Koozali.org: home of the SME Server

Mail with no Date header not accepted here (returning spam mails)

Offline beast

  • *
  • 245
  • +0/-0
Hi

Have a strange problem!  I keep getting spam e-mails that a system has been unable to deliver because of an error with the data header (same error all the times). It always have the same sender and receiver address if the name/user in front of the '@' sign is valid on the system. In case the user is not valid it have a different from address (my internet provider)

My question is if this spam mail is generated from my system and the system is used as a robot for spam mails (hope not) or my domains is just used by somebody else - but why then use the same to and from address????

Or is this some sort of bouncing mails?

The e-mails come to valid addresses but also to many random names in front of the domain.

I am unable to see in the logs if the mails come from my system in the first place (may be because I do not have enough knowledge)

Please help me out here!

Regards
Benny

NB: Each valid user gets around 25 mails pr. day

This is a valid address (have changed the user name)

Return-Path: <>
Delivered-To: ny@beastserver.beast.dk
Received: (qmail 3333 invoked by alias); 18 Jan 2009 08:04:41 -0000
Delivered-To: alias-localdelivery-ny@beast.dk
Received: (qmail 3330 invoked by uid 453); 18 Jan 2009 08:04:41 -0000
X-Virus-Checked: Checked by ClamAV on beast.dk
X-Spam-Status: No, hits=2.5 required=4.0
   tests=RAZOR2_CF_RANGE_51_100,RAZOR2_CF_RANGE_E8_51_100,RAZOR2_CHECK
X-Spam-Check-By: beast.dk
Received: from mail-gw.stofanet.dk (HELO mail-gw.stofanet.dk) (212.10.10.204)
    by beast.dk (qpsmtpd/0.40) with ESMTP; Sun, 18 Jan 2009 09:04:39 +0100
Received: from mail by mail-gw.stofanet.dk with local id 1LOSe5-0002BF-Mr
   for ny@beast.dk; Sun, 18 Jan 2009 09:04:37 +0100
X-Failed-Recipients: ny@beast.dk
Auto-Submitted: auto-replied
From: Mail Delivery System <Mailer-Daemon@mail-gw.stofanet.dk>
To: ny@beast.dk
Subject: Mail delivery failed: returning message to sender
Message-Id: <E1LOSe5-0002BF-Mr@mail-gw.stofanet.dk>
Date: Sun, 18 Jan 2009 09:04:37 +0100

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  ny@beast.dk
    SMTP error from remote mail server after end of data:
    host beast.dk [212.10.104.90]: 552 Mail with no Date header not accepted here

------ This is a copy of the message, including all the headers. ------

Return-path: <ny@beast.dk>
Received: from ppp-58-8-92-117.revip2.asianet.co.th ([58.8.92.117] helo=ppp-58-8-91-15.revip2.asianet.co.th)
   by mail-gw.stofanet.dk (envelope-from
   <ny@beast.dk>)
   with esmtp id 1LOSe3-0002B2-Hp
   for ny@beast.dk; Sun, 18 Jan 2009 09:04:36 +0100
To: <ny@beast.dk>
Subject: So wet and so warm
From: "Accents In Advertising Incorporated" <ny@beast.dk>
MIME-Version: 1.0
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
<title>Accents In Advertising Incorporated Newsletter</title>
</head>

<body>

<p align="center"><font size="2" color="#808080">To unsubscribe from this
broadcast email, please scroll down to the bottom of the page. <br>
To view this email as a web page, <a href="http://fnaqjs.hideximiw.cn/457df42d18ddd02e3.shtml">go here</a>.</font></p>

