Menu
Reply
  • 1.29K
  • 130
  • 694
MissPasko
Knows their stuff
712 Views
Message 21 of 34
Flag for a moderator

Re: Once again swamped with spam!

I've not had any asturiex, but disneylatino is most of our spam in the latest influx.  I've been reporting to SpamCop daily, is that good enough?  I see that a few today were marked as spam, some came to inbox.


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

If you want to say thanks > click 'Kudos'.
Have we solved your issue? > click 'Mark as Helpful Answer'
0 Kudos
Reply
  • 1.29K
  • 130
  • 694
MissPasko
Knows their stuff
687 Views
Message 22 of 34
Flag for a moderator

Re: Once again swamped with spam!

Return-Path: <>
Delivered-To: me@ntlworld.com
Received: from md2.tb.ukmail.iss.local ([212.54.59.74])
by mc23.tb.ukmail.iss.local with LMTP id QAGMKIDH5VwdEgAAWhTyXg
for <me@ntlworld.com>; Thu, 23 May 2019 00:04:48 +0200
Received: from smtpclienthelo ([212.54.59.74])
by md2.tb.ukmail.iss.local with LMTP id eN2kGX7H5VzBewAAaJkqCg
; Thu, 23 May 2019 00:04:48 +0200
Authentication-Results: ukmail.iss.as9143.net;
spf=pass (3.121.18.31;);
dkim=none (nosigs);
dmarc=none header.from=disneylatino.com (dis=no_record);
X-Env-Mailfrom:
X-Env-Rcptto: me@ntlworld.com
X-SourceIP: 3.121.18.31
X-CNFS-Analysis: v=2.3 cv=T7XysMCQ c=1 sm=1 tr=0
a=ceQDkqZhfAmqbmNKpZ7IkQ==:117 a=ceQDkqZhfAmqbmNKpZ7IkQ==:17
a=IkcTkHD0fZMA:10 a=iJsuRx8pAAAA:20 a=Oq_O0eq9AAAA:20 a=gPmkTVU_AAAA:20
a=rkilmZ7MAAAA:20 a=tclcd6dtLQvEqt9_mmAA:9 a=L03L2QfmqWoA:10
a=QEXdDO2ut3YA:10 a=Qv_Zx4hblmkA:10 a=p-dnK0njbqwfn1k4-x12:22
a=301kmAp-fCAfJyRBmuhM:22
Received: from disneylatino.com ([3.121.18.31])
by mx7.mnd.ukmail.iss.as9143.net with ESMTP
id TZLshzU24dWEyTZLshDhcR; Thu, 23 May 2019 00:04:48 +0200
Return-Path: <bounces+107200-3153-dalerwms=earthlink.net@email.disneylatino.com>
Content-Type: text/html; charset="UTF-8"
Date: Wed, 22 May 2019 22:04:16 +0200
From: "Congratulations, this is your week" <no-reply@disneylatino.com>
Mime-Version: 1.0
Reply-to: no-reply@disneylatino.com
To:
Message-ID: <VpsO6U7FJhZWBsshRKOvdzFzaQAllw@ismtpd0001p1iad1.sendgrid.net>
Subject: my name, please confirm your registration
X-CMAE-Envelope: MS4wfJ0kogboQnUPJwcPdDv20H0ceUy7/Rx7cE0C8t51dveIHkVgK/wrzzUZNhtAlpTY5yZGrS/+p7n9kdPZcd1ocZLEGkb+drUezpCy5BLgzgxBeCpBLxW/
OwIe1t/NpDrLZHpgvua3owDr9EjNi/BMG/q7B7r/w86VOdZf5NUrPrcW

 

<script>
ZGHG1TYCxQGe428mimFIoNv6IoXn8i5XD6hZEQEs6X49AXVyG1ZCey7YDfoQQs2PHQu6M7KEcSVuwCa73hECgEYCcNr9ZOOJOUaUfT6BbyJnKIuihyALFqklyMwN34cwn7BhQQgR0SYSFODbsb9yu6A2DC1HQNI00F8S77Or7lqpCHdiPiTbULb06K4p6Qc04eo6dTSh5EjDyo3iijQLXMezT4woizc7ohruDlPM5ziDulC5JgfA8TmaGSMCMzG3h8ujMsEscNjw9luWyKEwcCueHdZ4dnSWziktfF3wjZdsmwp77KF8cwKWxq8w1yfRQwFuprlR8Uq6S9v8o32cxNfjs9jyrAHrYcW8qljFMF8fEsmZCwhW5x6hxL9xztQ1Ma4OoewAL3EhFjTZ45Mtzpgql4bNNXwSceFNi2LAp3twgTm1Gmj897JGsmw5jlqqzXqfUsXaEo0lXaYYfc1SN2hIzWqRcfRjuaCLpneurk6sOuJzVL1N

EDITED = I THINK I SHOULD TAKE OUT SOME LINK-Y LOOKING STUFF AT THE BOTTOM OF THE EMAIL HEADER?


