Re: [mailop] [INFORMATIONAL] Larger than normal spam outbreak from web.de

2021-08-27 Thread Michael Kliewe via mailop
Hello, the "mout-xforward" servers of GMX + web.de are specifically used for "low reputation traffic", see: https://postmaster.web.de/en/email-server https://postmaster.gmx.net/en/email-server As far as I know they are used for forwarding mails which are likely/definitly spam (which were put

Re: [mailop] [INFORMATIONAL] Larger than normal spam outbreak from web.de

2021-08-26 Thread Michael Peddemors via mailop
Allowed to relay? Otherwise of course, my comment stands.. the ones that go MX-Direct are usually blocked, but if they relay through the web.de, per user rate limiters should kick in before it gets to this notable volume. Everyone IS using per user AUTH rate limiters correct? No one is still a

Re: [mailop] [INFORMATIONAL] Larger than normal spam outbreak from web.de

2021-08-26 Thread Chris via mailop
Someone inside web.de land got infected with a variant of Gamut spewing bitcoin extortion scams, and for one reason or other, they routed thru web.de's mail servers INSTEAD of going MX-direct (perhaps a port 25 redirector). The raw emails have all the fingerprints of gamut, except that it went

Re: [mailop] [INFORMATIONAL] Larger than normal spam outbreak from web.de

2021-08-26 Thread Jarland Donnell via mailop
I've been seeing a trend from there the last few days as well. More were filtered successfully than not, but the ones that slipped through all looked similar: https://paste.mxrouteapps.com/?0b5071a4b2cb089d#HYSAYYMSheQbYiXCZHMfjaVoqRM7naZiXKPkAK2UHju6 On 2021-08-26 14:36, Michael Peddemors via

[mailop] [INFORMATIONAL] Larger than normal spam outbreak from web.de

2021-08-26 Thread Michael Peddemors via mailop
82.165.159.12 x5 mout-xforward.gmx.net 82.165.159.13 x7 mout-xforward.gmx.net 82.165.159.14 x5 mout-xforward..gmx.net 82.165.159.2x66 mout-xforward.web.de 82.165.159.3x62 mout-xforward.web.de 82.165.159.34 x68 mout-xforward.web.de 82.165.159.35 x56