Hi list

We have been receiving a lot of spam from the .jp tld lately.  What's more is 
this:

Received: from vlaamse-kern.com (pl027.nas934.d-osaka.nttpc.ne.jp 
[61.197.82.27])
        by giga.vlaamse-kern.com (8.13.1/8.13.1) with SMTP id jADFi1Wo028374
        for [EMAIL PROTECTED]; Sun, 13 Nov 2005 16:44:02 +0100

Note that OUR domain is vlaamse-kern.com and that the sender pretends to be 
vlaamse-kern.com as well!

Other statistics:

From: =?iso-2022-jp?B?QVRTVVNISQ==?=<[EMAIL PROTECTED]>

From pretends to be hotmail but is not.

With this info, is it possible to craft a rule that rejects these messages?

We have spamassassin running via kmail on all user accounts and I noticed a 
spamassasin subdirectory in /etc/mail on the smtp server.  I don't know if 
sendmail calls it automatically?

With kind regards


Andy

-- 
Now listening to Top! Radio Live www.topradio.be/stream on amaroK
Geek code: www.vlaamse-kern.com/geek
Registered Linux User No 379093
If life was for sale, what would be its price?
www.vlaamse-kern.com/sas/ for free php utilities
--

Attachment: pgpBEHRy7QpDS.pgp
Description: PGP signature

Reply via email to