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

If you want to say thanks > click 'Kudos'.
Have we solved your issue? > click 'Mark as Helpful Answer'
0 Kudos
Reply
  • 17.89K
  • 988
  • 7.5K
Very Insightful Person
Very Insightful Person
681 Views
Message 23 of 34
Flag for a moderator

Re: Once again swamped with spam!

If you're posting headers use the code button in the GUI </> as this posts the code as is without the Forum "helpfully" changing any smiley combinations into icons.

E.g. Inserting using the code button

:) :S :D

Without the code button

🙂 :S 😄

Edit Copying MissPasko's post (I'd leave the <script> section out for now as it's actually part of the email body.

Return-Path: <>
Delivered-To: me@ntlworld.com
Received: from md2.tb.ukmail.iss.local ([212.54.59.74])
by mc23.tb.ukmail.iss.local with LMTP id QAGMKIDH5VwdEgAAWhTyXg
for <me@ntlworld.com>; Thu, 23 May 2019 00:04:48 +0200
Received: from smtpclienthelo ([212.54.59.74])
by md2.tb.ukmail.iss.local with LMTP id eN2kGX7H5VzBewAAaJkqCg
; Thu, 23 May 2019 00:04:48 +0200
Authentication-Results: ukmail.iss.as9143.net;
spf=pass (3.121.18.31;);
dkim=none (nosigs);
dmarc=none header.from=disneylatino.com (dis=no_record);
X-Env-Mailfrom:
X-Env-Rcptto: me@ntlworld.com
X-SourceIP: 3.121.18.31
X-CNFS-Analysis: v=2.3 cv=T7XysMCQ c=1 sm=1 tr=0
a=ceQDkqZhfAmqbmNKpZ7IkQ==:117 a=ceQDkqZhfAmqbmNKpZ7IkQ==:17
a=IkcTkHD0fZMA:10 a=iJsuRx8pAAAA:20 a=Oq_O0eq9AAAA:20 a=gPmkTVU_AAAA:20
a=rkilmZ7MAAAA:20 a=tclcd6dtLQvEqt9_mmAA:9 a=L03L2QfmqWoA:10
a=QEXdDO2ut3YA:10 a=Qv_Zx4hblmkA:10 a=p-dnK0njbqwfn1k4-x12:22
a=301kmAp-fCAfJyRBmuhM:22
Received: from disneylatino.com ([3.121.18.31])
by mx7.mnd.ukmail.iss.as9143.net with ESMTP
id TZLshzU24dWEyTZLshDhcR; Thu, 23 May 2019 00:04:48 +0200
Return-Path: <bounces+107200-3153-dalerwms=earthlink.net@email.disneylatino.com>
Content-Type: text/html; charset="UTF-8"
Date: Wed, 22 May 2019 22:04:16 +0200
From: "Congratulations, this is your week" <no-reply@disneylatino.com>
Mime-Version: 1.0
Reply-to: no-reply@disneylatino.com
To:
Message-ID: <VpsO6U7FJhZWBsshRKOvdzFzaQAllw@ismtpd0001p1iad1.sendgrid.net>
Subject: my name, please confirm your registration
X-CMAE-Envelope: MS4wfJ0kogboQnUPJwcPdDv20H0ceUy7/Rx7cE0C8t51dveIHkVgK/wrzzUZNhtAlpTY5yZGrS/+p7n9kdPZcd1ocZLEGkb+drUezpCy5BLgzgxBeCpBLxW/
OwIe1t/NpDrLZHpgvua3owDr9EjNi/BMG/q7B7r/w86VOdZf5NUrPrcW

 

Tim

As a Very Insightful Person, I'm here to share my knowledge. I don't work for Virgin Media.

Click to learn more about VIP

Use Kudos to say thanks

Mark as Helpful Answer if I've helped

  • 1.29K
  • 130
  • 694
MissPasko
Knows their stuff
668 Views
Message 24 of 34
Flag for a moderator

Re: Once again swamped with spam!

Thanks Tim, I'll try that next time.  How many more examples does Kev_B need?


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

If you want to say thanks > click 'Kudos'.
Have we solved your issue? > click 'Mark as Helpful Answer'
0 Kudos
Reply
  • 17.89K
  • 988
  • 7.5K
Very Insightful Person
Very Insightful Person
657 Views
Message 25 of 34
Flag for a moderator

Re: Once again swamped with spam!

My thoughts are if everyone posting into this thread posts a single email header, that should be enough.

@Kev_B - would that be a fair assessment?

Tim

As a Very Insightful Person, I'm here to share my knowledge. I don't work for Virgin Media.

Click to learn more about VIP

Use Kudos to say thanks

Mark as Helpful Answer if I've helped

0 Kudos
Reply
  • 6.78K
  • 221
  • 1.24K
Community Lead
Community Lead
641 Views
Message 26 of 34
Flag for a moderator

Re: Once again swamped with spam!

