I want to know the from where the spam are genrated for my domain & how can i block using Exchange server 2003 and Trend Micro InterScan Security suites 5.5.
Can anyone let me know how can I get the IP address and domain name of the orignal spammer. Here with i am sending the header I received with my email.
Note: for security reason I am using sanjana@mydomainname.com to hide my domain name.
Following is the Header: –
Microsoft Mail Internet Headers Version 2.0
Received: from mygateway.mydomainname.com ([192.168.100.16]) by server.mydomainname.com with Microsoft SMTPSVC(6.0.3790.1830);
Sat, 30 Aug 2008 12:18:55 +0400
Delivered-To: To: sanjana@mydomainname.com
Received: by 10.199.220.17 with SMTP id x15cs289914muq; Sat, 30 Aug
2008 04:12:51 -0500 (PDT)
Received: by 10.108.215.50 with SMTP id c80mr2918768ybg.191.1279460844068;
Sat, 30 Aug 2008 04:12:51 -0500 (PDT)
Return-Path:
Received: from n71.bullet.mail.mud.yahoo.com (n01.bullet.mail.mud.yahoo.com
[88.252.36.130]) by mx.google.com with SMTP id
5si2674079ywl.4.2008.08.22.22.05.15; Sat, 30 Aug 2008 04:12:51 -0500
(PDT)
Received-SPF: pass (google.com: domain of Hendricks86@acsinc.net designates
88.252.36.130 as permitted sender) client-ip=88.252.36.130;
DomainKey-Status: good (test mode)
Authentication-Results: mx.google.com; spf=pass (google.com: domain of
Hendricks86@acsinc.net designates 88.252.36.130 as permitted sender)
smtp.mail=Hendricks86@acsinc.net; domainkeys=pass (test mode)
header.From=Hendricks86@acsinc.net
Received: from [68.142.132.275] by n01.bullet.mail.mud.yahoo.com with NNFMP;
Sat, 30 Aug 2008 04:12:51 -0500
Received: from [76.13.15.22] by t2.bullet.mud.yahoo.com with NNFMP; Sat, 30
Aug 2008 04:12:51 -0500
Received: from [76.13.14.147] by t1.bullet.mail.ac0.yahoo.com with NNFMP;
Sat, 30 Aug 2008 04:12:51 -0500
Received: from [127.0.0.1] by omp126.mail.ac7.yahoo.com with NNFMP; Sat, 30
Aug 2008 04:12:51 -0500
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 740977.47222.bm@omp281.mail.ac0.yahoo.com
Received: (qmail 5429 invoked by uid 60001); Sat, 30 Aug 2008 04:12:51 -0500
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com;
h=X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-T
ype:Message-ID;
b=ihWzks23rHLG2ivVUaQPEXNLo4wgqDhrcm6Rkszt4xmi0117J9BYUgeq13p606hb8rJbwPm2q
bi5buQG7xoX/x/SARs9U230cGGsMiUdcluKkVSO/IotEBEllWLaNHxwovoFIqpc15SGZJWPXxoN
8LTbePt1nfIHxiIWaSPxPEI=;
X-YMail-OSG: YtddQHAVM1k4YpfA8KLhDQewHq.RJqx40aZqsveLtPdrMk.QMS.wQ2di50gZXCt
tVcg–
Received: from [88.252.36.130] by web68648.mail.sp1.yahoo.com via HTTP; Sat,
30 Aug 2008 04:12:51 -0500 PDT
X-Mailer: YahooMailRC/9771.00 YahooMailWebService/0.8.631.3
Date: Sat, 30 Aug 2008 04:12:51 -0500 (PDT)
From: Taylor Harris
Subject: You want yours bigger, all men do
To: To: sanjana@mydomainname.com
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=”0-1761366887-1219460752=:76606″
Message-ID: <954734.77041.qm@web83006.mail.sp1.yahoo.com>
X-imss-version: 2.051
X-imss-result: Passed
X-imss-scores: Clean:0.27270 C:2 M:3 S:5 R:5
X-imss-settings: Baseline:2 C:2 M:2 S:4 R:4 (0.1500 0.1500)
X-OriginalArrivalTime: 30 Aug 2008 08:18:55.0843 (UTC) FILETIME=[0B956330:01C90A79]
–0-1761366887-1219460752=:76606
Content-Type: text/plain; charset=us-ascii
–0-1761366887-1219460752=:76606
Content-Type: text/html; charset=us-ascii
–0-1761366887-1219460752=:76606?
Kindly let me know the oregnal sender & how to block that domain and using that IP addresses.
Thanks a lot for helping me out.