Spam Deluge

Computer problems not related to MailWasher or other Firetrust programs getting you down. Put the geeks to the test by asking about your problem here.
PaulEaston
Student Sheep
Posts: 10
Joined: Wed Jul 07, 2010 4:09 am

Spam Deluge

Mon Dec 20, 2010 3:29 am

(Sorry if this is in the wrong section. Admin please feel free to move if necessary)

Is anybody else currently experiencing sudden very high (250+ a day) levels of spam? I seem to get a few days when it’s very high then it stops for about a week before resuming. Much of it is easily identifiable because of the obvious 'slfsdhjbfjk [at] genuinedomain.com'-type addresses - quite a lot seem to be hijacking Canadian (.ca) domains at the moment.

Fortunately the mailserver for my web domain has a very good filter and is catching around 99% of all the crap that’s being sent - I only noticed this because I occasionally check my Junk mailbox just in case some genuine mail has been caught by accident.

The remaining few that slip through that net get dealt with by the excellent MailWasher Pro.

So, while the amount of spam itself doesn’t bother me - most of it gets zapped before I see it - I’m just intrigued by the very high volume of spam emails and wondered whether anybody else was experiencing this.

On Friday I got over 300 and yesterday over yet until recently I would get less than 10 a day on average!

And before anybody suggests it - no I have not been registering with dodgy websites! In fact for any website that requires an email address - unless it’s an obviously-reputable one - I have a gmail account, which gets spammed on a regular basis.
User avatar
stan_qaz
Omniscient Kiwi
Location: Gilbert, Arizona
Posts: 8671
Joined: Fri Jul 25, 2008 5:13 am

Re: Spam Deluge

Mon Dec 20, 2010 7:19 am

It is likely that someone that has your e-mail address stored on their computer is running Windows and got a computer cootie that harvested your address and sent it off to a spammer to use and resell to his spammer buddies.

No solution but to not e-mail your Windows using friends from your good e-mail address. You can use a throw-away one for your Windows using friends and once it starts getting hammered drop it and move to a new one.

On a bad day the spammer won't send you spam but will use your address as the reply-to / from address on a spam and then you'll see thousands of bogus bounce and service messages. Now that smarts even with MW until you have filters in place to detect and delete the bogus junk.
I am not a Firetrust employee just a MW user.
--
First rule of computer consulting: Sell a customer a Linux computer and you'll eat for a day,
sell a customer a Windows computer and you'll eat for a lifetime.
PaulEaston
Student Sheep
Posts: 10
Joined: Wed Jul 07, 2010 4:09 am

Re: Spam Deluge

Mon Dec 20, 2010 8:58 pm

Thanks, Stan - I've previously experienced the fake bounces a couple of years ago. It's not likely to happen now because my email host only allows incoming mail addressed to a limited number of pre-defined email addresses and automatically rejects something like kasjcvjkdb@mydomain.com so they don't even get through to their spam filter.

I quite understand how email addresses are harvested but my question was more about why I have suddenly seen such a massive increase in the past week or so, When I've previously been getting around 10 spam emails a day I'm obviously going to want to know why that figure has suddenly escalated to around 250-300 a day in the past week or so!
User avatar
stan_qaz
Omniscient Kiwi
Location: Gilbert, Arizona
Posts: 8671
Joined: Fri Jul 25, 2008 5:13 am

Re: Spam Deluge

Tue Dec 21, 2010 7:21 am

I see my spam load jump up and down based on addresses getting harvested all the time. I get an address compromised and it will pick up a few hundred spams in the next few days. Since I use a lot of dedicated addresses I can often identify the person who has been infested and let them know to clean their computer, usually before they find it on their own from a system scan. I spamcop the spams and never activate the tracking stuff in the spam message and they drop me off their list thinking it is a bad address or a spamtrap and my spam count goes back down.

I really do think that you are seeing the results of your address getting harvested, what you reported is the usual result of that happening.


I"m not sure how a server rejecting bounces works when the spammer is directing them to a harvested but real e-mail address that you are using. Rejecting bounces or any other mail to a non-existing address I understand but that hasn't been an issue here as all have been directed to addresses that are in use.
I am not a Firetrust employee just a MW user.
--
First rule of computer consulting: Sell a customer a Linux computer and you'll eat for a day,
sell a customer a Windows computer and you'll eat for a lifetime.

Return to “General Tech. Help”