Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> How To Prevent Spammers From Using Your Domain?
Neverseen
post Dec 4 2005, 10:24 PM
Post #1


Premium Member
Group Icon

Group: Members
Posts: 227
Joined: 25-April 05
Member No.: 4,369



Ok. Here we go. I've got a website, and some lame spammer uses my domain name to send his fckin SPAM. Now I'm only receiving "Delivery Failure" messages from the adresses where this mofo has sent spam but that doesn't exist. I was told that with some software, it's possible to send an email, and to put whatever you want in the field "From:" so, even if you're sending the message from blabla@hotmail.com you still can make people believe that you send it from any other adress (ex: admin@astahost.com) and when they receive it they really think that it was the admin who has sent them this sh*t.
Now my question would be: is it possible to prevent spammers from using my domain name ?? Is there any way to block them ? Please let me know, because this really makes me sick sad.gif
Thanks in advance.
Go to the top of the page
 
+Quote Post
WeaponX
post Dec 5 2005, 12:48 AM
Post #2


Way Out Of Control - You need a life :)
Group Icon

Group: Members
Posts: 1,086
Joined: 21-June 05
From: New York
Member No.: 6,440



If I understand your questions correctly, I don't think it's possible. If anything take down your email address from your site if you put it up. That might be what triggered them to start doing this in the first place.

They can, as you know it, "spoof" (fake) their emails so it looks like it's coming from one source when it's really from someone else. You can take a look at the header details to see where it's coming from...but even this will not work as some can even spoof that information.

As far as I know, there's no way to prevent spammers from doing this. I would love to know how also (if someone has ideas) as I have tried many things already (including delisting my email address from my site - even though it doesn't use my domain).
Go to the top of the page
 
+Quote Post
miCRoSCoPiC^eaRt...
post Dec 5 2005, 04:08 AM
Post #3


PsYcheDeLiC dR3aMeR
Group Icon

Group: Admin
Posts: 2,242
Joined: 29-January 05
From: Nakorn Chaisri, Thailand
Member No.: 2,411



Spoofing like this is extremely easy to do in fact.. if you're wondering how, you don't even need any special software infact. Just simple TELNET will suffice.

For example, say my SMTP server is smtp.blah.net

This is what I do:
CONSOLE

shell> telnet smtp.blah.net

Trying x.x.x.x
Connected to mail.domain.ext.
Escape character is '^]'.
220 smtp.blah.net ESMTP Sendmail


What you get is a blank SMTP Prompt - where you simple type in from, to and body of the message... The commands used are MAIL FRM, RCPT TO and DATA. But first you need to tell the SMTP server you own domain. This is where the trick starts.. Example...(continuing from above)

CONSOLE

HELO myspoofed.domain.com
250 myspoofed.domain.com Hello smtp.domain.name [sm.tp.i.p], pleased to meet you


Next you type:
CONSOLE

MAIL FROM: spoofed@address.com
250 spoofed@address.com... Recipient ok


That's it - your trick is done.. the SMTP believes that your mail is comng from this spoofed address... So you see how easy it is to do it.. what you need to do is simply run some sort of a script that takes a bunch of email addresses and mails out to them using a spoofed domain as shown.. in your case it was your own doman..

As far as I know there's no way to stop this at all.. only inspecting the headers might give you a clue as to who's doing it. In turn you can report back to the original ISP of the sender that he's into serious spamming and thus get his account cancelled. But most likely he's using some free public email as his base - so closing that down won't affect him in any way. All he's got to do is open another account and start all over again...
Go to the top of the page
 
+Quote Post
yordan
post Dec 6 2005, 09:42 PM
Post #4


Way Out Of Control - You need a life :)
Group Icon

Group: [MODERATOR]
Posts: 1,980
Joined: 16-August 05
Member No.: 7,896



You can even configure your own mailer (Netscape Messenger for example), giving as "from" and "return mail address" an address like "thebestman@in.the.world", the mailer will send it's message with this "from" address. If this happens to be a valid address, bad luck.
Unfortunately, i agree with WeaponX, there is probably no way for avoiding that.
Go to the top of the page
 
+Quote Post
Neverseen
post Dec 14 2005, 02:51 PM
Post #5


Premium Member
Group Icon

Group: Members
Posts: 227
Joined: 25-April 05
Member No.: 4,369



thanks for your replies guys... so as I can see there's now way to get rid of that sad.gif too bad... I'll try at least to trace the sender, maybe I'll be able to find out who does this unfair thing.
Go to the top of the page
 
+Quote Post
vujsa
post Dec 18 2005, 02:16 AM
Post #6


Absolute Newbie
Group Icon

Group: Admin
Posts: 887
Joined: 20-February 05
From: Indianapolis, Indiana, USA (Midwest)
Member No.: 2,714



QUOTE(Neverseen @ Dec 14 2005, 09:51 AM)
thanks for your replies guys... so as I can see there's now way to get rid of that sad.gif too bad... I'll try at least to trace the sender, maybe I'll be able to find out who does this unfair thing.
*


You can actually track where the email really came from. Every Email message sent is encoded with the route used to get the message from sender to receipient. This can be used to track down the spammer and get justice.

