|
From: Lionel B. <lio...@bo...> - 2006-11-30 21:51:45
|
Tomislav Filip=C4=8Di=C4=87 wrote the following on 30.11.2006 19:15 : > On 2006-11-30 14:10:50 +0100, Lionel Bouton=20 > <lio...@bo...> said: > > =20 >> I've received a notification for the two following servers. >> >> mxs1.siemens.at (194.138.12.131) >> mxs2.siemens.at (194.138.12.133) >> >> Apparently they don't retry. Can anyone confirm this? At least they=20 >> seem legitimate. So baring any problem, I'll add them in the whitelist= s=20 >> tomorrow. >> =20 > > > ahd1014.activehost.com [69.89.227.49] > =20 That's a suspicious looking little box... This is not the MX for the domain (although it isn't uncommon to have different outgoing servers, it's rather uncommon that they have such anonymous names). A bunch of dns lookups in the same class C shows several other ahd10??.activehost.com names scattered across the class C. Does this system really send legitimate mails and if affirmative, from which domain= s? Lionel |