Spoofer email Bounce backs create invalid account on server

Every now and then one of those bottom feeding spoofers starts spoofing our domain name with a random account name to send out scads of spam - and of course the inevitable slew of bounce backs from the unfortunate "spamees" then flood our server. Fortunately I do use the excellent Frontline spam defense which helps tremendously.
What I am finding really odd is that these spoofers sometimes use a username of the variety "<[email protected]>" and for whatever reason this actually creates(?!) an account name in our email directory on the server?! (Acl privileges are l,r,s (any))
I have analyzed the traffic and there is absolutely no outbound mail going from our server with this username from our server (i.e. our server has definitely not been cracked)- I further verify this by checking the IP address of initial sender from some of the bouncebacks which have ALL info of the email transaction and it is definitely the work of a spoofer.
The "account" is relatively easy to delete with Siradmin - create an acl for the administrator with all privileges and then delete the account. There is nothing in it.
However I am just wondering if A) This odd "feature" (read bug!) is something that is known, and B) How can I possibly stop this strange behavior from happening again.
Any help or advise would be most appreciated.
Regards,
Rohin
p.s. a bit of my log is listed below FYI
Mar 15 14:03:14 dns postfix/smtp[4976]: E7D2423F87E: to=<[email protected]>, relay=127.0.0.1[127.0.0.1], delay=15, status=sent (250 2.6.0 Ok, id=02844-07, from MTA: 250 Ok: queued as AA9E423F8AA)
Mar 15 14:03:14 dns postfix/pipe[4985]: AA9E423F8AA: to=<[email protected]>, relay=cyrus, delay=1, status=bounced (data format error. Command output: jirfinesseembroideriesxyf: Mailbox does not exist )
Mar 15 15:08:06 dns postfix/pipe[5331]: 5225323DC99: to=<[email protected]>, relay=cyrus, delay=35729, status=deferred (temporary failure)
Mar 15 16:14:46 dns postfix/pipe[5681]: 5225323DC99: to=<[email protected]>, relay=cyrus, delay=39729, status=deferred (temporary failure)

Could verify this.
Mails to non existent shared folders create this shared folders like you mentioned above:
(imapd.conf: "postuser: test")
Apr 20 16:43:44 mc postfix/pipe[44755]: AFE26165AB4: to=<[email protected]>, relay=cyrus, delay=0.07, delays=0/0.01/0/0.06, dsn=5.6.0, status=bounced (data format error. Command output: test+xxx.test2: Permission denied )
this creates the shared folder "Shared Folders/xxx.test2"
If the part in front of the + is not defined in imapd.conf and no user with this name is present it gets rejected:
Apr 20 16:47:19 mc postfix/pipe[44878]: 9F148165AEB: to=<[email protected]>, relay=cyrus, delay=0.08, delays=0/0.01/0/0.06, dsn=5.6.0, status=bounced (data format error. Command output: test2+xxx.test2: Mailbox does not exist )

Similar Messages

  • Check Email Bounce Back

    Hi Experts,
    My client needs to check if an email bounces back to the SAP inbox. The email is sent using the function module 'SO_DOCUMENT_SEND_API1'. Is there any way to do this?
    Thanks and regards,
    Vishal.

    Normally the mails will be sent out by SCOT program. Hence you don't have a control in your program whether the mail will bounce or not?
    If any failure happens the mail status will be updated in user's outbox folder.
    You need to check whether the sent mail status is success or not, if failure then take an action.
    For this you need write a program to read the user's mails status.
    Regds
    Manohar

  • I typed my email wrong when creating an account. How can i get my $15 itunes card credit back? help!

    Hi Guys. Okay. Here is what happened. I was helping my friend create an account and he gave me his e-mail account but i accidentally misspelled it. It was a company email so i am certain that it has not been claimed since it ended with example (@companyname.com). My question is how do i go about retrieving my $15 dollar itunes card that we used when creating the account? Has anyone experienced this already? If so how did you fix it? I would really appreciate everyone's help. Let me know. Thanks in advance. =)

    You have to contact iTunes support
    They don't have a telephone call center
    You can submit a form on expresslane.apple.com and an iTunes store advisor will respond with you over email