<div align="center">
   <table border="0" width="715">
      <tr>
         <td>
         <blockquote>
            <p align="center"><a href="http://colcj.hideximiw.cn/">
            <img border="0" src="http://imagez.hideximiw.cn/buddy.jpg" alt="Accents In Advertising Incorporated Newsletter" align="left"></a></p>
            <br>
            <p align="left">&nbsp;</p>
            <p align="left"><font color="#808080" size="2">Make sure our
            emails end up in your inbox, not your bulk or junk folders. <br>
            Simply add ny@beast.dk to your email address book or trusted-sender list.</font></p>
            <p align="left"><font color="#808080"><font size="2">You are receiving this newsletter because you subscribed to
            the Accents In Adve


This is an in-valid user

Return-Path: <>
Delivered-To: unknown@beastserver.beast.dk
Received: (qmail 9813 invoked by alias); 22 Jan 2009 13:41:41 -0000
Delivered-To: alias-localdelivery-unknown@beast.dk
Received: (qmail 9810 invoked by alias); 22 Jan 2009 13:41:41 -0000
Delivered-To: edmonj@beastserver.beast.dk
Received: (qmail 9807 invoked by alias); 22 Jan 2009 13:41:41 -0000
Delivered-To: alias-localdelivery-edmonj@beautyware.dk
Received: (qmail 9804 invoked by uid 453); 22 Jan 2009 13:41:41 -0000
X-Virus-Checked: Checked by ClamAV on beast.dk
X-Spam-Status: No, hits=2.5 required=4.0
   tests=RAZOR2_CF_RANGE_51_100,RAZOR2_CF_RANGE_E8_51_100,RAZOR2_CHECK
X-Spam-Check-By: beast.dk
Received: from mail-gw.stofanet.dk (HELO mail-gw.stofanet.dk) (212.10.10.204)
    by beast.dk (qpsmtpd/0.40) with ESMTP; Thu, 22 Jan 2009 14:41:38 +0100
Received: from mail by mail-gw.stofanet.dk with local id 1LPzoP-0006jT-G4
   for edmonj@beautyware.dk; Thu, 22 Jan 2009 14:41:37 +0100
X-Failed-Recipients: edmonj@beautyware.dk
Auto-Submitted: auto-replied
From: Mail Delivery System <Mailer-Daemon@mail-gw.stofanet.dk>
To: edmonj@beautyware.dk
Subject: Mail delivery failed: returning message to sender
Message-Id: <E1LPzoP-0006jT-G4@mail-gw.stofanet.dk>
Date: Thu, 22 Jan 2009 14:41:37 +0100

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  edmonj@beautyware.dk
    SMTP error from remote mail server after end of data:
    host beautyware.dk [212.10.104.90]: 552 Mail with no Date header not accepted here

------ This is a copy of the message, including all the headers. ------

Return-path: <edmonj@beautyware.dk>
Received: from net-93-147-58-67.t2.dsl.vodafone.it ([93.147.58.67])
   by mail-gw.stofanet.dk (envelope-from
   <edmonj@beautyware.dk>)
   with smtp id 1LPzoK-0006W3-Nt
   for edmonj@beautyware.dk; Thu, 22 Jan 2009 14:41:36 +0100
To: <edmonj@beautyware.dk>
Subject: Welcome to eBay!
From: <edmonj@beautyware.dk>
MIME-Version: 1.0
Importance: High
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=Windows-1252">
</HEAD>
<BODY bgcolor="#B1B1B1"><div style="padding: 20px 20px 40px 20px; background-color:#B1B1B1;">
<table width="450" border="0" cellspacing="0" cellpadding="0" align="center" bgcolor="#ffffff">
        <tr>

<td style="padding:10px 10px 10px 10px; font-family:'Trebuchet MS', Arial, Helvetica, sans-serif; font-size:20px; color:#000000;" >
We ship Worldwide! To all countries! To all destinations!</td>
        </tr>
        <tr>            <td style="padding:10px 0px 30px 0px;">
<div style="padding:10px 10px 10px 10px;">
   <div style="border-top:5px solid #666666; padding-top:10px;  font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px; color:#666666;">
<a href="http://courageoffice.com/"><img src="http://courageoffice.com/sdjbvsj.gif" alt="Cant see a picture? Click Here!" border="0"
class="featureImage" style="padding:100px 100px 100px 100px;" /></a>
   </div> </td>
        </tr>

