on 31-10-2022 17:20
Contacted SPAMHAUS as I can't send emails via my blueyonder account. Said HELO values indicate a problem, usually caused by malware. I have carried out scans on all my devices and found no problems. Can send by Gmail no problem, so it looks like VM problem.
Can you help
on 31-10-2022 19:08
If the malware is no longer active on your network then go through Spamhaus's de-listing process. if Spamhaus relists your public network's IP Address then unfortunately the malware is still active.
--
I'm a Very Insightful Person, I'm here to share knowledge, I don't work for Virgin Media. Learn more
Have I helped? Click Mark as Helpful Answer and solved, or use
Kudos to say thanks
on 31-10-2022 22:04
@Wiganer wrote:Contacted SPAMHAUS as I can't send emails via my blueyonder account. Said HELO values indicate a problem, usually caused by malware. I have carried out scans on all my devices and found no problems. Can send by Gmail no problem, so it looks like VM problem.
Can you help
Lets look at some of the above:
Contacted SPAMHAUS as I can't send emails via my blueyonder account. Said HELO values indicate a problem, usually caused by malware.
There's a whole two way conversation that goes on between the two devices involved in a mail transaction - That's even before you get to the HELO exchange, and a whole lot more besides.
Furthermore the IP address that's recorded by Spamhaus is the public IP address of the network an offending device resides on (any and all devices on your home network will appear to be on that IP address (this is one of the drawbacks of NAT).
So if Spamhaus reports that your IP address has been sending spam - that's all the evidence you need.
I have carried out scans on all my devices and found no problems.
No antivirus/antimalware scan is 100% effective. Add to that some applications (called PUP's - Potentially Unwanted Programs) aren't classed as malware but can sometimes carry out undesirable activity on the side.
Add to that are you sure you've scanned everything? In the past we've seen compromised Amazon Firesticks running third party apps sending spam - and there's no tool aroud to scan them!
Not to mention HOLA free VPN 😞 Which can be used to send email via an unsuspecting third party.
so it looks like VM problem.
Nope - it's your problem. Malicious traffic is comig from your network - If someone's sending spam via your IP address - what else are they doing on your network?
Tim
I'm a Very Insightful Person, I'm here to share knowledge, I don't work for Virgin Media. Learn more
Have I helped? Click Mark as Helpful Answer or use Kudos to say thanks