procmail
[Top] [All Lists]

Direct spam injection to secondary MX

1998-07-11 15:21:13
I just received a piece of spam that slipped past my filters (I hate when that
happens). What I thought was interesting about this particular piece of spam
was that it was injected directly from a Compuserve dialup node to the machine
listed as a backup in the MX records for my domain. The primary was up, but for
some reason this miscreant decided to send it to a lower priority machine
instead.

I realize this isn't a procmail question, but since people using procmail are
generally spam-conscious I thought I'd bring this up here. The question is: why
would a spammer choose to send me spam in this somewhat roundabout way? Is
there any advantage in it for him? Or is his spamware just too stupid or lazy
to bother sorting MX records?

Also, this particular piece of spam had no Message-ID header. As far as I
recall such a header is not required by any RFC, but how common is it for
legitimate mail not to have a Message-ID header?

Chris Johnson

<Prev in Thread] Current Thread [Next in Thread>