  • Exchange 2010 - Bounce backs from unknown accounts

    Hi There,
    I am running exchange 2010 and i had a " Catch all " mailbox setup so any email sent to *@domain.com would get caught in this mailbox using a policy even if the account did not exist. I went to remove the " catch all " mailbox
    as it was no longer needed but if someone external was to email " [email protected] " or spelt a users name wrong the external user will not receive a bounce back telling them that the address is invalid.
    Any ideas?
    Regards,
    Jack 

    Check out the Set-RemoteDomain -NDREnabled parameter.
    http://technet.microsoft.com/en-us/library/aa997857(v=exchg.141).aspx
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • Email Bounce Back

    Hi,
    The email will auto bounce back if I send email and the recipient is point to my contact group. How to solve this issue. The bounce back email is shows below:
    Delivery has failed to these recipients or groups:
    [email protected]?
    The format of the e-mail address isn't correct. A correct address looks like this: [email protected] Please check the recipient's e-mail address and try to resend the message.
    Diagnostic information for administrators:
    Generating server: 172.18.1.202
    [email protected]?
    #550 5.1.3 STOREDRV.Submit; invalid recipient address #SMTP#
    Thanks

    Hi,
    This NDR message indicates that the format of the recipient's address is not incorrect.
    I've noticed that there is a question mark behind the email address:
    "[email protected]?
    #550 5.1.3 STOREDRV.Submit; invalid recipient address #SMTP#".
    Please check whether you have mistakenly added an question mark behind the address, then try again.
    Regards,
    Ethan Hua
    TechNet Community Support
    It's recommended to download and install
    Configuration Analyzer Tool (OffCAT), which is developed by Microsoft Support teams. Once the tool is installed, you can run it at any time to scan for hundreds of known issues in Office
    programs.
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

  • BT Email bounce backs

    Friends who send emails to my BT addresses are getting bounce backs occasionally, It's as if the mail servers don't know my address. If they try a little later it goes through. Is there something up with one, or more, of the BT mail servers? I'm on the "new" BT Email.

    I and 3 others I know of are also getting these occasional bounce backs.  Yesterday I spent over an hour being bounced around within BT until I finally got someone to accept some responsibility to investigate.  Most of the "help desk" want you to log out and in again or change your password or will 'pass you on to correct department', failing to understand that access to my inbox is not the issue, it's the non-arrival of original emails that is.
    In my case many of the returned emails are sent from my website when re-directing me an email to me.  The re-directed email fails, generates the error email which does arrive!  Both emails going to the same email address within milli-seconds of each other.  I have yet to have the error email rejected thus causing a third email to be sent!
    When I asked for an email address to send a copy of what I was getting as the error message I was told they don't have one.  A communications company that offers email services that doesn't have an email address for the help desk!  No wonder they don't understand their customers frustrations with the [lack of] service offered.  After asking to speak to a manager an email address was provided and I have sent them the reject email with full headers and have been promised a response within 48 hours.  I will just have to wait and see before escalating this further.
    They did comment at one point that there were no problems indicated on their servers, to which I had to point out that this was the very reason I was calling them.  Just because there is nothing indicated their end does not mean we, the punters, aren't having problems.
    So I'm sorry you, too, are getting this issue but at least it gives me more ammunition that it's nothing to do with my particular set up, but more obviously with something in the BT network.  I doubt anyone in BT actually reads these forums, but I can direct them to this thread if needed.

  • Emails bouncing back as undelivered

    I have a client that is trying to send out an e-mail to a specific e-mail address but it bounces back saying the e-mail could not be delivered and this is a permanent error contact your ISP (I also believed my client mentioned something about too many attempts
    or something along those lines) Does this mean my client might be black listed?  I don't have the exact error msg in front of me due to not having the computer myself but I am wondering if anyone has seen this before, or something similar, and what
    steps have been taken to resolve this issue.
    Thank You

    Hello,
    Any update on this issue? Please don't hesitate to post back.
    In addition, please try sending an email to the specific user from webmail to see if it sends successfully.
    Please also try removing the recipient from your contact folder and deleting the autocomplete entry for the recipient, and then try testing the issue again.
    Please let me know the result.
    Regards,
    Steve Fan
    TechNet Community Support
    It's recommended to download and install
    Configuration Analyzer Tool (OffCAT), which is developed by Microsoft Support teams. Once the tool is installed, you can run it at any time to scan for hundreds of known issues in Office
    programs.
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

