Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


decibel

315 posts

Ultimate Geek


#289224 20-Aug-2021 17:58
Send private message

I have committed the same sin as Hilary Clinton; I have an email server in my garage.


All has been well for many years untill I woke up a few days ago and found over 10,000 emails in my inbox.


They were mostly replies from domains saying "no such address exists" and a few from real people saying "out-of-office"


As fast as I deleted them more came in.  I then deleted the email address, but that just resulted in me sending out a ton of emails saying  "no such address exists"  from my end.


I have now shutdown the domain altogether.


In the meantime though, I have been blacklisted from here to the moon, included Geekzone.


[Thanks Mauricio for unblocking me)


Any suggestions for what I can do about this?  (other than going to Mexico doing the spammer in?  -if I found him)


Create new topic

xpd

xpd
Geek @ Coastguard NZ
13765 posts

Uber Geek

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #2763950 20-Aug-2021 18:09
Send private message

Do you have SPF etc enabled on your domain ? Sounds like you dont and someones used that to their advantage to spam.....





       Gavin / xpd / FastRaccoon / Geek of Coastguard New Zealand

 

                      LinkTree

 

 

 




freitasm
BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2763980 20-Aug-2021 19:47
Send private message

It doesn't help much after but any domain should have SPF/DKIM/DMARC set to the strictest settings.

The IP address is now blacklisted. Your ISP won't like you for it. It will be hard to recover but can be done - with time you can remove it from all the blacklists.

Other than this, the IP address being marked as suspicious will disappear from some lists over time.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


decibel

315 posts

Ultimate Geek


  #2764044 20-Aug-2021 22:32
Send private message

Bummer - amateur mistake on my part.  Surprised it didn't happen sooner.

 

Anyway, at least nobody will be chanting  "lock him up!"

 

 

 

 




BarTender
3606 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2764068 20-Aug-2021 23:14
Send private message

Suggestion, move to GMail and stop running your own domain at home. I did that back in the day when GSuite was free and I have never looked back.


michaelmurfy
meow
13240 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #2764074 20-Aug-2021 23:36
Send private message

It may even have been compromised and not related specifically to the domain itself. Out of interest, what mail server were you using?

 

But I strongly recommend shifting this to an actual email provider. Dug deep in their website, Zoho still offer a "Forever Free" plan: https://mail.zoho.com.au/orgsignup.do?plan=free





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


fe31nz
1228 posts

Uber Geek


  #2764077 21-Aug-2021 00:27
Send private message

Which ISP?  I run my own SMTP server still, but since I am on 2Degrees, I get it to send by relaying via their SMTP servers, which fixes the blacklisting problems.  If you send email from an ordinary ISP IP address, there is a fair chance that the receiving SMTP server will block it simply because it is in a block of ordinary IP addresses that are not expected to send emails.  However, it is getting rare for ISPs to provide SMTP servers you can use - that is one more reason I am with 2Degrees.  There are SMTP servers out there you can pay to use in a similar way - they vary from the occasional free one (for low traffic) through fairly cheap up to massively expensive (intended for use by large corporates sending out daily mailings to millions).  I use dynu.com for my backup MX servers, and they have an option to do SMTP relay for US$9.99 per year.  I would probably use them if I needed to change to an ISP that did not have SMTP relay as an option.

 

I do also have SPF set up, but not DKIM.  Before SPF arrived, I used to occasionally get a few of those "no such address" reply type emails, but I do not think I have had one since I set up SPF.


BarTender
3606 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2764080 21-Aug-2021 06:32
Send private message

fe31nz:

 

Which ISP?  I run my own SMTP server still, but since I am on 2Degrees, I get it to send by relaying via their SMTP servers, which fixes the blacklisting problems.  If you send email from an ordinary ISP IP address, there is a fair chance that the receiving SMTP server will block it simply because it is in a block of ordinary IP addresses that are not expected to send emails.  However, it is getting rare for ISPs to provide SMTP servers you can use - that is one more reason I am with 2Degrees.  There are SMTP servers out there you can pay to use in a similar way - they vary from the occasional free one (for low traffic) through fairly cheap up to massively expensive (intended for use by large corporates sending out daily mailings to millions).  I use dynu.com for my backup MX servers, and they have an option to do SMTP relay for US$9.99 per year.  I would probably use them if I needed to change to an ISP that did not have SMTP relay as an option.

 

I do also have SPF set up, but not DKIM.  Before SPF arrived, I used to occasionally get a few of those "no such address" reply type emails, but I do not think I have had one since I set up SPF.

 

 

You know that because you are relaying via 2D, then you would need the 2D SMTP servers in your SPF as an allowed IP and DKIM won't work as 2D won't be signing the outbound messages.

 

It also means that anyone else using the 2D SMTP servers can spam as your domain, while that is unlikely they would be legitimate outbound emails that your SPF rule had allowed.


 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
freitasm
BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2764081 21-Aug-2021 07:00
Send private message

I have been thinking about this event and I don't think someone spoofed your address. From your description I think your server was compromised and used to send out spam.

Under this circumstances even if you had SPF/DKIM/DMARC your IP would still be considered toxic as all those emails would be "valid" as they would have been sent from your server and pass all those restrictions.

Lesson learnt. Don't run your email server if not constantly patching and updating. The IP is toxic now (as OP mentioned I had to create a WAF rule just to allow him to post this topic) and you might have problems in the future accessing some services.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


decibel

315 posts

Ultimate Geek


  #2764167 21-Aug-2021 10:55
Send private message

BarTender:

 

Suggestion, move to GMail and stop running your own domain at home. I did that back in the day when GSuite was free and I have never looked back.

 

 

I do have a Gmail address also - but I have an aversion to outfits like Google and wish to minimise my dependence on them.


decibel

315 posts

Ultimate Geek


  #2764169 21-Aug-2021 10:57
Send private message

fe31nz:

 

Which ISP?  I run my own SMTP server still, but since I am on 2Degrees, I get it to send by relaying via their SMTP servers, which fixes the blacklisting problems. 

 

 

I am on 2degrees as well, running an  hMail server.  I was not using the snap SMTP outgoing server; too late now.


decibel

315 posts

Ultimate Geek


  #2764222 21-Aug-2021 11:00
Send private message

freitasm: I have been thinking about this event and I don't think someone spoofed your address. From your description I think your server was compromised and used to send out spam.

Under this circumstances even if you had SPF/DKIM/DMARC your IP would still be considered toxic as all those emails would be "valid" as they would have been sent from your server and pass all those restrictions.

Lesson learnt. Don't run your email server if not constantly patching and updating. The IP is toxic now (as OP mentioned I had to create a WAF rule juat to allow him to post this topic) and you might have problems in the future accessing some services.

 

Possible but I am past this point now.

 

I am getting email through 1stDomains from now on.

 

Cheers and thanks guys for keeping my brain active. 👍


xpd

xpd
Geek @ Coastguard NZ
13765 posts

Uber Geek

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #2764234 21-Aug-2021 11:21
Send private message

I used to run hMailserver, only had issues with it once after an update turned off the SMTP external access - woke up to 50k+ emails queued up - soon flushed those out and found the setting. Did end up being blacklisted but managed to remove from most, others was just a waiting game.

 

 





       Gavin / xpd / FastRaccoon / Geek of Coastguard New Zealand

 

                      LinkTree

 

 

 


decibel

315 posts

Ultimate Geek


  #2764331 21-Aug-2021 14:18
Send private message

freitasm: ... I had to create a WAF rule juat to allow him to post this topic.

 

Yes, lesson learned - I thought WAF stood for "Wife Acceptance Factor"  - now I know better.


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.