How do I block a domain from the recieved portion of headers
Ed Bruce
ebruce at hpmich.com
Wed Mar 22 13:57:31 GMT 2006
Brandon Hoppe wrote:
>
> A virus on a users machine from an outside domain keeps sending email
> to a user on my domain. MailScanner is detecting the virus and
> removing it. But the problem is that I get these emails atleast once
> an hour. It always comes from the same place. It disguises itself as
> though the email comes from my domain, but the full headers shows it
> comes from another domain. For example:
>
>
>
>
>
> Full headers are:
>
> Return-Path: <?g>
> Received: from test-domain.com (cpe-24-170-49-168.stx.res.rr.com
> [24.170.49.168])
>
>
>
>
>
> My domain is named test-domain.com. I am not on RoadRunner so the
> rr.com address above is where its originating from.
>
>
>
> What's the best way to go about blocking this domain or sub-domain so
> that I stop receiving the notices of detected virus emails from
> MailScanner.
>
>
>
What MTA are you using. I'm using PostFix and have a check_helo_access
rule that rejects email falsely claiming to be from within my domain.
--
This message, including any attachments, is intended solely for the use
of the named recipients(s) and may contain confidential and/or
privileged information. Any unauthorized review, use, disclosure or
distribution of this communication is expressly prohibited. If you are
not the intended recipient, please contact the sender by reply e-mail
and destroy any and all copies of the original message.
Thank you for your cooperation.
--
This message has been scanned for viruses and dangerous content by
Secure Resource, and is believed to be clean.
MailScanner thanks transtec Computers for their support.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060322/08869bba/attachment.html
More information about the MailScanner
mailing list