Today I am getting returning emails that have weird subjects (obviously spam), stating that the mail was rejected as spam.
Checking the IP the server seems to be my hosted server. http://www.klaustukai.lt/ (q2a 1.6.3) - Or is it just the returning mail?
Since I only use q2a on this site, I wonder if spammers have found a way of how to abuse the mailing scripts (e.g. the feedback form).
Has anyone had this situation before? Did you find a solution?
Example Body of Returning Email:
Received: from [80.67.18.5] (helo=mx05.ispgateway.de)
by atair.ispgateway.de with esmtp (Exim 4.68)
id 1YXw27-0002W0-6E; Tue, 17 Mar 2015 19:16:03 +0100
Return-path: <>
X-Envelope-To: agpl@klaustukai.lt
Received: from [212.227.15.26] (helo=mout-bounce.web.de)
by mx05.ispgateway.de with esmtps (TLSv1.2:DHE-RSA-AES256-GCM-SHA384:256)
(Exim 4.84)
id 1YXw27-0004DV-1q
for agpl@klaustukai.lt; Tue, 17 Mar 2015 19:16:03 +0100
Received: from mda by moweb001.server.lan id 0MVLws-1Z258O3pqo-00YmUX
Tue, 17 Mar 2015 19:16:02 +0100
Date: Tue, 17 Mar 2015 19:16:02 +0100
From: <keineantwortadresse@web.de>
To: agpl@klaustukai.lt
Subject: Mail delivery failed: returning message to sender
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
X-UI-Out-Filterresults: unknown:0;
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on
spamfilter18.ispgateway.de
X-Spam-Level:
X-Spam-Status: No, hits=-1.9 required=9999.0 tests=BAYES_20 autolearn=disabled
version=3.3.1
X-Spam-CMAETAG: v=2.1 cv=TbAYtHgh c=1 sm=0 tr=0 a=IrfWlsxY9BMA:10
a=IkcTkHD0fZMA:10 a=emO1SXQWCLwA:10 a=pGLkceISAAAA:8
a=T7oggLqKmhABh1HWmBQA:9 a=QEXdDO2ut3YA:10 a=jqkU2Be4inkA:10
xcat=Undefined/Undefined
X-Spam-CMAECATEGORY: 0
X-Spam-CMAESUBCATEGORY: 0
X-Spam-CMAESCORE: 0
Message-Id: <E1YXw27-0002W5-7V@atair.ispgateway.de>
X-Antivirus: avast! (VPS 150317-0, 17.03.2015), Inbound message
X-Antivirus-Status: Clean
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of
its recipients. This is a permanent error. The following address
failed:
<claudius.preiss@gmail.com>
Reason:
delivery retry timeout exceeded
--- The header of the original message is following. ---
Received: from [212.227.15.17] ([212.227.15.17]) by mx-ha.web.de (mxweb006)
with ESMTP (Nemesis) id 0MehfU-1YrcE90kRM-00OGt5; Tue, 17 Mar 2015 17:40:38
+0100
Received: from bembrasil.pt ([77.234.124.16]) by mx-ha.web.de (mxweb006) with
ESMTP (Nemesis) id 0MdsBp-1Yszfc0kJB-00Pdvm for <michael.messing@web.de>;
Tue, 17 Mar 2015 17:40:37 +0100
Received: by %63.185.48.134; Tue, 17 Mar 2015 21:20:06 +0500
From: "Helena Schmitt" <agpl@klaustukai.lt>
Reply-To: "Helena Schmitt" <agpl@klaustukai.lt>
To: christian_stingl@web.de
Subject: Du hast eine wichtige VideoNachricht von Christian erhalten
Date: Tue, 17 Mar 2015 20:17:06 +0400
Content-Transfer-Encoding: 7Bit
Content-Type: text/html;
The address agpl@klaustukai.lt does not exist. Could it be that the spam bot only uses my domain (fake email) and then the mails return to my mail server?