[Asrg] Increase in spoofed spam using bogus sender

"Eric Dean" <eric@purespeed.com> Wed, 18 June 2003 17:13 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA16724 for <asrg-archive@odin.ietf.org>; Wed, 18 Jun 2003 13:13:04 -0400 (EDT)
Received: (from exim@localhost) by www1.ietf.org (8.11.6/8.11.6) id h5IHCbN13692 for asrg-archive@odin.ietf.org; Wed, 18 Jun 2003 13:12:37 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19SfjU-0001V6-9f for asrg-web-archive@optimus.ietf.org; Wed, 18 Jun 2003 12:24:24 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA15024; Wed, 18 Jun 2003 12:24:20 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19SfhD-0006Po-00; Wed, 18 Jun 2003 12:22:03 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19SfhC-0006Pk-00; Wed, 18 Jun 2003 12:22:02 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Seze-0007b4-5J; Wed, 18 Jun 2003 11:37:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19SeYl-0006Ni-Cr for asrg@optimus.ietf.org; Wed, 18 Jun 2003 11:09:15 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA11563 for <asrg@ietf.org>; Wed, 18 Jun 2003 11:09:11 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19SeWT-0005aY-00 for asrg@ietf.org; Wed, 18 Jun 2003 11:06:54 -0400
Received: from [63.210.22.4] (helo=relay.purespeed.com) by ietf-mx with esmtp (Exim 4.12) id 19SeWT-0005aT-00 for asrg@ietf.org; Wed, 18 Jun 2003 11:06:53 -0400
Received: from purespeed.com (mail.purespeed.com [63.210.23.8]) by relay.purespeed.com (Postfix Relay Hub) with ESMTP id D514F1815E for <asrg@ietf.org>; Tue, 17 Jun 2003 23:11:22 -0400 (EDT)
Received: from HOMEY [68.100.19.197] by purespeed.com (SMTPD32-7.13) id A07F6710296; Wed, 18 Jun 2003 11:08:47 -0400
From: Eric Dean <eric@purespeed.com>
To: asrg@ietf.org
Message-ID: <MBEKIIAKLDHKMLNFJODBKEDKFKAA.eric@purespeed.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2911.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
In-reply-to: <20030616160418.GA25291@dumbo.pobox.com>
Content-Transfer-Encoding: 7bit
Subject: [Asrg] Increase in spoofed spam using bogus sender
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Wed, 18 Jun 2003 11:11:37 -0400
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

I have seen a rather dramatic increase in the amount of spam coming from
spoofed senders using bogus email addresses.  About 3% of the total email
(including valid email) that makes it through our front-line that filters
out bogus-domains..HELO..whatever winds up getting filtered due to a bogus
sender based upon an SMTP reject from the challenge message.

I'm wondering if the increased threat of litgation by companies such as
Microsoft, AOl, Yahoo...are forcing spammers to further anonymize
themselves.


_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg