[ALUG] question about spam and email

Phil Ashby phil.ashby at bt.com
Thu Mar 5 09:20:42 GMT 2009


On Thu, 2009-03-05 at 09:01 +0000, Peter Alcibiades wrote:
> Received: from 89.255.66.166  (HELO amerblind.outbound.ed10.com)

Looking this IP address up gives:

Non-authoritative answer:
166.66.255.89.in-addr.arpa  name = obl66.66.255.89.in-addr.arpa.

doing the same for the alleged source:

Non-authoritative answer:
Name:	amerblind.outbound.ed10.com
Address: 209.202.164.111
... [other similar 208/209 addresses]

thus it appears that this email has been sent from a dynamic address
pool (obl66...) which does not match the claimed sender machine, and I
would conclude that it's plain ol' spam from a zombie machine that
perhaps Yahoo could be filtering out.

P



More information about the main mailing list