We are currently receiving lots of password phishing mails with envelope sender and From: header [EMAIL PROTECTED] and Reply-To: [EMAIL PROTECTED]
The connecting mail servers que41.charter.net[209.225.8.24] que51.charter.net[209.225.8.25] do apparently *not* stop re-connecting after receiving REJECT (554) errors, but keep coming back with the same sender-recipient pairs. That's interesting. I am seeing mailgw1.lmco.com sending repeated mails From <> to [EMAIL PROTECTED], where [EMAIL PROTECTED] is valid but the 551 is spurious (yes, that's a username with a number prepended). I am sending 554 each time. period is 1h20m to 1h30m or so.
pgpWnP6ovuvZe.pgp
Description: PGP signature