I have a big problem ... We receive Returns Recept of mails that nobody sent

Any person received this return receipt sometimes …but he never send a mail at this adress … That lets they think that safety is not sufficient on our server Domino V6.

How can I do to block this message ? To prevent spoofing sender ?? it’s a very big problem …

----- Réacheminé par xxxx le 25/03/2004 14:10 -----

Avis de non-distribution

Votre document : Re: Excel file

n’a pas été distribué à michaberna@aol.com

Motif : 550 MAILBOX NOT FOUND

Que faire ?

Vous pouvez renvoyer le document non distribué aux destinataires de la liste ci-dessus en cliquant sur le bouton Renvoyer, ou en sélectionnant la commande Renvoyer du menu Actions.

Vous pouvez ensuite supprimer l’avis de non-distribution.

Si l’envoi du document échoue à nouveau, vous recevrez un nouvel avis de non-distribution.

Sinon, le document a bien été distribué aux autres destinataires.

LotusNotes/ xxx

Pour :	michaberna@aol.com			cc :			

Date :	08:36:49 Aujourd'hui

		Objet :	Re: Excel file

Subject: I have a big problem … We receive Returns Recept of mails that nobody sent

Many current mass mailing worms (virus type mail messages) will use a made up or copied ‘From’ address to disguise where it came from. If the ‘To’ address is incorrect, the message will be automatically returned to the ‘from’ address.

It may be that your users have had their names copied by a worm that is using them as a disguised ‘from’.

Make sure your anti-virus set-up is up to date.

Subject: I have a big problem … We receive Returns Recept of mails that nobody sent

Hi,this is what happens when people use crappy e-mail programs, in this case Outlook. Ther eare several virusses around that affect there PC: it automatically sends mail to people that are listed in their address book, and put another name from that address book as the sender, with the virus itself attached. When the mail address to which it is sent to does not exist anymore, it gets bounced. That is, to the peron in the from-field, which is spoofed.

In the end, it is not your problem, so nothing to worry about. Keep on using Notes mail!

Regards,

Marco

Subject: RE: I have a big problem … We receive Returns Recept of mails that nobody sent

Yes I say that you says …but I would like to know if there are a issue( solutions ) to protect my server to spoofing … a special configuration to need ?¨perhaps …

A solution could be for the error 550, not send return recept to users if the error message 550 happen … but it can be dangerous …

How the error 550 can be configured not to be received by the person ??? it is one of solutions ?

Subject: RE: I have a big problem … We receive Returns Recept of mails that nobody sent

It should be possible to create a server rule that stops returned mail with 550 from being delivered, but that opens a whole new can of worms.

Most of the time your users will want to know if a real message sent by them was not delivered for any reason.

My advice would be (as others have said) to stop worrying about it, tell your users that this problem is caused by something outside of both your and their control, and get on with life.

If you are a user, how hard is it to realise that a ‘returned mail’ message that you never sent in the first place can just be deleted?

If your users are giving you problems, refer them to Joe Nelson. He’ll sort them out for you…

Subject: RE: I have a big problem … We receive Returns Recept of mails that nobody sent

What can Joe Nelson do for me ? ?

Subject: RE: I have a big problem … We receive Returns Recept of mails that nobody sent

Well if you ask him nicely and pay for his 'plane ticket he may come over and beat them up for you…

However I don’t know the guy personally and I’m probably upsetting him with this, so just in case he’s bigger than me I’ll stop here!

Subject: enduser education

The others are right, these messages are created by viruses and worms. Because it all happens outside your environment, there’s nothing you can do about it. You need to educate your endusers about this: there’s nothing you or your domino server can do about this. You, nor your endusers, are responsible for these mesages.If you have an intranet, put a message up there. If your company isn’t large, send a message to your endusers

Subject: enduser education==> that’s a cop out

Sounds to me like you and Leo Green are JUST developers or administrators. Do you let viruses and worms into your organization? Why would you let these spoofed return address emails into your organization? Perhaps it’s because you can’t figure a way to block them.

I think the advice you have given users in this thread is incorrect.

A year ago, it was really cool to add DNS blacklist functionality and 60% of spam was rejected before it made a connection to your external mail server. Now spammers use the return address spoofing technique to make the DNS blacklist filter useless (or at least severely limits it’s usefulness). I’m looking for advice on how to configure checking the validity of a return address (not sure how, but maybe someone has explored this) so that we can once again cut the amount of spam BEFORE we have to inspect it’s content.

Maybe your user community likes the Outlook functionality removing spam at the client, but in larger organizations this becomes a tremendous burden on human capital, as well as a drain on network and hardware resources. What are the chances your CEO or CFO have Palm or BlackBerry devices? Do you want to put yourself in the position having to tell them that they are obliged to receive the V I A G R A emails on their handhelds because they were created externally by viruses and we can’t do anything about them? And when they ask you how many other people receive these emails, what do you answer?

Sure we need to educate users, but that’s only a small component of a plan. To rely on users to delete the spoofed address spam is a real step backwards.

Subject: RE: enduser education==> that’s a cop out

“Now spammers use the return address spoofing technique to make the DNS blacklist filter useless (or at least severely limits it’s usefulness).”

Sorry this is just plain wrong. Email address spoofing has no effect on the operation of DNSBLs because DNSBLs only act on the IP address of the computer attempting to deliver the mail. Nothing that happens during the protocol phase of message delivery (HELO/EHLO, MAIL FROM, RCPT TO, whatever) has the slightest bearing on DNSBL effect.

Perhaps the reason you are not seeing good results is that you are using the wrong DNSBLs. You need to use quite aggressive lists these days to get good results and therefore must either be prepared to tolerate some false positives or else have whitelisting capability available to you. Whitelisting is incidentally a native feature of Domino 7.

The issue of sender address spoofing itself is certainly a nuisance and the now joined up standard Sender ID (being the bringing together of Microsoft Caller ID and SPF) addresses the issue head on.

You would be well advised to publish SPF/Sender ID information about your own domain(s) in the DNS now because some large systems already have deployed Sender ID checks on inbound mail and this will reduce some of the backscatter of bounces coming back to spoofed senders.

Sender ID will ultimately not reduce spam though because spammers have access to DNS too and will simply switch from spoofing other people’s domains where those domains publish Sender ID to spoofing domains that do not publish Sender ID or publishing Sender ID for their own domains.

Hope this clarifies some things for you.

Chris Linfoot

Subject: RE: enduser education==> that’s a cop out

“Now spammers use the return address spoofing technique to make the DNS blacklist filter useless (or at least severely limits it’s usefulness).” Sorry this is just plain wrong. Email address spoofing has no effect on the operation of DNSBLs because DNSBLs only act on the IP address of the computer attempting to deliver the mail. "

I’m not sure I articulated the situation I am seeing. Spammers send email to aphoneyaddress@awellknownisp.com with a spoofed return address. The well known isp says we have no user at this site and then tries to return the email to the spoofed return address. If it is our domain included as the spoofed return address, then the isp server tries to connect to our server. The isp’s server is not found in DNSbl and then our server allows the connection.

In effect the server delivering the spam is a valid server that normally does not send out spam and is therefore not in DNSbls.

Even if spammers don’t use well known isp’s they can still use any smtp server that’s not in a blacklist.

The email is received as a delivery failure, and depending on the SMTP server more or less of the original message may be included in the failure notice.

Subject: RE: enduser education==> that’s a cop out

OK I understand now.

Comments re sender ID still apply. We used to see a lot of forged bounces coming off AOL for example.

Since we published Caller ID and SPF for our main production domain here we have seen not one bogus bounce off AOL to that domain.