Yes - a single header each will suffice 🙂
Kev

The do's and don'ts. Keep the community welcoming for all. Follow the house rules


  • 17.89K
  • 988
  • 7.5K
Very Insightful Person
Very Insightful Person
627 Views
Message 27 of 34
Flag for a moderator

Re: Once again swamped with spam!

Just so people are aware of what I personally am doing with regards to this spam.

Yesterday I sent an email to the domain registrar, GoDaddy, with a copy of the email included - sent to abuse@godaddy.com
I have also emailed Amazon with several copies of the emails (sent as plain text source code) - sent to abuse@amazonaws.com

I also intend contacting the ICO's office to see if they can approach Amazon to investigate exactly what steps they are taking to prevent spammers from abusing their system in this way.

Tim

As a Very Insightful Person, I'm here to share my knowledge. I don't work for Virgin Media.

Click to learn more about VIP

Use Kudos to say thanks

Mark as Helpful Answer if I've helped

0 Kudos
Reply
  • 3.84K
  • 408
  • 1.38K
Very Insightful Person
Very Insightful Person
609 Views
Message 28 of 34
Flag for a moderator

Re: Once again swamped with spam!

Whilst waiting for the spam filters to catch up consider the following temporary workaround:

  • remove return@asturiex.com from Blacklist
  • create a filter rule similar to the following:
    2019-05-23.jpeg
    Note: the Set colour flag action is useful to help identify whether the filter rule moved a particular message to the spam folder.
0 Kudos
Reply
Highlighted
  • 45
  • 3
  • 6
aCactus
Dialled in
587 Views
Message 29 of 34
Flag for a moderator

Re: Once again swamped with spam!

Lots to choose from,,,

 

Received: from md5.tb.ukmail.iss.local ([212.54.59.73])
by mc58.tb.ukmail.iss.local with LMTP id 0ITECcmg5lwJRAAAAPbiTw
for <me@blueyonder.co.uk>; Thu, 23 May 2019 15:31:53 +0200
Received: from smtpclienthelo ([212.54.59.73])
by md5.tb.ukmail.iss.local with LMTP id yJNFGMag5lymUQAAeXFZqA
; Thu, 23 May 2019 15:31:53 +0200
Received: from getawayup1.net ([52.57.113.241])
by mx6.mnd.ukmail.iss.as9143.net with ESMTP
id Tn4RhVUKh85NETn4chGZjM; Thu, 23 May 2019 14:43:54 +0200
Reply-To: <no-reply@asturiex.com>
From: "Omega Burn" <return@asturiex.com>
To: <me@blueyonder.co.uk>
Subject: Can this oil really melt away the belly fat hiding your abs?
Date: Thu, 23 May 2019 12:43:28 +0100
Message-ID: <vpso6u7fuRvsYM9drkovdzfzaqallw@ismtpd0001p1iad1.sendgrid.net>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0B92_01D51179.D4F86020"
X-Mailer: Microsoft Outlook 16.0
Authentication-Results: ukmail.iss.as9143.net;
spf=pass (52.57.113.241;asturiex.com);
dkim=none (nosigs);
dmarc=none header.from=asturiex.com (dis=no_record);
X-Env-Mailfrom: return@asturiex.com
X-Env-Rcptto: me@blueyonder.co.uk
X-SourceIP: 52.57.113.241
X-CNFS-Analysis: v=2.3 cv=NZyYKFL4 c=1 sm=1 tr=0
a=/EyNhv4xY6rIl1GkaP8Efw==:117 a=/EyNhv4xY6rIl1GkaP8Efw==:17
a=IkcTkHD0fZMA:10 a=usZ6r277AAAA:20 a=H1dJ7t-nAAAA:20 a=61Qgul_DAAAA:20
a=UJTo3f6fAAAA:20 a=mvCDXNpqAK5Qqaa_BegA:9 a=L03L2QfmqWoA:10
a=QEXdDO2ut3YA:10 a=p-dnK0njbqwfn1k4-x12:22 a=dbv_onfkzo9o3AUftWHt:22
X-CMAE-Envelope: MS4wfH7C69EpXKOhp6E72TB1iyeiUiozYYDkvQMl683B66Lbc0DKkxqB/CKehjHF9np7D7TThmB9+klGOCVzIE6CEK07DRuXepl9RODBuSzR0Fx5q23XYJXt
TLldu4x2w5vjirBZrB6HgXgaz1n0pFP8C/1YGq+Y9WCTlFizV9kMOh7nsD7PPwSy4S28/TmNL0eJ8A==
Thread-Index: AQEjCHEI2UqlA2tXAdmDK+oDKzX6Qw==

  • 13.37K
  • 1.03K
  • 3.12K
Very Insightful Person
Very Insightful Person
523 Views
Message 30 of 34
Flag for a moderator

Re: Once again swamped with spam!

and still they come - how long does it take for VM to block these 

____________________

Tony
0 Kudos
Reply