Brian,
We received your 4 spam samples, but I'm a bit confused. Let me pre-say that the samples were in a Outlook .msg format, and thus that completely altered the original email's format, headers included. It is thus possible that the headers we received were not the original ones.
This said, assuming the headers were actually semi-correct, none of the 4 spam emails had SpamFilter's headers in them. These headers should be as follows for example:
Received: from 117.26.121.8 by mail.netwide.net (LogSat Software SMTP Server); Sat, 07 Jun 2012 09:04:59 -0500 X-Server: LogSat Software SMTP Server X-SF-RX-Return-Path: <test@test.logsat.comt> X-SF-HELO-Domain: test.somedomain.com X-SF-Originating-IP: 117.26.121.8
The fact that these headers are not present in an email indicates that the email was not processed by SpamFilter. I then checked the MX records for one of your domains (your main one - the one I will use to send you a copy of this forum reply via email). That domain has to MX records: mail01.pro-----------ng.com mail02.pro-----------ng.com
When I connected via telnet on port 25 and established an SMTP session on those two hosts, in neither case I was connected to a SpamFilter server. There are two different mail servers listening for SMTP traffic on those two IPs, not SpamFilter. This confirms what I noticed in the headers - SpamFilter did not process those 4 spam email samples.
However, when looking at you SpamFilter activity logfile you forwarded us, I do indeed see internet emails being processed by SpamFilter, and that emails originated from a multitude of different internet IPs, indicating that somehow internet emails are reaching SpamFilter even though the MX records do not point to SpamFilter servers.
This is why I'm a bit confused... A possible explanation is that you *may* have another application/proxy processing inbound emails from the internet, and that this other application/proxy is masking its IP when forwarding some of the emails to SpamFilter. However as you are receiving emails not processed by SpamFilter, this application/proxy may not be forwarding all of its emails to SpamFilter. Unfortunately I can't be sure without knowing more about your network.
I hope all this will help you anyways to see what is happening as you are getting more familiar with the setup you inherited.
------------- Roberto Franceschetti
http://www.logsat.com" rel="nofollow - LogSat Software
http://www.logsat.com/sfi-spam-filter.asp" rel="nofollow - Spam Filter ISP
|