It appears that when a spammer sends to many recipients the blocking process may have a problem. We have some email addresses that we set up as unfiltered because they are shared accounts and critical quarantined items were being missed....now it looks like an email that includes them in the recipient list may forward on to others after them in the list of recipients yet be blocked for those before. In a perfect world the spam message should only go to those recipients that are unfiltered....right? Here is a log entry showing the sequence that happened. The mailto:T6Planners@portptld.com - T6Planners@portptld.com is the unfiltered email address.
01/29/07 13:05:26:256 -- (4048) Connection from: 89.53.51.117 - Originating country : Germany 01/29/07 13:05:56:100 -- (4048) Resolving 89.53.51.117 - Q3375.q.pppool.de 01/29/07 13:05:56:584 -- (4048) - SPF analysis for pppool.de done: - none 01/29/07 13:05:56:600 -- (4048) Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:05:56:943 -- (4048) - MAPS search done... 521 The IP 89.53.51.117 is Blacklisted by combined.njabl.org. Dynamic/Residential IP range listed by NJABL dynablock - http://njabl.org/dynablock.html - http://njabl.org/dynablock.html -- 01/29/07 13:05:56:943 -- (4048) 89.53.51.117 - Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de To: mailto:billwyattnn@portptld.com - billwyattnn@portptld.com will be rejected 01/29/07 13:06:01:818 -- (4048) Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:01:818 -- (4048) 89.53.51.117 - Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de To: mailto:maracb@portptld.com - maracb@portptld.com will be rejected 01/29/07 13:06:03:584 -- (4048) Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:03:584 -- (4048) 89.53.51.117 - Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de To: mailto:oestem@portptld.com - oestem@portptld.com will be rejected 01/29/07 13:06:06:475 -- (4048) Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:06:475 -- (4048) 89.53.51.117 - Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de To: mailto:matheb@portptld.com - matheb@portptld.com will be rejected 01/29/07 13:06:12:303 -- (4048) Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:12:303 -- (4048) 89.53.51.117 - Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de To: mailto:daniem@portptld.com - daniem@portptld.com will be rejected 01/29/07 13:06:14:178 -- (4048) Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:14:178 -- (4048) 89.53.51.117 - Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de To: mailto:riedeh@portptld.com - riedeh@portptld.com will be rejected 01/29/07 13:06:15:350 -- (4048) Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:15:350 -- (4048) 89.53.51.117 - Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de To: mailto:baumak@portptld.com - baumak@portptld.com will be rejected 01/29/07 13:06:16:631 -- (4048) Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:16:646 -- (4048) 89.53.51.117 - Mail from: mailto:cindymokyava@pppool.de - cindymokyava@pppool.de To: mailto:maitlk@portptld.com - maitlk@portptld.com will be rejected 01/29/07 13:06:17:896 -- (4048) Bypassed all rules for: mailto:T6Planners@portptld.com - T6Planners@portptld.com from mailto:cindymokyava@pppool.de - cindymokyava@pppool.de ( Whitelisted EMail Address To) 01/29/07 13:06:21:771 -- (4048) Bypassed all rules for: mailto:3dolberd@portptld.com - 3dolberd@portptld.com from mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:24:225 -- (4048) Bypassed all rules for: mailto:crosst@portptld.com - crosst@portptld.com from mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:28:740 -- (4048) Bypassed all rules for: mailto:nelsoj@portptld.com - nelsoj@portptld.com from mailto:cindymokyava@pppool.de - cindymokyava@pppool.de 01/29/07 13:06:50:943 -- (4048) EMail from mailto:cindymokyava@pppool.de - cindymokyava@pppool.de to mailto:billwyattnn@portptld.com - billwyattnn@portptld.com , mailto:maracb@portptld.com - maracb@portptld.com , mailto:oestem@portptld.com - oestem@portptld.com , mailto:matheb@portptld.com - matheb@portptld.com , mailto:daniem@portptld.com - daniem@portptld.com , mailto:riedeh@portptld.com - riedeh@portptld.com , mailto:baumak@portptld.com - baumak@portptld.com , mailto:maitlk@portptld.com - maitlk@portptld.com , mailto:T6Planners@portptld.com - T6Planners@portptld.com , mailto:3dolberd@portptld.com - 3dolberd@portptld.com , mailto:crosst@portptld.com - crosst@portptld.com , mailto:nelsoj@portptld.com - nelsoj@portptld.com was queued. Size: 28 KB, 28672 bytes 01/29/07 13:06:54:600 -- (4048) Disconnect
ps...we are on version 3.1.3.605
|