yu.fanks 發表於 2008-12-26 08:24:56

一直收到自己寄給自己的垃圾信

最近一直收到自己寄給自己的垃圾信,怪的是連查看電子郵件信箱真的也是自己的,可是確定沒有自己寄給自己,排除電腦中毒現象,請問有沒有那位前輩遇過,該問題mail server該如何防堵呢?

zxman0126 發表於 2016-4-5 14:34:22

感謝!可是權限不夠...我也依職受到偽造信困擾
最近還發生實際詐騙....

MarchFun 發表於 2008-12-26 10:30:55

用這招POP Before SMTP
http://www.suma.tw/thread-881-1-1.html

lp78789789 發表於 2016-3-31 10:17:38

公司目前也是一直有這問題存在,受教了    謝謝

MarchFun 發表於 2008-12-26 09:30:05

以前碰到過。如果自己沒中毒的話,那可能就是你的朋友中毒或被垃圾客拿來利用。

你可以檢查一下 SMTP IN 的 Log,看看這些信是否來自外部。

shem888 發表於 2008-12-26 10:06:02

我近日也是一直收到自己的垃圾郵件 , 查過是從外面假冒的 ,鎖 IP (189.106.87.81) 過幾天他又換一個 ...
應該可以用DNS-BL來封鎖 , 但開DNS-BL會有 2-3 個客人的信會進不來 . 真的很煩 !!!
還有其他方法嗎 ?


Fri 2008-12-26 03:02:46: Session 901; child 2; thread 968
Fri 2008-12-26 03:02:31: Accepting SMTP connection from
Fri 2008-12-26 03:02:31: Performing PTR lookup (81.87.106.189.IN-ADDR.ARPA)
Fri 2008-12-26 03:02:32: *D=81.87.106.189.IN-ADDR.ARPA TTL=(7200) PTR=
Fri 2008-12-26 03:02:32: *Gathering A records...
Fri 2008-12-26 03:02:32: ---- End PTR results
Fri 2008-12-26 03:02:32: --> 220 xxxx.com.tw ESMTP MDaemon 10.0.2; Fri, 26 Dec 2008 03:02:32 +0800
Fri 2008-12-26 03:02:41: <-- EHLO 189106087081.user.veloxzone.com.br
Fri 2008-12-26 03:02:41: --> 250-xxxx.com.tw Hello 189106087081.user.veloxzone.com.br, pleased to meet you
Fri 2008-12-26 03:02:41: --> 250-ETRN
Fri 2008-12-26 03:02:41: --> 250-AUTH=LOGIN
Fri 2008-12-26 03:02:41: --> 250-AUTH LOGIN CRAM-MD5
Fri 2008-12-26 03:02:41: --> 250-8BITMIME
Fri 2008-12-26 03:02:41: --> 250 SIZE 0
Fri 2008-12-26 03:02:43: <-- MAIL FROM:<[email protected]> SIZE=1632
Fri 2008-12-26 03:02:43: Performing IP lookup (xxxx.com.tw)
Fri 2008-12-26 03:02:43: *D=xxxx.com.tw TTL=(60) A=
Fri 2008-12-26 03:02:43: *P=010 S=000 D=runrun.com.tw TTL=(60) MX= {60.xxx.xx.xx}
Fri 2008-12-26 03:02:43: ---- End IP lookup results
Fri 2008-12-26 03:02:43: --> 250 <[email protected]>, Sender ok
Fri 2008-12-26 03:02:44: <-- RCPT TO:<[email protected]>
Fri 2008-12-26 03:02:44: Performing DNS-BL lookup (189.106.87.81 - connecting IP)
Fri 2008-12-26 03:02:44: *zen.spamhaus.org - failed - 127.0.0.11
Fri 2008-12-26 03:02:44: ---- End DNS-BL results
Fri 2008-12-26 03:02:44: --> 250 <[email protected]>, Recipient ok
Fri 2008-12-26 03:02:44: <-- DATA
Fri 2008-12-26 03:02:44: Creating temp file (SMTP): c:\mdaemon\temp\md50000076324.tmp
Fri 2008-12-26 03:02:44: --> 354 Enter mail, end with <CRLF>.<CRLF>
Fri 2008-12-26 03:02:45: Message size: 1634 bytes
Fri 2008-12-26 03:02:45: Performing DomainKeys lookup (Sender: [email protected])
Fri 2008-12-26 03:02:45: *File: c:\mdaemon\temp\md50000076324.tmp
Fri 2008-12-26 03:02:45: *Message-ID: n/a
Fri 2008-12-26 03:02:45: *Querying for policy: xxxx.com.tw
Fri 2008-12-26 03:02:45: *    Querying: _domainkey.xxxx.com.tw ...
Fri 2008-12-26 03:02:45: *    DNS: *Name server reports domain name unknown
Fri 2008-12-26 03:02:45: *Result: neutral
Fri 2008-12-26 03:02:45: ---- End DomainKeys results
Fri 2008-12-26 03:02:45: Passing message through AntiVirus (Size: 1634)...
Fri 2008-12-26 03:02:45: *Message is clean (no viruses found)
Fri 2008-12-26 03:02:45: ---- End AntiVirus results
Fri 2008-12-26 03:02:46: Message creation successful: c:\mdaemon\inbound\md50000520101.msg
Fri 2008-12-26 03:02:46: --> 250 Ok, message saved <Message-ID: >
Fri 2008-12-26 03:02:46: <-- QUIT
Fri 2008-12-26 03:02:46: --> 221 See ya in cyberspace
Fri 2008-12-26 03:02:46: SMTP session successful (Bytes in/out: 1764/414)
Fri 2008-12-26 03:02:46: ----------

