[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] Email Issues - Bogus, but confusing to users... Could confuse yours !



>Chuck,
>
>	The only easy way to see where the garbage is coming from
>if you use Outlook is to use the 'Options' under 'View' when 
>you look at the message.  At the bottom of the dialog window
>that pops up is the full and complete headers.  If you look
>into the section for originating IP and sender, you can normally
>see a constant IP (even if the sender relay is forged and would
>be with these ignorant viruses of late) that is your source.

>	Drop that IP into your spam filters and firewalls and
>all your users will be saved from having to deal with it.  If
>the originating IP sends you a complaint, you have all you need
>to explain the problem and let them solve it before restoring
>their access to your e-mail server(s).

>	Sometimes you can use ARIN (www.arin.net) to trace that
>IP back and find a real user that may be infected.  If you're
>so inclined, you can report that IP to the abuse@ address the
>ARIN report provides and they'll deal with it.  If you do, make
>sure you cut n' paste the info from the 'Options' full header
>so the Abuse department can follow up on it.  Forwarding the 
>e-mail tends to strip everything out and they won't act on 
>something with limited info.
>
>	HTH!
>
>      David J. Duffner
>      VP Operations
>      NWC Corporation
>      NWCWEB.com

David, 

Very helpful. I am pretty much clueless on this stuff. I did use the email
options in Outlook and that is what I MEANT to paste into the initial
email... Here that is:

Return-Path: <Swinter@xxxxxxxxxxx>
Received: from cc2374442-b (207-250-217-146.gen.twtelecom.net
[207.250.217.146])by leeqube2.leesupply.net (8.10.2-SOL3/8.10.2) with SMTP
id i23GCYj22781 for <jan.doe@xxxxxxxxxxxxx>; Wed, 3 Mar 2004 11:12:34 -0500
Date: Wed, 03 Mar 2004 11:20:41 -0500
To: jan.doe@xxxxxxxxxxxxx
Subject: Important notify about your e-mail account.
From: management@xxxxxxxxxxxxx
Message-ID: <kalvbjwtjxgojueeamx@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="--------fmkvmtfnhlmsfeybinan"
X-UIDL: Q8o!!ie1!!AF^!!<`\"!

So what is the above telling me ?

Thanks !

Chuck