Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Applications > fake messages from "Mail Delivery Subsystem"

fake messages from "Mail Delivery Subsystem"
Thread Tools
msuper69
Professional Poster
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Jul 18, 2010, 08:52 AM
 
I've just recently started getting a lot of bogus messages similar to this:

From: Mail Delivery Subsystem <[email protected]>
Subject: Returned mail: see transcript for details
Date: July 18, 2010 7:40:03 AM EDT
To: xxxxxxxxxxxx <[email protected]>
The original message was received at Sun, 18 Jul 2010 11:21:35 GMT
from [41.249.29.114]

----- The following addresses had permanent fatal errors -----
<[email protected]>
(reason: 550 5.1.1 User unknown)

----- Transcript of session follows -----
550 5.1.1 <[email protected]>... User unknown
Reporting-MTA: dns; ogham.futhark.ch
Arrival-Date: Sun, 18 Jul 2010 11:21:35 GMT

Final-Recipient: RFC822; [email protected]
X-Actual-Recipient: RFC822; [email protected]
Action: failed
Status: 5.1.1

--------------------------------------

Now I know this is some kind of scam or social engineering attempt but I don't see how it's supposed to work.

Anybody seen this kind of stuff before?
     
ghporter
Administrator
Join Date: Apr 2001
Location: San Antonio TX USA
Status: Offline
Reply With Quote
Jul 18, 2010, 09:21 AM
 
Not necessarily a scam. It could be that someone has used your email address in the "from" field for spam. This happens to me on one of my public addresses every now and then. I've wound up either writing a rule to trash "mailer daemon" mail or simply ignoring these replies.

Glenn -----OTR/L, MOT, Tx
     
msuper69  (op)
Professional Poster
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Jul 18, 2010, 09:25 AM
 
Originally Posted by ghporter View Post
Not necessarily a scam. It could be that someone has used your email address in the "from" field for spam. This happens to me on one of my public addresses every now and then. I've wound up either writing a rule to trash "mailer daemon" mail or simply ignoring these replies.
Yeah, it's probably somebody using my email address.

I've had the same email address for about 10 years now. I think it's time to start fresh and NEVER post the new address on the Internet. MobileMe lets you set up alias so I could use one of them for those times when places like Amazon.com require an email address. If that alias gets compromised I think you can delete it and create a replacement. Not sure about the MobileMe rules regarding aliases.

Thanks!
     
mduell
Posting Junkie
Join Date: Oct 2005
Location: Houston, TX
Status: Offline
Reply With Quote
Jul 18, 2010, 11:49 AM
 
Yea, looks like backscatter to me.
     
seanc
Moderator Emeritus
Join Date: Apr 2005
Location: Cambridge, UK
Status: Offline
Reply With Quote
Jul 18, 2010, 03:25 PM
 
You don't have your own mail server do you?
     
pcryan5
Mac Enthusiast
Join Date: Mar 2006
Location: Vancouver, BC
Status: Offline
Reply With Quote
Jul 18, 2010, 05:18 PM
 
Originally Posted by msuper69 View Post
MobileMe lets you set up alias so I could use one of them for those times when places like Amazon.com require an email address.
I attend a few tech conferences each year and create an alias for each one. The amount of post conference spam your mandatory badge scanning generates is quite the bore. I simply filter the email into the matching folder and review whenever.
     
mduell
Posting Junkie
Join Date: Oct 2005
Location: Houston, TX
Status: Offline
Reply With Quote
Jul 20, 2010, 07:02 PM
 
Was there any javascript in the message? Apparently it's a new attack that Google is now blocking.
     
msuper69  (op)
Professional Poster
Join Date: Jan 2000
Location: Columbus, OH
Status: Offline
Reply With Quote
Jul 20, 2010, 08:07 PM
 
Originally Posted by mduell View Post
Was there any javascript in the message? Apparently it's a new attack that Google is now blocking.
How can I tell? It looks like a plain text message to me.
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 11:47 AM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,