You can either forward this information to your service provider or find a more inventive method of resolving the problem.

vujsa
Go to the top of the page
 
+Quote Post
WeaponX
post Dec 18 2005, 03:29 AM
Post #7


Way Out Of Control - You need a life :)
Group Icon

Group: Members
Posts: 1,086
Joined: 21-June 05
From: New York
Member No.: 6,440



vujsa, I heard that they can spoof the information in the header of the emails also. Does this include that routing information? If not, how do we trace it? Use a whois or DNS search service?
Go to the top of the page
 
+Quote Post
saint-michael
post Dec 18 2005, 04:34 PM
Post #8


SM- the Man -The Myth - The Legend Himself
Group Icon

Group: Members
Posts: 433
Joined: 4-September 05
From: Drinking da rootbeers
Member No.: 8,313



actually its gets harder and hard to trace spammers unless you have some elite of software to find them cuz spammers came reroute the original email/ip to dozens before they can get tracked. But most of the time people give up after the hundreds of different locations are traced. basically the stupider the email the harder it is to trace.

of course only rookies would fall for the admin sending you an email but sometimes the older users get caught sometimes, of course the best suggestion is used a back email address that you want to use to make sure that if you sign up all the junk goes their and not your primary email. of course some people go overboard and got like 20-30 email accounts just cuz of the features ***cough*** gmail ***cough***. but of course with todays current email technology alot of the spam goes to the junk folders anyway.

But i would have to say though only the idiots send spam if you want to get account info the smart people would hack for it and not send a spam email.
Go to the top of the page
 
+Quote Post
saxsux
post Dec 31 2005, 08:06 AM
Post #9


Bursting with vegany goodness!
Group Icon

Group: Members
Posts: 342
Joined: 8-April 05
From: Norwich, UK
Member No.: 3,753



Unfortuantely Vujsa, m^e, and everyone else who've posted are right. There's no easy way to stop this, other than going to thier ISP.
Seeing as billion dollar companies like eBay suffer from this problem and haven't been able to resolve it, I think that you don't stand much of a chance either (no offence intended).

Sorry neverseen, and good luck in with your website - hopefully the spammers shouldn't blight you too much.
Go to the top of the page
 
+Quote Post
iGuest
post Jan 16 2008, 12:43 AM
Post #10


Newbie [ Level 1 ]
Group Icon

Group: Members
Posts: 0
Joined: 1-November 07
Member No.: 25,869



How to stop spammers using your domain
How To Prevent Spammers From Using Your Domain?

Try using SPF (Sender Policy Framework). This is added to your domain zone file, and allows you to say which email servers are permitted to send for your domain. If a receiving server uses SPF validation, it will check to see if the domain the email is coming from has an SPF listed, and if the email isn't from an allowed server, it will reject it. If the domain doesn't have an SPF nominated, or the sending server matches the SPF nominated servers, then it is accepted.

It isn't perfect, and will only work really well once receiving servers have it setup, but it's a start - and if people start demanding it - then it will make a difference.

Http://www.Openspf.Org/

Rgds
See

-Craig
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Total Free Top Level Domain Names!(10)
  2. Domain Registrar(8)
  3. Very Cheap Domain Names(18)
  4. Domain Names(12)
  5. Yahoo Domain Sale: $2.99/yr. For .com(8)
  6. Free Domain Registration ( Against Earned Points )(25)
  7. Domain Names And Trademark Disputes(2)
  8. Free Domain Registration!(32)
  9. Mys Host.com(8)
  10. You Will Soon Be Paying For Safe Delivery Of Your Email..!(8)
  11. Gmail Hosted Domain(9)
  12. Wanna Free Domain Like .com, .org, .net?(18)
  13. Free Domain Registration Against 25 Forum Posts(13)
  14. Where To Find Free Hosting & Domain/Subdomain(11)
  15. Misleading Domain Names And Hyperlink Law(5)
  1. Email From Microsoft And Gmail For Your Own Domain For Free(8)
  2. Domain Registration(14)
  3. Choosing A Domain Name(6)
  4. Sogou Mail, Hosted For Your Domain,1g Size(5)
  5. Free Domain Website!(11)
  6. Free Hosted E-mail For Your Domain(200g)(4)
  7. Domain(1)
  8. Links: Free Stuffs Needed For Webmasters!(15)
  9. Domain "eater" Companies(6)
  10. How To Have The Domain In The Cheapest Way(7)
  11. Get Domain By Completing Offers !(4)
  12. Amazing Results From Reverse Ip Domain Check Tool(7)
  13. Best Place To Register A Domain(3)


 



- Lo-Fi Version Time is now: 6th September 2008 - 06:16 AM