>I'm receiving a lot of spam which use such as mailfrom the same valid >address which is on my mail server and which spam send mail...
We have had many reports of spammers doing this now. A year or so ago, no spammer would even think of doing that (except with batches of 20 or so E-mails, where only about 5% of the recipients would see their name in both places). >Received: from $domain [VariableIpAddress!!!] by MyServerMail.MyDomain.com > (SMTPD32-7.07) id A6187C014E; Mon, 01 Jul 2002 11:51:20 +0200 Note that the $domain in the HELO/EHLO text seems to be used by default by a major new spamware package. Filtering on that would be a good idea (the latest version of Declude JunkMail would catch that with the HELOBOGUS test and SPAMHEADERS test). >There are a way to stop this kind of spam using Imail features ? I think the best way right now (without blocking legitimate mail) would be to use IMail's filters on the "$domain". -Scott --- Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for IMail. http://www.declude.com --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/