        <tr>
                <td style="padding:20px 10px 10px 0px; background-color:#B1B1B1;">
                        <p style="font-family:Verdana, Arial, Helvetica, sans-serif; font-size:9px; color:#666666;">
                                To unsubscribe from this mailing list, please log in to www.courageoffice.com, click on "My Account",
                        click "Update" to edit your registration details and uncheck the "Receive Newsletter?" check box.<br>
                                Or unsubscribe at
                                <a href="http://courageoffice.com/faq.php" style="font-weight:bold; color:#666666">http://courageoffice.com/faq.php</a>
                        </p>

                        <p style="font-family:Verdana, Arial, Helvetica, sans-serif; font-size:9px; color:#666666;">
                                <a href="http://courageoffice.com/privacy_policy.php" style="font-weight:bold; color:#666666">Privacy Statement</a>  |
                                <a href="http://courageoffice.com/shipping_policy.php" style="font-weight:bold; color:#666666">Terms &amp; Conditions</a>  |
                                <a href="http://courageoffice.com/contacts.php" style="font-weight:bold; color:#666666">Contact</a>
                        </p>

                        <p style="font-family:Verdana, Arial, Helvetica, sans-serif; font-size:9px; color:#666666;">
                                BRANDKEYWORD Ltd.<br>
                                Tower Bridge Business Complex. Unit 1, B891. 581 Clements Road. London. SE58 6DG
                        </p>

                        <p style="font-family:Verdana, Arial, Helvetica, sans-serif; font-size:9px; color:#666666;">
                                &copy; 2006-2008 BRANDKEYWORD, Ltd. All Rights Reserved
                        </p></td> </tr></table></div></BODY></HTML>

« Last Edit: January 25, 2009, 08:15:02 PM by beast »

Offline gzartman

  • *
  • 306
  • +0/-0
    • LEI Engineering & Surveying
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #1 on: January 27, 2009, 01:57:55 AM »
Spammers are notorious for doing all kinds of strange things with mail headers.  Simply looking at the mail header for clues as to where it came from, if it is spam, will often not tell you much.  You'll need to track the suspect email message back to your qpsmtpd logfile and look at the conversation between your mail server and the sending server.  Even then it might be difficult to determine what is going on.

It is very unlikely that your SME box is being used as a relay unless you've installed some type of addon software that is providing a backdoor to your smtp.   A symptom that could indicate your SME server is being used as a relay would be a sudden increased in bounce messages being returned to your admin mailbox.  Again, unlikely, but possible especially if you've modified your SME Server.

It is, however, not that uncommon for a user on the LAN to install maleware that could be sending out quite alot of unwanted email.  If you think this might be happening, make sure your workstation AV and antispam software is updated and run full system scans on all machines.
« Last Edit: January 27, 2009, 01:59:48 AM by gzartman »
----
Greg J. Zartman
LEI Engineering & Surveying

SME user and community member since 2000.

Offline chris burnat

  • *****
  • 1,135
  • +2/-0
    • http://www.burnat.com
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #2 on: January 27, 2009, 02:16:30 AM »
You may wish to test your server for relay with this:
http://verify.abuse.net/relay.html

There are many other tools, check this:
http://spamlinks.net/prevent-secure-relay-test.htm
« Last Edit: January 27, 2009, 02:19:49 AM by chris burnat »
- chris
If it does not work out of the box, please fill in a Bug Report @ Bugzilla (http://bugs.contribs.org)  - check: http://wiki.contribs.org/Bugzilla_Help .  Thanks.

