary="------------037311822467668401940839"
    Return-Path: qwer7@mydomain.ru**

    *

    even there is no mention about the wrong spf

     

    Last edit: Anonymous 2016-05-20
  • Alejandro Lengua

    Did you manage to solve your issue?
    It would be great is Scrollout could do strict SPF check at least for the domains they protect.

     

    Last edit: Alejandro Lengua 2016-07-30
  • Anonymous

    Anonymous - 2016-07-30

    It does that if the protected domains use -all in SPF record.

     
  • Anonymous

    Anonymous - 2016-07-30

    In the example above, the DKIM must take effect since the From: is spoofed, not the sender (return-path)

     

Log in to post a comment.