[MDaemon-L] Performing DomainKeys lookup (Sender: hp_prin...@caberawit.com)

2013-07-10 Terurut Topik Antyo
Ok pak, terima kasih banyak




Thanks

Tyo

-- 
--[MDaemon-L]
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: http://www.netmeister.org/news/learn2quote
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 13.5.1, SP 4.1.5, BES 2.0.2, OC 2.3.2, SG 2.1.2, PP 2.0.1



[MDaemon-L] Performing DomainKeys lookup (Sender: hp_prin...@caberawit.com)

2013-07-09 Terurut Topik Syafril Hermansyah
On 2013-07-10 12:52, Antyo Adhi B. wrote:
> Ini spam ya? 

Ya.

> Kenapa from di inbox client bisa pakai domain saya ya?

> Wed 2013-07-10 11:25:58: * Message return-path: al...@dnb.com
> Wed 2013-07-10 11:25:58: * Message from: hp_prin...@caberawit.com
> Wed 2013-07-10 11:25:58: * Message to: na...@caberawit.com

Spammernya jagoan :-(
Spam model ini hanya bisa ditangani oleh IPshield

http://mdaemon.dutaint.co.id/13.5/index.html?security__ip_shielding.htm

[x] Don't apply IP Shield to messages sent to valid local users
[x] Don't apply IP Shield to authenticated sessions
[x] IP Shield honors aliases
[x] Check FROM header address against IP Shield


-- 
syafril
---
Syafril Hermansyah
MDaemon-L Moderators, running MDaemon 13.5.1 SecurityPlus 4.1.5
Harap tidak cc: atau kirim ke private mail untuk masalah MDaemon.


-- 
--[MDaemon-L]
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: http://www.netmeister.org/news/learn2quote
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 13.5.1, SP 4.1.5, BES 2.0.2, OC 2.3.2, SG 2.1.2, PP 2.0.1



[MDaemon-L] Performing DomainKeys lookup (Sender: hp_prin...@caberawit.com)

2013-07-09 Terurut Topik Antyo Adhi B.
Dear Pak Syafril,

Ini spam ya? Kenapa from di inbox client bisa pakai domain saya ya? Mohon
pencerahannya