  • Email Bounce backs with Outlook for Mac 2011

    An email I am sending to a company in the US from the UK bounces back saying there is an SMTP remote server error problem. No other emails appear to be affected. Can anyone help? Thanks

    Hi
    If its only 1 domain i would then ask the recipient to check with there ISP to whitelist your domain.
    Hope this helps. Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Email bounced back from valid addresses

    Hello,
    When I send email using Mail, people with certain email addresses (i.e. "pacbell" or "hotmail") don't receive them. Even though they are valid addresses, they are bounced back to me. I have a ".mac" address; when I send mail to these people through .mac's webmail, the mail goes through fine. Any ideas why?
    Thanks!
    -Vincas

    hi allan,
    this is what i get:
    "A message that you sent could not be delivered to one or more of its
    recipients. This is a permanent error. The following address(es) failed:"
    (even though the address is valid; this happens with newly composed and replied emails)
    when i send through webmail, they go through fine.
    thanks for any advice!
    -vincas

  • ICloud email bouncing back

    Why do my incoming emails still gets bounced back to sender after inbox has been cleared?

    Why do my incoming emails still gets bounced back to sender after inbox has been cleared?

  • Email bounce back - HELP

    I require some help if possible as i am going round in circles:
    My client has two email addresses, address1 @domainname.com and address2 @domainname.com - There is a rule on address1 which when an email is sent it automatically is forwarded onto address2.  My client has an external customer and when she tries
    sending she receives the error:
    An error occurred while trying to deliver this message to this recipient
    e-mail address. Microsoft Exchange will not try to redeliver this message for you. Please try resending this message, or provide the
    following diagnostic text to your system administrato
    Last week she was receiving a different error
    This message has too many recipients.  Please try to resend with fewer recipients:
    This message has too many recipients. Please try to resend with fewer recipients.
    External users colleagues also receive the same error, surprisingly the external user can email address 2
    directly without any issues.  The email they are sending is blank without any attachments.
    Lastly I have tried to send address1 and email using my company email address and it works fine and is received in address2 - I have also tried to send an email using my google email address and again it works fine.
    If anyone can help that will be great, they use Exchange 2003

    Exchange limits checked and no limits have been set, rules have been deleted and modified but still the same issue.
    More interesting though We have added three address as a rule,  now when emailing to address1
    @domainname.com there is a rule which sends to address2 @domainname.com, address3
    @domainname.com and an external Gmail address.
    The user once again emails address1 @domainname.com and it is delivered fine, the autoforwarder
    kicks in and it only gets to the Gmail address and fails on address 2 and address 3,
    When the external sends these emails directly to address 2 and address 3 they send just fine, it only
    fails when they are being forwarded by the rule yet it is able to forward to the external Gmail account.

  • Email bounce backs and delivery failures

    Over the past few months my client has started having trouble sending emails to a few domains (worked fine for multiple years).  The timing of these failures seems to match the new anti-spam software ISP are using.
    Our internal exchange server shuttles pop3 mail to our local ISP via popcon (program).  Not sure is the information in the message headers is the issue, how to change it, or what to do next.
    One feedback:
    "I also dealt with a similar issue a few days where an Exchange 2013 server which had been happily running for over a year, with the exact same settings as
    it used for 3 years previous on Exchange 2010 suddenly and mysteriously stopped sending to certain recipients but randomly, with the same error message as we see here. We suspected later that perhaps some mail servers on the internet were tightening things
    up when it comes to dealing with Spam etc."  The issue was in the Exchange servers FQDN. (Fully Qualified Domain Name)
    So far I have:
    1) restarted the ‘Transport Service’
    2) Updated send connector EHLO or HELO to bcbuildingtrades.org
    Here is a message header from a failed email:
    Diagnostic information for administrators:
    Generating server: bcyt.local
    [email protected]
    #550 4.4.7 QUEUE.Expired; message expired ##
    Original message headers:
    Received: from FILESERVER.bcyt.local ([fe80::f44a:5231:60f1:4519]) by
    FILESERVER.bcyt.local ([fe80::f44a:5231:60f1:4519%14]) with mapi id
    14.01.0218.012; Tue, 2 Sep 2014 11:26:01 -0700
    From: BC Building Trades <[email protected]>
    To: BC Building Trades <[email protected]>, BC Building Trades
            <[email protected]>
    Subject: RE: John MacTavish BCBCBTU Constitution Meeting: Wednesday,
    September 3, 2014
    Thread-Topic: John MacTavish BCBCBTU Constitution Meeting: Wednesday,
    September 3, 2014
    Thread-Index: Ac/DEBF+4GZ9fh2STdipo6AwiH8sMQDyotzw
    Date: Tue, 2 Sep 2014 18:26:00 +0000
    Message-ID: <[email protected]>
    Accept-Language: en-US, en-CA
    Content-Language: en-US
    X-MS-Has-Attach:
    X-MS-TNEF-Correlator:
    x-originating-ip: [fd7b:c71e:611b:0:69a3:67a5:2baf:593a]
    Content-Type: multipart/alternative;
            boundary="_000_B050148A9707274AA84DC8B1B93386997920417BFILESERVERbcytl_"
    MIME-Version: 1.0