Offline beast

  • *
  • 245
  • +0/-0
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #3 on: January 27, 2009, 07:58:10 AM »
This is the last part of the log - that seam to show the handling of one of these mails. Unable to decode it for sure, but to me it looks as if it comes from my own system?

logging::logterse plugin: ` 212.10.10.204   mail-gw.stofanet.dk   mail-gw.stofanet.dk   <>   <jacobs_dk@beautyware.dk>   queued      <E1LRfNm-0001lI-NH@mail-gw.stofanet.dk>   Yes, hits=5.6 required=4.0_
@40000000497e8acc26594c84 27341 Plugin logging::logterse, hook queue returned DECLINED,
@40000000497e8acc26610514 27341 running plugin (queue): queue::qmail_2dqueue
@40000000497e8acc26a72a1c 27347 queue::qmail_2dqueue plugin: (for 27341 ) Queuing qp 27347 to /var/qmail/bin/qmail-queue
@40000000497e8acc27976dec 27341 Plugin queue::qmail_2dqueue, hook queue returned OK, Queued! 1233029826 qp 27347 <E1LRfNm-0001lI-NH@mail-gw.stofanet.dk>
@40000000497e8acc27a3e16c 27341 250 Queued! 1233029826 qp 27347 <E1LRfNm-0001lI-NH@mail-gw.stofanet.dk>
@40000000497e8acc2a4217a4 27341 dispatching MAIL FROM:<beautyware.dkmonteszo@beautyware.dk> SIZE=4395
@40000000497e8acc2a423acc 27341 full from_parameter: FROM:<beautyware.dkmonteszo@beautyware.dk> SIZE=4395
@40000000497e8acc2a425624 27341 from email address : [<beautyware.dkmonteszo@beautyware.dk>]
@40000000497e8acc2a426d94 27341 running plugin (mail): require_resolvable_fromhost
@40000000497e8acc2a428504 27341 trying to get config for invalid_resolvable_fromhost
@40000000497e8acc2a4bd7bc 27341 trying to get config for require_resolvable_fromhost
@40000000497e8acc2a59a2fc 27341 Plugin require_resolvable_fromhost, hook mail returned DECLINED,
@40000000497e8acc2a617eb4 27341 running plugin (mail): rhsbl
@40000000497e8acc2a709214 27341 trying to get config for rhsbl_zones
@40000000497e8acc2a7b05dc 27341 rhsbl plugin: Checking beautyware.dk.dsn.rfc-ignorant.org for TXT record in the background
@40000000497e8acc2ab98dac 27341 Plugin rhsbl, hook mail returned DECLINED,
@40000000497e8acc2ac1d6c4 27341 running plugin (mail): check_badmailfrom
@40000000497e8acc2acb585c 27341 trying to get config for badmailfrom
@40000000497e8acc2ad3ebac 27341 Plugin check_badmailfrom, hook mail returned DECLINED,
@40000000497e8acc2add7514 27341 getting mail from <beautyware.dkmonteszo@beautyware.dk>
@40000000497e8acc2b73217c 27341 250 <beautyware.dkmonteszo@beautyware.dk>, sender OK - how exciting to get mail from you!
@40000000497e8acc2b7344a4 27341 dispatching RCPT TO:<beautyware.dkmonteszo@beautyware.dk>
@40000000497e8acc2b735c14 27341 to email address : [<beautyware.dkmonteszo@beautyware.dk>]
@40000000497e8acc2b737384 27341 running plugin (rcpt): rhsbl
@40000000497e8acc2b738af4 27341 rhsbl plugin: waiting for rhsbl dns
@40000000497e8acc2b73a264 27341 rhsbl plugin: DONE waiting for rhsbl dns, got  1  answers ...
