Weekly spam summary on August 27th, 2005
The overall SMTP connection rate is up from
last week, as we hit 213,000 SMTP
connections from at least 36,000 different IP addresses.
The SMTP frontend hit a new highwater of 22 simultaneous connections
being checked at once. It's possible that a lot of this is from spammers
forging our domains as the
MAIL FROM of their spams.
Top 10 kernel level SMTP rejections:
Host/Mask Packets Bytes 18.104.22.168 16370 736K [dns] 22.214.171.124 12959 660K [trap] 126.96.36.199/24 10593 553K 188.8.131.52/12 6472 311K 184.108.40.206 5752 284K [trap] 220.127.116.11 4621 222K [dyn] 18.104.22.168/10 4219 211K 22.214.171.124 4127 198K [dyn] 126.96.36.199 4049 206K [dns] 188.8.131.52 3706 163K [helo]
||Bad or missing reverse DNS|
||Apparent dynamic IP address|
||Sent mail to a spamtrap|
Clearly we've had some very persistent callers this week; however, most of the individual machines are new on the list (the only exception is 184.108.40.206, appearing in SpamSummary-2005-07-23).
Connection-time rejection stats:
27462 total 13178 dynamic IP 7721 bad or no reverse DNS 1668 class bl-cbl 1195 class bl-spews 1032 class bl-sbl 880 class bl-dsbl 775 class bl-ordb 189 class bl-sdul 83 class bl-njabl 27 class bl-opm
SBL-based rejections are up significantly, and break down like this for the top five:
SBL20671 is a /19 ROKSO listing for OC3 Networks. SBL27384
aruba.it IP address listed for hosting a 'phish' site that
tried to send us a bunch of email. SBL29615 is 220.127.116.11,
www.portafree.com, listed as an Advance Fee Fraud source. (There
is a lesson here for people running free email
services, but they clearly keep on not learning.)
SPEWS rejections have no specific bad source, although 18.104.22.168
kept retrying a lot (it looks like it's a Microsoft mailer, and
those tend to do that in my experience). Big SPEWS contributions
seamail.go.com, both of
which are widely abused free email services that I am not sorry
to see rejected.
wanadoo.co.uk also got into the act.
(I am seriously considering specific connection-time rejections for all of the widely abused free email providers that I don't want to bother talking to. It would probably make these reports more streamlined and it might get the message through to their operators. Or at least any real users trying to email our users.)
Bad HELOs and SMTP bounces to nonexistent local addresses are up quite a lot over last week. The numbers:
|what||# this week||(distinct IPs)||# last week||(distinct IPs)|
Much of the increase in the bad
HELO count is due to various people
retrying much more often. The drastic increase in the number of distinct
IP addresses sending us bad bounces suggests that our domains are being
forged more by spammers again.