shem888 發表於 2008-12-29 10:30:51

我的mail server 一直有設定 pop before Smtp
    還是一直出現 自己寄給自己的垃圾郵件 ...

MarchFun 發表於 2008-12-29 10:46:37

那再加上這一招:
IP Shielding (防護罩) 抵禦偽造信件

shem888 發表於 2008-12-31 10:54:18

已經成功擋住 !!! 感謝 !!!原因真的是POP before SMTP ....

我之前有參改MarchFun'r的說明來設定 ,可能是多次改版而被修改:
在POP before SMTP 的設定下的四個選項 都被打勾,

只要將第 3 個:
Don't apply POP Before SMTP to messages sent to local accounts, 打勾取消就ok !
我也找到被擋下垃圾信的Log , 如下 :xxxx   must check for new mail first



Wed 2008-12-31 02:52:29: Session 7691; child 1; thread 3124
Wed 2008-12-31 02:52:27: Accepting SMTP connection from
Wed 2008-12-31 02:52:27: Performing PTR lookup (99.212.40.162.IN-ADDR.ARPA)
Wed 2008-12-31 02:52:27: *D=99.212.40.162.IN-ADDR.ARPA TTL=(1440) PTR=
Wed 2008-12-31 02:52:27: *Gathering A records...
Wed 2008-12-31 02:52:27: *D=h99.212.40.162.dynamic.ip.windstream.net TTL=(1440) A=
Wed 2008-12-31 02:52:27: ---- End PTR results
Wed 2008-12-31 02:52:27: --> 220 xxxx.com.tw ESMTP MDaemon 10.0.2; Wed, 31 Dec 2008 02:52:27 +0800
Wed 2008-12-31 02:52:28: <-- EHLO h99.212.40.162.dynamic.ip.windstream.net
Wed 2008-12-31 02:52:28: Performing IP lookup (h99.212.40.162.dynamic.ip.windstream.net)
Wed 2008-12-31 02:52:28: *D=h99.212.40.162.dynamic.ip.windstream.net TTL=(1440) A=
Wed 2008-12-31 02:52:28: ---- End IP lookup results
Wed 2008-12-31 02:52:28: --> 250-xxxx.com.tw Hello h99.212.40.162.dynamic.ip.windstream.net, pleased to meet you
Wed 2008-12-31 02:52:28: --> 250-ETRN
Wed 2008-12-31 02:52:28: --> 250-AUTH=LOGIN
Wed 2008-12-31 02:52:28: --> 250-AUTH LOGIN CRAM-MD5
Wed 2008-12-31 02:52:28: --> 250-8BITMIME
Wed 2008-12-31 02:52:28: --> 250 SIZE 0
Wed 2008-12-31 02:52:29: <-- MAIL FROM:<[email protected]> SIZE=1618
Wed 2008-12-31 02:52:29: Performing IP lookup (xxxx.com.tw)
Wed 2008-12-31 02:52:29: *D=xxxx.com.tw TTL=(60) A=
Wed 2008-12-31 02:52:29: *P=010 S=000 D=xxxx.com.tw TTL=(25) MX= {60.xxxx.xx.83}
Wed 2008-12-31 02:52:29: ---- End IP lookup results
Wed 2008-12-31 02:52:29: --> 550 [email protected] must check for new mail first
Wed 2008-12-31 02:52:29: <-- QUIT
Wed 2008-12-31 02:52:29: --> 221 See ya in cyberspace
Wed 2008-12-31 02:52:29: SMTP session terminated (Bytes in/out: 96/318)

