Our server have been receiving alot of spam from this company. Has any one else experienced this especially from 216.9.176.0/24 ip block.
 
Does anyone know if they are legit?
 
Their IP block has only been registered with ARIN since 7/30/2003
 
The domain names from these server were all registered with godaddy on 8/21/2003
Looks like a spammer outfit posing as a legitimate net marketing firm.
 
Their full ip block range is
OrgName:    Mosaic Data Solutions
OrgID:      MDS-74
Address:    1880 Oak Avenue, Second Floor
City:       Evanston
StateProv:  IL
PostalCode: 60201
Country:    US

NetRange:   216.9.176.0 - 216.9.191.255
CIDR:       216.9.176.0/20
NetName:    INFORMATIONHOST-NET1
NetHandle:  NET-216-9-176-0-1
Parent:     NET-216-0-0-0-0
NetType:    Direct Assignment
NameServer: DNS01.EXODUS.NET
NameServer: DNS02.EXODUS.NET
Comment:    Informationhost 1880 Oak Avenue, Suite 250 Evanston, IL 60201 US Phone: 847-864-3900 Fax..: 847-864-9016 Email: [EMAIL PROTECTED]
RegDate:    2003-07-30
Updated:    2003-07-30

TechHandle: RJT35-ARIN
TechName:   Tindell, Richard Jeffrey
TechPhone:  +1-571-434-6630
TechEmail:  [EMAIL PROTECTED]

OrgTechHandle: RJT35-ARIN
OrgTechName:   Tindell, Richard Jeffrey
OrgTechPhone:  +1-571-434-6630
OrgTechEmail:  [EMAIL PROTECTED]
Kevin Bilbee
 
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]On Behalf Of Serge
Sent: Wednesday, August 27, 2003 8:15 PM
To: [EMAIL PROTECTED]
Subject: [Declude.JunkMail] IPNOTINMX

the manual say:
It will be triggered when an E-mail is sent from an IP address that is not in its MX record
 
1-is this the mx record for the domain of the from adress ? if the from is empty the test will fail?
 
2-also, declude never uses the reply to adress, correct ? is there a variable (declude virus) for the reply to adress ?
 
 

Reply via email to