SPAM-Present their email like ours

Discussion forum for Enterprise Edition.
Post Reply
dottysbb
Posts: 4
Joined: Fri Nov 07, 2014 11:54 am

SPAM-Present their email like ours

Post by dottysbb » Thu Oct 04, 2018 10:56 am

Hello all,
In last one month, we are facing a very big spam attack and we cannot take any actions for it.
We got emails, which pretend that are sent by our domain (masking like our colleagues) ... in sort of someone@ourdomain.comsspi.adomi2@kk-sano.co.jp.
MXScan and SPF dont match this as spam , which is strange, because this is obviously not sent by our domain.
Here is the full email properties:

Code: Select all

Received-SPF: pass (ourdomain.com: domain of kk-sano.co.jp designates 163.44.3.2 as permitted sender)
client-ip=163.44.3.2
Received: from dc56.etius.jp ([163.44.3.2]) by ourdomain.com with MailEnable ESMTP; Thu, 4 Oct 2018 06:56:49 +0300
Received: (qmail 19350 invoked by SAV 20181003.001 by uid 0); 4 Oct 2018 12:56:46 +0900
Received: from unknown (HELO 10.14.51.18) (sspi.adomi2@kk-sano.co.jp@24.139.176.42)
  by dc56.etius.jp (163.44.3.2) with ESMTPA; 4 Oct 2018 12:56:46 +0900
Date: Wed, 03 Oct 2018 23:50:35 -0400
From: Domain.com <someone@ourdomain.com> <sspi.adomi2@kk-sano.co.jp>
To: someoneelse@ourdomain.com
Message-ID: <3745744969174119589.D4AEF1AEE7C16F93@ourdomain.com>
Subject: Sales Receipt
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_Part_11561_3398992923.19995388301088820257"
X-Envelope-Sender: sspi.adomi2@kk-sano.co.jp
X-MXScan-Scan: Scanned by MxScan 3.1.101.0 for SERVERME
X-MXScan-Msgid: 03BCFE23D05A49A5B45E30427849022E_
X-MXScan-Country-Sequence: JAPAN->Destination
X-MXScan-AntiSpam: CLAM_SANE [Pass], KEYWORD [Pass], COUNTRYFILTER [Pass], URLBL [Pass], SPAMASSASSIN [1.3 (RDNS_NONE)], DCC_CHECK [Body=1 Fuz1=1 Fuz2=42 (1)], BACKSCATTER [Pass], SENDERBASE [SB_PASS]
X-MXScan-SpamScore: 2.3
X-MXScan-ProcessingTime: 1.484 sec(s)
Return-Path: <sspi.adomi2@kk-sano.co.jp>
[/i]

We cannot filter them by IP or domain, because every mail is from different IP address or domain.
Spam attack sends email almost every night in non-working time and they are about like 40-50 emails per day to different mailboxes and groups.

PeteBatin
Posts: 21
Joined: Fri Jan 22, 2016 9:32 am

Re: SPAM-Present their email like ours

Post by PeteBatin » Thu Oct 04, 2018 10:58 am

We're facing the exact same problem. See my post here https://www.mailenable.com/forum/viewto ... =7&t=42612

Post Reply