MarchFun 發表於 2008-12-31 11:09:29

不太對喔!
Don't apply POP Before SMTP to messages sent to local accounts, 打勾取消
表示寄給本地帳號的信不要套用 POP Before SMTP,這樣不是讓垃圾郵件更容易進來嗎?為什麼之前開啟了 POP Before SMTP 後還有信可以假冒,有可能是因為在那之前不久你剛好收過信?

shem888 發表於 2009-1-5 13:54:34

8# MarchFun

沒有錯la ..... Don't apply POP Before SMTP to messages sent to local accounts 英翻中:

當郵件發送到本地帳戶不適用 POP Before SMTP ,

打勾代表 送給 Local User不用 POP Before SMTP
不打勾    送給Local User   是要 POP Before SMTP

MarchFun 發表於 2009-1-5 22:22:11

9# shem888
沒有錯la ..... Don't apply POP Before SMTP to messages sent to local accounts 英翻中:

當郵件發送到本地帳戶不適用 POP Before SMTP ,

打勾代表 送給 Local User不用 POP Before SMTP
不打勾    送給Local User   是要 POP Before SMTP
是啊!這是負負得正的問題...是我被弄糊塗了!我們這裏也是沒勾選:P

hank_hcr 發表於 2009-3-6 10:11:36

我也相同的問題,一直無法解決!!

30678 發表於 2009-5-18 11:04:32

感謝分享我也來實驗看看~~~~~~

lefov 發表於 2009-8-10 09:39:01

感謝版上眾大的分享
最近也是被垃圾信件問題所困擾

gn00337958 發表於 2010-6-29 13:47:28

感謝各位先進詳細的說明,我也來試試看此設定

gn00337958 發表於 2010-6-29 13:52:54

垃圾郵件也是公司一直所困擾的,在試試先進所教導的方式囉

飛恩 發表於 2010-8-4 18:02:41

解決辦法我也想看啊
權限不夠@@

rx8killer 發表於 2011-1-6 09:23:29

副董的電腦中毒了
趕緊來試看看

mmmm168 發表於 2011-1-11 12:55:29

我的天啊,我也是現在才發現這個負負得正的勾選,真要命,我也是四個全勾,剛剛被老闆娘叫去問了,好險在這裡發現這個解答,感謝。

rogerben 發表於 2011-3-10 16:59:47

我想解決我公司MAIL 的問題.在此發言.希望不會被當成灌水..

pilotliu 發表於 2011-3-11 11:39:09

受教了,即時解決了我的問題
頁: [1] 2
檢視完整版本: 一直收到自己寄給自己的垃圾信