    Hi
    Can you not ask your ISP to whitelist those domains you sending to? Also just verify that your domain is not listed at all, you can do so on MXToolbox.com
    Hope this helps. Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Outlook 2010 - Strange email bounce back issue.

    Hello,
       I have a user who's emails are getting rejected by some mail servers.  We are on Exchange 2007, and the user is using Outlook 2010.  The strange thing is, I and many other users on the same server can send to the same address no problem.
       I also found that if the user sends mail from OWA or his phone, it goes through fine as well.  His emails get blocked only when he sends from Outlook 2010 on his PC.  I thought it might be something with his ost file, so I had him
    delete it and Outlook rebuilt it.  But the issue persisted.  His emails got rejected with a 554 denied error.
       I checked and our Exchange server is not on any blacklists and has a good reputation.  Its just this one user that is getting rejected when he sends mail to certain addresses from Outlook 2010.  Is there an issue with Outlook that
    would cause something like this?
    Thanks.

    Hi,
    According to your description, I understand that the issue only occurs when sending message from the Outlook client.
    Please check the Blocked Senders and Safe Recipients settings in Junk E-mail Options in Outlook 2010. Also try to start Outlook in safe mode and send the test message to check whether the issue persists. If it doesn’t work, change a computer to have a try.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Sent Emails Bouncing Back

    I am new to the Blackberry world but have so far been able to set up everything to my liking.
    EXCEPT...
    everytime i send an email, a copy of that same email goes to my inbox and i have no idea how to stop this.  Essentially, the only emails i want to receive are the ones that other people send me, not copies of what i have sent.
    help!

    Are you facing this problme while using a Gmail ID?
    If the answer is yes the click on the link Duplicate sent email message arrives on BlackBerry smartphone when sent using Gmail
    tanzim                                                                                  
    If your query is resolved then please click on “Accept as Solution”
    Click on the LIKE on the bottom right if the post deserves credit

  • I have a problem with my iphone ! I cant remembe myid and pasword and i cant turn on my phone ! I dont remember the alternative email used to create the account ! What can i do ?

    hey

    You appear to have logged in here, which requires an Apple ID. Did you change your Apple ID at some point? If not, try the one that got you here.
    Are you the original owner of the phone?
    Try here:
    https://iforgot.apple.com

Maybe you are looking for

  • I tried to turn off VoiceOver with my iPod touch

    I tried to turn off voice over with my iPod by plugging it in to my Mac but it says that because there is a passcode on there I cannot get in to my iPod and I will not wipe it out. What do I do?!?? I cannot get VoiceOver off

  • SQL Error using cachedrowSet.populate.

    Hi, I am trying to use cachedrowset to pass my result set into my jsp. I use request.setAttribute and pass my cachedrowset and in my jsp I use <jsp:usebean> tag to retrieve it. This usually works for me. However, I have one query which when I am tryi

  • I'm new to Mac and iPhoto. How do I change 2.9Mb to 1Kb?

    I need to reduce the photo so that it will be accepted for a special app but I haven't been able to figure out how to get iPhoto to do this.

  • Text Quality Changes?

    It seems text used to be smoother on screen and when I saved my web images. Now, particularly smaller sized serif fonts don't look as nice as I remember them before. I keep my text settings at Sharp. I've noticed it over time but never brought it up

  • How do I import photos to iPhoto from a slideshow created in .wmv format

    How do I import photos to iPhoto from a slideshow created in .wmv format?