Re: Agressieve spam ( vind ik)
Geen idee, ik ben geen TN klant. Mail komt bij mij op eigen server (hosting) en wordt gelezen met Pegasus mail waar ik een tab "raw view" heb die de mails laat zien als "ruwe" data, zonder formatting en met inbegrip van alle "headers" zoals IP van de afzender, server van waar gestuurd werd e.d.
Het ziet er zo uit (mail van BD dat er een reactie was in deze thread):
Afhankelijk van de configuratie staat er bij jou niets meer waar bij mij "X-Spam-Status" begint. Dit wordt toegevoegd door spamassassin, de antispam op de mailserver.
De onderste "received by" is de eerste stap van de verzending van de mail, dat zie je ook aan de tijd die er bij staat. Ga je naar boven dan zie je de volgende stap en zo verder tot de bovenste waar je aflevering ziet op de mailserver (in jouw geval dus telenet).
De afzender van de BD mails is het IP adres 178.208.39.215 en dat kan je opzoeken met als resultaat:
Oorspronkelijk geplaatst door toerist
Bekijk bericht
Het ziet er zo uit (mail van BD dat er een reactie was in deze thread):
Return-Path: <*******@minoc.com>
Delivered-To: *******@******.com
Received: from goron.hyliahub.com
by goron.hyliahub.com with LMTP id mPglOqpYrFma1wcA3K39pA
for <******@******.com>; Sun, 03 Sep 2017 15:31:54 -0400
Return-path: <******@minoc.com>
Envelope-to: *******@*******.com
Delivery-date: Sun, 03 Sep 2017 15:31:54 -0400
Received: from relay-r12.mailprotect.be ([217.21.190.12]:42082 helo=relay-ix.mailprotect.be)
by goron.hyliahub.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256)
(Exim 4.89)
(envelope-from <******@minoc.com>)
id 1doacb-002A2G-Fs
for ******@*******.com; Sun, 03 Sep 2017 15:31:54 -0400
Received: from localhost (localhost [127.0.0.1])
by relay-ix.mailprotect.be (Postfix) with ESMTP id 2F09960B60
for <*******@*******.com>; Sun, 3 Sep 2017 21:31:11 +0200 (CEST)
X-Virus-Scanned: amavisd-new at relay.ix.mailprotect.be
Received: from relay.ix.combell-ops.net (178.208.39.215.static.hosted.by.combell.com [178.208.39.215])
by relay-ix.mailprotect.be (Postfix) with ESMTP id D70C660B8C
for <**********@********.com>; Sun, 3 Sep 2017 21:31:10 +0200 (CEST)
Date: Sun, 03 Sep 2017 19:31:10 +0000
To: ******@******.com
From: "Belgiumdigital forum - Digitale fotografie" <*******@belgiumdigital.com>
Auto-Submitted: auto-generated
Message-ID: <20170903193110.e79c41c10353@forum.belgiumdigital. com>
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-Mailer: vBulletin Mail via PHP
Subject: Reactie op bericht 'Agressieve spam ( vind ik)'
X-Spam-Status: No, score=-98.6
X-Spam-Score: -985
X-Spam-Bar: ---------------------------------------------------
X-Ham-Report: Spam detection software, running on the system "goron.hyliahub.com",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Beste on4bam, toerist heeft zojuist gereageerd op een discussie
getiteld Agressieve spam ( vind ik), waarop je bent geabonneerd in het forum
Chit Chat van het Belgiumdigital forum - Digitale fotografie. [...]
Content analysis details: (-98.6 points, 3.5 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-100 USER_IN_WHITELIST From: address is in the user's white-list
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low
trust
[217.21.190.12 listed in list.dnswl.org]
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
for more information.
[URIs: belgiumdigital.com]
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
4.0 SPF_FAIL SPF: sender does not match SPF record (fail)
[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;i....hyliahub.com]
-1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1%
[score: 0.0000]
X-Spam-Flag: NO
X-Antivirus: Avast (VPS 170903-0, 03/09/2017), Inbound message
X-Antivirus-Status: Clean
Delivered-To: *******@******.com
Received: from goron.hyliahub.com
by goron.hyliahub.com with LMTP id mPglOqpYrFma1wcA3K39pA
for <******@******.com>; Sun, 03 Sep 2017 15:31:54 -0400
Return-path: <******@minoc.com>
Envelope-to: *******@*******.com
Delivery-date: Sun, 03 Sep 2017 15:31:54 -0400
Received: from relay-r12.mailprotect.be ([217.21.190.12]:42082 helo=relay-ix.mailprotect.be)
by goron.hyliahub.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256)
(Exim 4.89)
(envelope-from <******@minoc.com>)
id 1doacb-002A2G-Fs
for ******@*******.com; Sun, 03 Sep 2017 15:31:54 -0400
Received: from localhost (localhost [127.0.0.1])
by relay-ix.mailprotect.be (Postfix) with ESMTP id 2F09960B60
for <*******@*******.com>; Sun, 3 Sep 2017 21:31:11 +0200 (CEST)
X-Virus-Scanned: amavisd-new at relay.ix.mailprotect.be
Received: from relay.ix.combell-ops.net (178.208.39.215.static.hosted.by.combell.com [178.208.39.215])
by relay-ix.mailprotect.be (Postfix) with ESMTP id D70C660B8C
for <**********@********.com>; Sun, 3 Sep 2017 21:31:10 +0200 (CEST)
Date: Sun, 03 Sep 2017 19:31:10 +0000
To: ******@******.com
From: "Belgiumdigital forum - Digitale fotografie" <*******@belgiumdigital.com>
Auto-Submitted: auto-generated
Message-ID: <20170903193110.e79c41c10353@forum.belgiumdigital. com>
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-Mailer: vBulletin Mail via PHP
Subject: Reactie op bericht 'Agressieve spam ( vind ik)'
X-Spam-Status: No, score=-98.6
X-Spam-Score: -985
X-Spam-Bar: ---------------------------------------------------
X-Ham-Report: Spam detection software, running on the system "goron.hyliahub.com",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Beste on4bam, toerist heeft zojuist gereageerd op een discussie
getiteld Agressieve spam ( vind ik), waarop je bent geabonneerd in het forum
Chit Chat van het Belgiumdigital forum - Digitale fotografie. [...]
Content analysis details: (-98.6 points, 3.5 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-100 USER_IN_WHITELIST From: address is in the user's white-list
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low
trust
[217.21.190.12 listed in list.dnswl.org]
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
for more information.
[URIs: belgiumdigital.com]
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
4.0 SPF_FAIL SPF: sender does not match SPF record (fail)
[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;i....hyliahub.com]
-1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1%
[score: 0.0000]
X-Spam-Flag: NO
X-Antivirus: Avast (VPS 170903-0, 03/09/2017), Inbound message
X-Antivirus-Status: Clean
De onderste "received by" is de eerste stap van de verzending van de mail, dat zie je ook aan de tijd die er bij staat. Ga je naar boven dan zie je de volgende stap en zo verder tot de bovenste waar je aflevering ziet op de mailserver (in jouw geval dus telenet).
De afzender van de BD mails is het IP adres 178.208.39.215 en dat kan je opzoeken met als resultaat:
178.208.39.215 BE Brussels, Brussels Capital, Belgium, Europe 1012 50.8333, 4.3333 100 Sentia N.V. COMBELL Network combell.com
Comment