Wed 2013-07-10 11:25:22: --
Wed 2013-07-10 11:24:38: Session 89789; child 2
Wed 2013-07-10 11:24:38: Accepting SMTP connection from
[24.177.187.183:37378] to [111.68.127.107:25]
Wed 2013-07-10 11:24:38: --> 220 ms.caberawit.com ESMTP MDaemon 12.5.7; Wed,
10 Jul 2013 11:24:38 +0700
Wed 2013-07-10 11:24:39: <-- EHLO 24-177-187-183.dhcp.leds.al.charter.com
Wed 2013-07-10 11:24:39: --> 250-ms.caberawit.com Hello
24-177-187-183.dhcp.leds.al.charter.com, pleased to meet you
Wed 2013-07-10 11:24:39: --> 250-ETRN
Wed 2013-07-10 11:24:39: --> 250-AUTH LOGIN CRAM-MD5 PLAIN
Wed 2013-07-10 11:24:39: --> 250-8BITMIME
Wed 2013-07-10 11:24:39: --> 250 SIZE 2048
Wed 2013-07-10 11:24:39: <-- MAIL FROM:  BODY=7BIT
Wed 2013-07-10 11:24:39: Performing PTR lookup (183.187.177.24.IN-ADDR.ARPA)
Wed 2013-07-10 11:24:39: *  D=183.187.177.24.IN-ADDR.ARPA TTL=(1440)
PTR=[24-177-187-183.dhcp.leds.al.charter.com]
Wed 2013-07-10 11:24:39: *  Gathering A records...
Wed 2013-07-10 11:24:40: *  D=24-177-187-183.dhcp.leds.al.charter.com
TTL=(1440) A=[24.177.187.183]
Wed 2013-07-10 11:24:40:  End PTR results
Wed 2013-07-10 11:24:40: Performing IP lookup
(24-177-187-183.dhcp.leds.al.charter.com)
Wed 2013-07-10 11:24:40: *  D=24-177-187-183.dhcp.leds.al.charter.com
TTL=(1440) A=[24.177.187.183]
Wed 2013-07-10 11:24:40:  End IP lookup results
Wed 2013-07-10 11:24:40: Performing IP lookup (dnb.com)
Wed 2013-07-10 11:24:40: *  D=dnb.com TTL=(40) A=[159.137.136.250]
Wed 2013-07-10 11:24:40: *  P=010 S=000 D=dnb.com TTL=(31)
MX=[uscwygtw02.dnb.com]
Wed 2013-07-10 11:24:40: *  P=010 S=002 D=dnb.com TTL=(31)
MX=[uscwygtw01.dnb.com]
Wed 2013-07-10 11:24:40: *  P=020 S=001 D=dnb.com TTL=(31)
MX=[uslitgtw02.dnb.com]
Wed 2013-07-10 11:24:40: *  P=020 S=003 D=dnb.com TTL=(31)
MX=[uslitgtw01.dnb.com]
Wed 2013-07-10 11:24:41: *  D=dnb.com TTL=(40) A=[159.137.136.250]
Wed 2013-07-10 11:24:41: *  D=dnb.com TTL=(40) A=[159.137.136.250]
Wed 2013-07-10 11:24:41: *  D=dnb.com TTL=(40) A=[159.137.136.250]
Wed 2013-07-10 11:24:41: *  D=dnb.com TTL=(40) A=[159.137.136.250]
Wed 2013-07-10 11:24:41:  End IP lookup results
Wed 2013-07-10 11:24:41: Performing SPF lookup (dnb.com / 24.177.187.183)
Wed 2013-07-10 11:24:41: *  Policy: v=spf1 mx ip4:72.19.252.170
ip4:202.129.242.64/31 ip4:204.14.232.64/28 ip4:204.14.234.64/28
ip4:220.130.152.172 ip4:204.92.22.200/30 include:alerts.wallst.com ~all
Wed 2013-07-10 11:24:42: *  Evaluating mx: no match
Wed 2013-07-10 11:24:42: *  Evaluating ip4:72.19.252.170: no match
Wed 2013-07-10 11:24:42: *  Evaluating ip4:202.129.242.64/31: no match
Wed 2013-07-10 11:24:42: *  Evaluating ip4:204.14.232.64/28: no match
Wed 2013-07-10 11:24:42: *  Evaluating ip4:204.14.234.64/28: no match
Wed 2013-07-10 11:24:42: *  Evaluating ip4:220.130.152.172: no match
Wed 2013-07-10 11:24:42: *  Evaluating ip4:204.92.22.200/30: no match
Wed 2013-07-10 11:24:42: *  Evaluating include:alerts.wallst.com: performing
lookup
Wed 2013-07-10 11:24:43: *Policy: v=spf1 a:alerts-gw.wallst.com
a:alerts-gw2.wallst.com a:alerts-gw3.wallst.com -all
Wed 2013-07-10 11:24:43: *Evaluating a:alerts-gw.wallst.com: no match
Wed 2013-07-10 11:24:44: *Evaluating a:alerts-gw2.wallst.com: no match
Wed 2013-07-10 11:24:44: *Evaluating a:alerts-gw3.wallst.com: no match
Wed 2013-07-10 11:24:44: *Evaluating -all: match
Wed 2013-07-10 11:24:44: *  Evaluating include:alerts.wallst.com: no match
Wed 2013-07-10 11:24:44: *  Evaluating ~all: match
Wed 2013-07-10 11:24:44: *  Result: softfail
Wed 2013-07-10 11:24:44:  End SPF results
Wed 2013-07-10 11:24:44: --> 250 , Sender ok
Wed 2013-07-10 11:24:44: <-- RCPT TO:
Wed 2013-07-10 11:24:44: --> 250 , Recipient ok
Wed 2013-07-10 11:24:45: <-- DATA
Wed 2013-07-10 11:24:45: Creating temp file (SMTP):
d:\mdaemon\queues\temp\md5129501.tmp
Wed 2013-07-10 11:24:45: --> 354 Enter mail, end with .
Wed 2013-07-10 11:24:49: Message size: 139586 bytes
Wed 2013-07-10 11:24:49: Performing DKIM lookup
Wed 2013-07-10 11:24:49: *  File: d:\mdaemon\queues\temp\md5129501.tmp
Wed 2013-07-10 11:24:49: *  Message-ID:
b4bxk0l78649ourrty6a5up6ic2wslw75id...@caberawit.com
Wed 2013-07-10 11:24:51: *  Result: neutral
Wed 2013-07-10 11:24:51:  End DKIM results
Wed 2013-07-10 11:24:51: Performing DomainKeys lookup (Sender:
hp_prin...@caberawit.com)
Wed 2013-07-10 11:24:51: *  File: d:\mdaemon\queues\temp\md5129501.tmp
Wed 2013-07-10 11:24:51: *  Message-ID:
b4bxk0l78649ourrty6a5up6ic2wslw75id...@caberawit.com
Wed 2013-07-10 11:24:51: *  Querying for policy: caberawit.com
Wed 2013-07-10 11:24:51: *Querying: _domainkey.caberawit.com ...
Wed 2013-07-10 11:25:51: *  DNS: 60 second wait for DNS response exceeded
(DNS Server: 56.154.70.1)
Wed 2013-07-10 11:25:56: *DNS: *  Name server reports domain name
unknown
Wed 2013-07-10 11:25:56: *  Result: neutral
Wed 2013-07-10 11:25:56:  End DomainKey