Apple’s Worldwide Developers Conference to kick off June 10 at 10 a.m. PDT with Keynote address

The Keynote will be available to stream on apple.com, the Apple Developer app, the Apple TV app, and the Apple YouTube channel. On-demand playback will be available after the conclusion of the stream.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

'Undeliverable Mail Return To Sender' spam?

As of late, we have been getting 'undeliverable mail' which appears to be spam. The long headers appear to indicate that it is indeed coming from our mail server and the body of the message goes something like this:

This is the Postfix program at host nopali.com.

I'm sorry to have to inform you that your message could not be
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to <postmaster>

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The Postfix program

<clinique@ccpmtl.com>: host 127.0.0.1[127.0.0.1] said: 550 5.7.1 Message
content rejected, UBE, id=21361-04 (in reply to end of DATA command)
Reporting-MTA: dns; nopali.com
X-Postfix-Queue-ID: 7260D27DAB9
X-Postfix-Sender: rfc822; clinique@ccpmtl.com
Arrival-Date: Sat, 23 Dec 2006 04:10:46 -0500 (EST)

Final-Recipient: rfc822; clinique@ccpmtl.com
Action: failed
Status: 5.0.0
Diagnostic-Code: X-Postfix; host 127.0.0.1[127.0.0.1] said: 550 5.7.1 Message
content rejected, UBE, id=21361-04 (in reply to end of DATA command)

From: "Ronald Myers" <qbdldfs@alderking.com>
Date: December 23, 2006 4:11:11 AM EST (CA)
To: clinique@ccpmtl.com
Subject: Because that is curious girdle, and Hormah, and some therefore,


...and there is generally a spamish content underneath.

Has anyone encountered this?

I thought perhaps that somehow others were able to use my mail cue, but I closed the firewall for SMTP mail to only favourable IPs. However, when I look at my mail cue, I see a bunch of things waiting to be sent out. They appear to be a bunch of spam that the server trying to return. The cue would typically have this message:

Message ID: 266692764C8
Date: Thu Dec 21 13:31:52
Size: 6742
Sender: MAILER-DAEMON
Recipient(s) & Status:
----------------------
online_identity@wc.wachovia.com:
connect to wc.wachovia.com[169.200.182.108]: Operation timed out


It appears that the server is trying to return spammed mail to sender and it is timing out. I am not sure, though. This would not make sense since I have spam being redirected to a separate spam_depot account.

Any ideas on how to figure this one out?

Mirror Drive, Mac OS X (10.4.8)

Posted on Dec 23, 2006 4:17 AM

Reply
17 replies

Dec 28, 2006 2:41 PM in response to UptimeJeff

Yes, I had run spamtrainer (most excellent script) and it fixed the virtual domain issue

I also upped the attachment size cutoff for spam testing, and it cured the untested spam issue.


There is still some lingering issue: I seem to have 3 groups of post-tested emails:

1) Emails that are tested and delivered. These seems to be emails that have this sort of header text:

X-Virus-Scanned: by amavisd-new at nopali.com
X-Spam-Status: No, hits=3.5 tagged_above=-999 required=4 tests=BAYES_99
X-Spam-Level: *

To me, this seems like normal behaviour

2) Emails that are tested and redirected to my spam quarantine. These have this sort of header:

X-Spam-Status: Yes, hits=18.772 tag=-999 tag2=4 kill=7 tests=BAYES_99, EXTRA MPARTTYPE, etc....
X-Spam-Level: ***********

This seems like normal behaviour

3) Emails that are scanned and delivered. These emails are also prefixed with *Junk Mail * in the subject of the email. These ones have headers with:

X-Virus-Scanned: by amavisd-new at nopali.com
X-Spam-Status: Yes, hits=5.814 tagged_above=-999 required=4 tests=BAYES_99, DATE IN_PAST_0612, HTML 1020, HTML_MESSAGE
X-Spam-Level: ***
X-Spam-Flag: YES

In understanding this, these last emails probably fall into the grey-zone between the tag2 level of 4 and the kill level of 7. Is this correct? Should I go into /etc/amavisd.conf and comment-out the line:

$sa spam_subjecttag = ' * JUNK MAIL *';


I think everything is running very slick up to this point. Thanks for all your help!

'Undeliverable Mail Return To Sender' spam?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.