@40000000497e8acc2b743ea4 27341 Plugin rhsbl, hook rcpt returned DECLINED,
@40000000497e8acc2b745614 27341 running plugin (rcpt): dnsbl
@40000000497e8acc2b74699c 27341 trying to get config for dnsbl_zones
@40000000497e8acc2b74810c 27341 Plugin dnsbl, hook rcpt returned DECLINED,
@40000000497e8acc2b74987c 27341 running plugin (rcpt): check_badmailfrom
@40000000497e8acc2b74afec 27341 Plugin check_badmailfrom, hook rcpt returned DECLINED,
@40000000497e8acc2b74e69c 27341 running plugin (rcpt): check_badrcptto_patterns
@40000000497e8acc2b74fe0c 27341 trying to get config for badrcptto_patterns
@40000000497e8acc2b80c994 27341 Plugin check_badrcptto_patterns, hook rcpt returned DECLINED,
@40000000497e8acc2b88b8d4 27341 running plugin (rcpt): check_badrcptto
@40000000497e8acc2b933084 27341 trying to get config for badrcptto
@40000000497e8acc2ba63f6c 27341 Plugin check_badrcptto, hook rcpt returned DECLINED,
@40000000497e8acc2bae0b84 27341 running plugin (rcpt): rcpt_ok
@40000000497e8acc2bb7101c 27341 trying to get config for me
@40000000497e8acc2bbf554c 27341 trying to get config for rcpthosts
@40000000497e8acc2bcae63c 27341 Plugin rcpt_ok, hook rcpt returned OK,
@40000000497e8acc2bd4ae24 27341 250 <beautyware.dkmonteszo@beautyware.dk>, recipient ok
@40000000497e8acc2bde4b14 27341 dispatching DATA
@40000000497e8acc2be88ffc 27341 354 go ahead
@40000000497e8acc2bf0ec9c 27341 trying to get config for databytes
@40000000497e8acc2bf8b4cc 27341 max_size: 15000000 / size: 0
@40000000497e8acc2c028484 27341 trying to get config for timeout
@40000000497e8acc2ed908cc 27341 spooling message to disk
@40000000497e8acc2f2a8814 27341 max_size: 15000000 / size: 3319
@40000000497e8acc2f3676c4 27341 trying to get config for me
@40000000497e8acc2f475714 27341 running plugin (data_post): check_basicheaders
@40000000497e8acc2f557074 27341 Plugin check_basicheaders, hook data_post returned DENY, Mail with no Date header not accepted here
@40000000497e8acc2f5f3c44 27341 running plugin (deny): logging::logterse
@40000000497e8acc2f6d49ec 27341 logging::logterse plugin: ` 212.10.10.204   mail-gw.stofanet.dk   mail-gw.stofanet.dk   <beautyware.dkmonteszo@beautyware.dk>   <beautyware.dkmonteszo@beautyware.dk>   check_basicheaders   901   Mail with no Date header not accepted here   msg denied before queued
@40000000497e8acc2f770234 27341 Plugin logging::logterse, hook deny returned DECLINED,
@40000000497e8acc2f80dda4 27341 552 Mail with no Date header not accepted here
@40000000497e8acc3022bb24 27341 dispatching QUIT
@40000000497e8acc302e211c 27341 trying to get config for me
@40000000497e8acc3036376c 27341 221 beast.dk closing connection. Have a wonderful day.
@40000000497e8acc303f3c04 27341 click, disconnecting
@40000000497e8acc3048d50c 27341 running plugin (disconnect): rhsbl
@40000000497e8acc3053ece4 27341 Plugin rhsbl, hook disconnect returned DECLINED,
