This posting made from the web-site.  Please reply via
email in addition to the group.  Thanks.
------------------------------------------------------

I'm finding that SpamCop isn't working for me these days. Ever since I changed my 
provider and have to operate with two different IPs - one for computer management and 
the other for my MX records and SMTP/POP handling - I've been unable to get SpamCop to 
allow me to report the perpetrators of spam. Here's what happens using one sample 
email:


SpamCop version 1.3.1 (c) Julian Haight, Joel Martin 1998-2001 All Rights Reserved

Saved email:
This page may be saved for future reference:
http://spamcop.net/sc?id=z19053511zee9c71859115db129f01ec31ad569740z

<== this is the header line from my mail server that forwards email to SpamCop ==>

Parsing header:

Received: from smtp.radiantworld.net (indatamart.com.63.77.64.in-addr.arpa 
[64.77.63.85] (may be forged)) by sam.julianhaight.com (8.10.0/8.10.0) with SMTP id 
f3TCT0331140 for <[EMAIL PROTECTED]>; Sun, 29 Apr 2001 08:29:00 -0400
Possible spammer: 64.77.63.85
[show] "nslookup 85.63.77.64.dialups.mail-abuse.org." (checking ip) not found
[show] "nslookup indatamart.com.63.77.64.in-addr.arpa" (checking ip) ip not found; 
indatamart.com.63.77.64.in-addr.arpa discarded as fake.
[show] "dig indatamart.com.63.77.64.in-addr.arpa mx" (digging for mail exchanger) 
Can't find mailserver.
[show] "dig com.63.77.64.in-addr.arpa mx" (digging for mail exchanger) Can't find 
mailserver.
[show] "nslookup smtp.radiantworld.net" (checking ip) ip = 64.45.54.129
[show] "nslookup smtp.radiantworld.net" (checking ip) smtp.radiantworld.net not 
64.77.63.85, discarded as fake.
[show] "dig -x 64.77.63.85 soa" (digging for start of authority) - not found
ips don't match; smtp.radiantworld.net discarded as fake
Taking name from IP...
[show] "nslookup 64.77.63.85" (getting name) indatamart.com.63.77.64.in-addr.arpa 
invalid
[show] "dig mx indatamart.com.63.77.64.in-addr.arpa" (digging for mail exchanger) 
64.77.63.85 is not MX for indatamart.com.63.77.64.in-addr.arpa
[show] "nslookup 85.63.77.64.blackholes.mail-abuse.org." (checking ip) not found
[show] "nslookup 85.63.77.64.inputs.orbs.org." (checking ip) not found
Received line partially untrusted

OK fine, the receive line is partially untrusted because my hosting provider allows me 
to use my own ip at 64.45.54.129 for whatever I like, but the one that is the first IP 
on the card, 64.77.63.85, is for management purposes and is not linked to a domain 
name. Fair enough - it's an error, but not an indication of spam.



<== this is the header line that is for the machine that sent the spam to me ==>

Received: From athena.isicom.fr [194.98.30.34] by radiantworld.net [64.45.54.129] with 
MsgCore/NT [(C) 1998,2001 Nosque Workshop] BD0230 id28DAD8A4221E5AEAE5E70110; Sun, 29 
Apr 2001 05:29:08 -0700
Masking IP-based 'by' clause.
Received: From athena.isicom.fr [194.98.30.34] by radiantworld.net with MsgCore/NT 
[(C) 1998,2001 Nosque Workshop] BD0230 id28DAD8A4221E5AEAE5E70110; Sun, 29 Apr 2001 
05:29:08 -0700
no from
no auth from
[show] "nslookup 85.63.77.64.dialups.mail-abuse.org." (checking ip) not found
Possible spammer: 194.98.30.34
Taking name from IP...
[show] "nslookup 194.98.30.34" (getting name) 194.98.30.34 = athena.isicom.fr
[show] "nslookup athena.isicom.fr" (checking ip) ip = 194.98.30.34
[show] "nslookup 34.30.98.194.blackholes.mail-abuse.org." (checking ip) not found
[show] "nslookup 34.30.98.194.inputs.orbs.org." (checking ip) not found
Chain error; 'radiantworld.net' != '' or ''; received line discarded

How this is a chain error is beyond me. Perhaps I don't understand the process well 
enough, but this receive line has nothing to do with the first one, which is from the 
forward to SpamCOp, so why does the SpamCop system think this is a chain error on 
smtp.radiantworld.net? And the !- '' or ''; seems to me to be less than informative. 
How could any mail exchanger ip address = '' or ''? This seems to be an error in 
programming or a possible clever scheme by the spammers to eliminate SpamCop reports. 
In either case, it doesn't work. This is the spamming machine yet the SpamCop report 
doesn't even give me the option of reporting this ip address to anyone.



<== this is the receive line that appears to be used by the spammer to forward into 
the spamming machine ==>

Received: from mx4.mail.yahoo.com - 63.53.46.120 by isicom.fr with Microsoft 
SMTPSVC(5.5.1775.675.6); Sun, 29 Apr 2001 14:13:36 +0200
no auth from
[show] "nslookup 85.63.77.64.dialups.mail-abuse.org." (checking ip) not found
Possible spammer: 63.53.46.120
[show] "nslookup mx4.mail.yahoo.com" (checking ip) ip not found; mx4.mail.yahoo.com 
discarded as fake.
[show] "dig mx4.mail.yahoo.com mx" (digging for mail exchanger) Can't find mailserver.
[show] "dig mail.yahoo.com mx" (digging for mail exchanger) Can't find mailserver.
Taking name from IP...
[show] "nslookup 63.53.46.120" (getting name) 63.53.46.120 = 
pool-63.53.46.120.irvn.grid.net
[show] "nslookup pool-63.53.46.120.irvn.grid.net" (checking ip) ip = 63.53.46.120
[show] "nslookup 120.46.53.63.blackholes.mail-abuse.org." (checking ip) not found
[show] "nslookup 120.46.53.63.inputs.orbs.org." (checking ip) not found
Chain error; 'isicom.fr' != '' or ''; received line discarded
Right now, this email would be detained by SpamCop filters: chain error

Again, another chain error and no way to report this. 

So it goes for all my spam. My own email service that forwards to SpamCop is 
identified as the spammer and all others are rejected with chain errors.

Does anyone have any insights as to how to get SpamCop to work properly? Something I 
can change on my smtp server? (Changing the MX record in smtp.radiantworld.net to the 
management ip address is not an option) Or am I just up the creek without a paddle and 
should quit using SpamCop?


_______________________________________________
SpamCop-Help mailing list
[EMAIL PROTECTED]
http://news.spamcop.net/mailman/listinfo/spamcop-help

Reply via email to