When I got into work this morning and checked my email I got a bunch of messages from other servers saying they are receiving SPAM from my domain. I went into my logs and checked my "outmail_xx.log" files and couldn't find any of the domains listed. I also opened up some of the email headers and it doesn't look like they are actually coming from my server, here are a couple of the headers:
Received: from ti300710a080-3557.bb.online.no (ti300710a080-3557.bb.online.no [85.166.149.235])
by router.jcfumc.org (Postfix) with SMTP id 03FEB58EA5
for <xvrjh@jcfumc.org>; Mon, 10 Nov 2008 09:30:31 -0600 (CST)
Message-ID: <167601c94349$05f8a7c0$eb95a655@ti300710a080-3557.bb.online.no>
From: "Kate.Zak" <Subki.Arnoth@matsonalarm.com>
To: <xvrjh@jcfumc.org>
Subject: [SPAM] only smart people have finished the learnings
Date: Mon, 10 Nov 2008 15:30:22 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_2669_4ACC9E33.F0C8DAE7"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.3790.137
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.137
X-yoursite-MailScanner-Information: Please contact the ISP for more information
X-yoursite-MailScanner: Found to be clean
X-yoursite-MailScanner-SpamCheck: spam, spamcop.net,
SpamAssassin (not cached, score=21.692, required 4,
autolearn=disabled, DEAR_SOMETHING 2.23, DOS_OE_TO_MX 2.75,
HTML_IMAGE_ONLY_24 2.21, HTML_MESSAGE 0.00,
RCVD_IN_BL_SPAMCOP_NET 2.19, RCVD_IN_SORBS_DUL 1.61,
URIBL_AB_SURBL 1.61, URIBL_BLACK 1.96, URIBL_OB_SURBL 2.13,
URIBL_SBL 2.47, URIBL_SC_SURBL 2.52)
X-yoursite-MailScanner-SpamScore: sssssssssssssssssssss
X-yoursite-MailScanner-From: subki.arnoth@matsonalarm.com
X-Spam-Status: Yes
and
Received: from 9.subnet125-160-255.speedy.telkom.net.id ([125.160.255.9]) by biao.co.ci with Microsoft SMTPSVC(6.0.3790.211);
Mon, 10 Nov 2008 15:57:25 +0000
Message-ID: <2f2201c94416$19307afe$09ffa07d@9.subnet125-160-255.speedy.telkom.net.id>
From: "Jova.Ryad" <Chong.Orestes@matsonalarm.net>
To: <yo@biao.co.ci>
Subject: ****SPAM**** you can always start another learning, but only today - finish what is started
Date: Tue, 11 Nov 2008 16:00:08 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_94AC_C9E33F0C.8DAE7C53"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1123
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1123
Return-Path: Chong.Orestes@matsonalarm.net
X-OriginalArrivalTime: 10 Nov 2008 15:57:29.0849 (UTC) FILETIME=[08F38690:01C9434D]
X-NAI-Spam-Checker-Version: NAI SpamAssassin 1.2 (2.70 20081107 3143)
The "From" addresses are non-existent users the address in the "Received" section are not from any of my networks. Is there any way to stop this?
Thank you,
Ben Kiser