This posting made from the web-site. Please reply via email in addition to the group. Thanks. ------------------------------------------------------ I'm finding that SpamCop isn't working for me these days. Ever since I changed my provider and have to operate with two different IPs - one for computer management and the other for my MX records and SMTP/POP handling - I've been unable to get SpamCop to allow me to report the perpetrators of spam. Here's what happens using one sample email: SpamCop version 1.3.1 (c) Julian Haight, Joel Martin 1998-2001 All Rights Reserved Saved email: This page may be saved for future reference: http://spamcop.net/sc?id=z19053511zee9c71859115db129f01ec31ad569740z <== this is the header line from my mail server that forwards email to SpamCop ==> Parsing header: Received: from smtp.radiantworld.net (indatamart.com.63.77.64.in-addr.arpa [64.77.63.85] (may be forged)) by sam.julianhaight.com (8.10.0/8.10.0) with SMTP id f3TCT0331140 for <[EMAIL PROTECTED]>; Sun, 29 Apr 2001 08:29:00 -0400 Possible spammer: 64.77.63.85 [show] "nslookup 85.63.77.64.dialups.mail-abuse.org." (checking ip) not found [show] "nslookup indatamart.com.63.77.64.in-addr.arpa" (checking ip) ip not found; indatamart.com.63.77.64.in-addr.arpa discarded as fake. [show] "dig indatamart.com.63.77.64.in-addr.arpa mx" (digging for mail exchanger) Can't find mailserver. [show] "dig com.63.77.64.in-addr.arpa mx" (digging for mail exchanger) Can't find mailserver. [show] "nslookup smtp.radiantworld.net" (checking ip) ip = 64.45.54.129 [show] "nslookup smtp.radiantworld.net" (checking ip) smtp.radiantworld.net not 64.77.63.85, discarded as fake. [show] "dig -x 64.77.63.85 soa" (digging for start of authority) - not found ips don't match; smtp.radiantworld.net discarded as fake Taking name from IP... [show] "nslookup 64.77.63.85" (getting name) indatamart.com.63.77.64.in-addr.arpa invalid [show] "dig mx indatamart.com.63.77.64.in-addr.arpa" (digging for mail exchanger) 64.77.63.85 is not MX for indatamart.com.63.77.64.in-addr.arpa [show] "nslookup 85.63.77.64.blackholes.mail-abuse.org." (checking ip) not found [show] "nslookup 85.63.77.64.inputs.orbs.org." (checking ip) not found Received line partially untrusted OK fine, the receive line is partially untrusted because my hosting provider allows me to use my own ip at 64.45.54.129 for whatever I like, but the one that is the first IP on the card, 64.77.63.85, is for management purposes and is not linked to a domain name. Fair enough - it's an error, but not an indication of spam. <== this is the header line that is for the machine that sent the spam to me ==> Received: From athena.isicom.fr [194.98.30.34] by radiantworld.net [64.45.54.129] with MsgCore/NT [(C) 1998,2001 Nosque Workshop] BD0230 id28DAD8A4221E5AEAE5E70110; Sun, 29 Apr 2001 05:29:08 -0700 Masking IP-based 'by' clause. Received: From athena.isicom.fr [194.98.30.34] by radiantworld.net with MsgCore/NT [(C) 1998,2001 Nosque Workshop] BD0230 id28DAD8A4221E5AEAE5E70110; Sun, 29 Apr 2001 05:29:08 -0700 no from no auth from [show] "nslookup 85.63.77.64.dialups.mail-abuse.org." (checking ip) not found Possible spammer: 194.98.30.34 Taking name from IP... [show] "nslookup 194.98.30.34" (getting name) 194.98.30.34 = athena.isicom.fr [show] "nslookup athena.isicom.fr" (checking ip) ip = 194.98.30.34 [show] "nslookup 34.30.98.194.blackholes.mail-abuse.org." (checking ip) not found [show] "nslookup 34.30.98.194.inputs.orbs.org." (checking ip) not found Chain error; 'radiantworld.net' != '' or ''; received line discarded How this is a chain error is beyond me. Perhaps I don't understand the process well enough, but this receive line has nothing to do with the first one, which is from the forward to SpamCOp, so why does the SpamCop system think this is a chain error on smtp.radiantworld.net? And the !- '' or ''; seems to me to be less than informative. How could any mail exchanger ip address = '' or ''? This seems to be an error in programming or a possible clever scheme by the spammers to eliminate SpamCop reports. In either case, it doesn't work. This is the spamming machine yet the SpamCop report doesn't even give me the option of reporting this ip address to anyone. <== this is the receive line that appears to be used by the spammer to forward into the spamming machine ==> Received: from mx4.mail.yahoo.com - 63.53.46.120 by isicom.fr with Microsoft SMTPSVC(5.5.1775.675.6); Sun, 29 Apr 2001 14:13:36 +0200 no auth from [show] "nslookup 85.63.77.64.dialups.mail-abuse.org." (checking ip) not found Possible spammer: 63.53.46.120 [show] "nslookup mx4.mail.yahoo.com" (checking ip) ip not found; mx4.mail.yahoo.com discarded as fake. [show] "dig mx4.mail.yahoo.com mx" (digging for mail exchanger) Can't find mailserver. [show] "dig mail.yahoo.com mx" (digging for mail exchanger) Can't find mailserver. Taking name from IP... [show] "nslookup 63.53.46.120" (getting name) 63.53.46.120 = pool-63.53.46.120.irvn.grid.net [show] "nslookup pool-63.53.46.120.irvn.grid.net" (checking ip) ip = 63.53.46.120 [show] "nslookup 120.46.53.63.blackholes.mail-abuse.org." (checking ip) not found [show] "nslookup 120.46.53.63.inputs.orbs.org." (checking ip) not found Chain error; 'isicom.fr' != '' or ''; received line discarded Right now, this email would be detained by SpamCop filters: chain error Again, another chain error and no way to report this. So it goes for all my spam. My own email service that forwards to SpamCop is identified as the spammer and all others are rejected with chain errors. Does anyone have any insights as to how to get SpamCop to work properly? Something I can change on my smtp server? (Changing the MX record in smtp.radiantworld.net to the management ip address is not an option) Or am I just up the creek without a paddle and should quit using SpamCop? _______________________________________________ SpamCop-Help mailing list [EMAIL PROTECTED] http://news.spamcop.net/mailman/listinfo/spamcop-help