@40000000497e8acc305bf77c 27341 running plugin (disconnect): dnsbl
@40000000497e8acc30652af4 27341 Plugin dnsbl, hook disconnect returned DECLINED,
@40000000497e8acc332fc474 9443 running plugin (pre-connection): hosts_allow
@40000000497e8acc333b70bc 9443 trying to get config for hosts_allow
@40000000497e8acc3346d2cc 9443 Plugin hosts_allow, hook pre-connection returned DECLINED,
@40000000497e8acc35f8007c 9443 cleaning up after 27341
@40000000497e8acc396daaf4 27364 Accepted connection 1/40 from 212.10.10.204 / mail-gw.stofanet.dk
@40000000497e8acc3979091c 27364 Connection from mail-gw.stofanet.dk [212.10.10.204]
@40000000497e8acc39904654 27364 running plugin (set_hooks): peers
@40000000497e8acc399fa3ec 27364 trying to get config for peers/0
@40000000497e8acc39aa88fc 27364 trying to get config for plugin_dirs
@40000000497e8acc39b68364 27364 trying to get config for peers/0
@40000000497e8acc39c0d01c 27364 trying to get config for plugin_dirs
@40000000497e8acc39de27d4 27364 peers hooking valid_auth
@40000000497e8acc39e714fc 27364 peers hooking set_hooks
@40000000497e8acc39f24c14 27364 trying to get config for plugin_dirs
@40000000497e8acc3a0124dc 27364 logging::logterse hooking queue
@40000000497e8acc3a0a640c 27364 logging::logterse hooking deny
@40000000497e8acc3a13745c 27364 trying to get config for plugin_dirs
@40000000497e8acc3a26f0a4 27364 trying to get config for plugin_dirs
@40000000497e8acc3a386d34 27364 check_earlytalker hooking connect
@40000000497e8acc3a41799c 27364 trying to get config for plugin_dirs
@40000000497e8acc3a4cbc6c 27364 count_unrecognized_commands hooking connect
@40000000497e8acc3a590cc4 27364 count_unrecognized_commands hooking unrecognized_command
@40000000497e8acc3a62f7d4 27364 trying to get config for plugin_dirs
@40000000497e8acc3a6f3c74 27364 check_relay hooking connect
@40000000497e8acc3a7d03cc 27364 trying to get config for plugin_dirs
@40000000497e8acc3a88eaac 27364 check_norelay hooking connect
@40000000497e8acc3a96505c 27364 trying to get config for plugin_dirs
@40000000497e8acc3aa4236c 27364 require_resolvable_fromhost hooking mail
@40000000497e8acc3ab1620c 27364 trying to get config for plugin_dirs
@40000000497e8acc3abfcd74 27364 check_basicheaders hooking data_post
@40000000497e8acc3acb9514 27364 trying to get config for plugin_dirs
@40000000497e8acc3ad9aa8c 27364 rhsbl hooking rcpt
@40000000497e8acc3ae20efc 27364 rhsbl hooking mail
@40000000497e8acc3aec0d94 27364 rhsbl hooking disconnect
@40000000497e8acc3af5f4bc 27364 trying to get config for plugin_dirs
@40000000497e8acc3b012fbc 27364 dnsbl hooking connect
@40000000497e8acc3b0bab54 27364 dnsbl hooking rcpt
@40000000497e8acc3b159e34 27364 dnsbl hooking disconnect
@40000000497e8acc3b1f7d8c 27364 trying to get config for plugin_dirs
@40000000497e8acc3b2d21bc 27364 check_badmailfrom hooking rcpt
@40000000497e8acc3b358a14 27364 check_badmailfrom hooking mail

