3 ms·
The only part of an email you can trust are the headers you or your ISP add when it arrives, which is going to be something like : Received: from farlep.ne
by wendroid 16y ago
The only part of an email you can trust are the headers you or your ISP add when it arrives, which is going to be something like :
Received: from farlep.net (unknown [89.105.247.162])
by mail.techiferous.net (Postfix) with ESMTP id B1E30EC456E
for <info@techiferous.net>; Fri, 14 May 2010 10:24:22 +0100 (BST)
everything else - especially the RCPT TO, MAIL FROM, From: and To: cannot be trusted (unless the message is signed etc.).
I administer the mail for 10k domains, finding 1 spammer and doing something about it is hard work.
Spamassassin, SPF, DKIM are all good tools against SPAM, I can recommend using them all in combination; 90% of all our incoming mail is refused / tagged in this way.
I would review your assumptions too :
% host discokenny.com
Host discokenny.com not found: 2(SERVFAIL)
If they tried to send it to me, I'd never even know.
- techiferous 16y agoThanks! I did check the mail headers, and it actually came from discokenny.com. By the way, this is what I get: $ host discokenny.com discokenny.com has address 38.106.76.52 discokenny.com mail is handled by 10 namednsservers.com.
- wendroid 16y agohmm, maybe it is in your DNS cache or utterly firewalled from the UK % whois discokenny.com ... snip ... NS1.NAMEDNSSERVERS.COM 38.106.76.52 NS2.NAMEDNSSERVERS.COM 38.106.76.53 % traceroute 38.106.76.52 ...snip... 4 vlan128.10ge.lon3.uk.griffin.com (217.79.112.98) 21.697 ms 19.927 ms 19.757 ms 5 vl423.mpd01.lon01.atlas.cogentco.com (149.6.2.177) 28.760 ...snip... 9 te4-2.mpd01.ewr03.atlas.cogentco.com (154.54.1.30) 219.641 ms 10 38.104.188.146 (38.104.188.146) 97.547 ms 109.962 ms 96.691 ms 11 38.106.76.52 (38.106.76.52) 100.634 ms 99.136 ms 99.728 ms % host discokenny.com 38.106.76.52 ;; connection timed out; no servers could be reached % host discokenny.com 38.106.76.53 ;; connection timed out; no servers could be reached # nmap -PN 38.106.76.52 All 1715 scanned ports on 38.106.76.52 are filtered
- wendroid 16y agoOh and running mail and DNS on the same box. I hope they know how to administer secure installations. It's not a risk I would be taking.
- wendroid 16y agoit's back % host discokenny.com discokenny.com A 38.106.76.52