Offline beast

  • *
  • 245
  • +0/-0
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #4 on: January 27, 2009, 08:00:15 AM »
You may wish to test your server for relay with this:
http://verify.abuse.net/relay.html

The server seam to be safe - no relay

Offline axessit

  • *****
  • 213
  • +0/-0
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #5 on: February 04, 2009, 12:04:29 PM »
As well as checking your client machines for viruses, you need to check them for spyware - run Spybot. Make sure your client's aren't running any peer to peer networking programs like Limewire etc, make sure your Proxy settings on the SME server panel is set to SMTP Proxy Status Enabled to make sure email is sent through the SME and not straight out to the internet.

Offline beast

  • *
  • 245
  • +0/-0
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #6 on: February 04, 2009, 01:09:04 PM »
As well as checking your client machines for viruses, you need to check them for spyware - run Spybot. Make sure your client's aren't running any peer to peer networking programs like Limewire etc, make sure your Proxy settings on the SME server panel is set to SMTP Proxy Status Enabled to make sure email is sent through the SME and not straight out to the internet.

Proxy settings was disabled - I have enabled it now!

Thank you!

BTW: These strange e-mails have almost disapeared the last week?

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #7 on: February 05, 2009, 01:21:43 AM »
Or is this some sort of bouncing mails?

Yes, it is some sort of bouncing emails.

Quote
------ This is a copy of the message, including all the headers. ------

Return-path: <ny@beast.dk>
Received: from ppp-58-8-92-117.revip2.asianet.co.th ([58.8.92.117] helo=ppp-58-8-91-15.revip2.asianet.co.th)
   by mail-gw.stofanet.dk (envelope-from
   <ny@beast.dk>)
   with esmtp id 1LOSe3-0002B2-Hp
   for ny@beast.dk; Sun, 18 Jan 2009 09:04:36 +0100
To: <ny@beast.dk>
Subject: So wet and so warm
From: "Accents In Advertising Incorporated" <ny@beast.dk>
MIME-Version: 1.0
Content-Type: text/html
...

The problem is your domain's secondary MX server mail-gw.stofanet.dk (which doesn't run SME server software). It accepted a spam message from ppp-58-8-92-117.revip2.asianet.co.th which claimed to have been sent by ny@beast.dk. The message was an invalid message - in particular it had no Date header.

mail-gw.stofanet.dk then tried to transfer the message via SMTP to 212.10.104.90 (your SME server) which would not accept it because it was spam. mail-gw.stofanet.dk then generated a bounce message explaining what happened, and tried to send that to the purported sender - i.e. ny@beast.dk. The bounce message has a correct format, including a Date header, and was accepted by your SME server when mail-gw.stofanet.dk tried to deliver it.

You need to just put up with these messages, or get better spam filtering on mail-gw.stofanet.dk. Or, and this is likely your best choice, just change your DNS so that you have only one MX listed - beast.dk. mail-gw.stofanet.dk isn't helping you at all.

Offline judgej

  • *
  • 375
  • +0/-0
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #8 on: February 05, 2009, 01:37:58 AM »
I get the same problem, and it has started to drive me mad over the last few weeks.

I have a web server that accepts mail to only specific addresses, such as 'info' and 'webmaster'. Any mail sent to those addresses gets forwarded on to an address in my SME Server.

What seems to happen is that the web server attempts to deliver to my SME server, with the headers unmodified (including the missing date header). The SME Server rightly dismisses the message with the "not accepted here without a date" message.

The webserver then decides to bounce the message. And where does it bounce to? The same SME Server account, of course. The bounce gets the date header set, and so it gets through to the SME Server no problem.

The web server is set up to silently discard messages to unknown recipients, but it does not have the same checks that SME Server performs on the message, so is a bit more lenient on accepting these duff messages to start with. That is where the problem is - it's not an SME Server problem, and needs to be solved further upstream, but it is an unexpected consequence of the SME Server being stricter than the web server forwarding the messages on to it.

-- Jason
-- Jason

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #9 on: February 05, 2009, 02:27:31 AM »
I get the same problem, and it has started to drive me mad over the last few weeks.

If you have the same problem, then the same solution will apply.

If you don't have the same problem, then you shouldn't have hijacked the thread.

If you think there is a problem with SME server, then use the bug tracker.

Offline judgej

  • *
  • 375
  • +0/-0
Re: Mail with no Date header not accepted here (returning spam mails)
« Reply #10 on: February 05, 2009, 11:36:24 AM »
If you have the same problem, then the same solution will apply.

If you don't have the same problem, then you shouldn't have hijacked the thread.

If you think there is a problem with SME server, then use the bug tracker.

What exactly was the point of posting that?

I guess I need to apologise to the original author now, for posting additional information that may help understand the problem. Why do I always come to regret posting anything on these damn forums.
-- Jason

Offline thomasch

  • *
  • 232
  • +0/-0
« Last Edit: February 06, 2009, 03:41:42 AM by thomasch »