You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by List Mail User <tr...@Plectere.com> on 2005/05/25 03:32:11 UTC

Re: Mail Failure

>...
>
>Hi, this is evan@coolrunningconcepts.com ... using an alternate email
>address to be sure you'd get it.   Reply to that address - it may take
>forever for me to read this one!
>
>The original message was sent both to you and the list, so you got it
>already through the list.  Also, it possibly would have gone through
>had I sent it from home, but it was sent from a webmail running on the
>server itself (the desktop is doing upgrades, so I use the webmail -
>they are both synced via IMAP so I can use either one).  According to
>the message - its a WHOIS check?
>
>Here's is the failure notice you wanted:
>
>This message was created automatically by mail delivery software.
>
>A message that you sent could not be delivered to one or more of its
>recipients. This is a permanent error. The following address(es)
>failed:
>
>  track@Plectere.com
>    SMTP error from remote mailer after RCPT TO:<tr...@Plectere.com>:
>    host svcs.plectere.com [199.184.245.68]: 554 Service unavailable;
>Client host [esc14.midphase.com] blocked using
>whois.rfc-ignorant.org=127.0.0.5; Inaccurate or missing WHOIS data
>
>------ This is a copy of the message, including all the headers. ------
>
>Return-path: <ev...@coolrunningconcepts.com>
>Received: from cpanel by esc14.midphase.com with local (Exim 4.44)
>        id 1DaRQH-0003d7-U4; Mon, 23 May 2005 23:53:46 -0500
>Received: from 67.187.51.187 ([67.187.51.187]) by
>coolrunningconcepts.com
>        (Horde) with HTTP for <ev...@coolrunningconcepts.com>; Mon, 23
>May 2005
>        23:53:45 -0500
>Message-ID: <20...@coolrunningconcepts.com>
>Date: Mon, 23 May 2005 23:53:45 -0500
>From: evan@coolrunningconcepts.com
>To: List Mail User <tr...@Plectere.com>
>Cc: jm@jmason.org, dev@spamassassin.apache.org, felicity@kluge.net,
>        users@spamassassin.apache.org
>Subject: Re: Additional SPAM recognition method
>References: <20...@Plectere.com>
>In-Reply-To: <20...@Plectere.com>
>MIME-Version: 1.0
>Content-Type: text/plain;
>        charset=ISO-8859-1;
>        format="flowed"
>Content-Disposition: inline
>Content-Transfer-Encoding: 7bit
>User-Agent: Internet Messaging Program (IMP) H3 (4.0)
>
>Quoting List Mail User <tr...@Plectere.com>:
>
>
	Now this make *much* more sense.  I'm blocking your hosting service's
machine because of bad whois - which was actually reported by me!  They were
hosting/operating 88puppydog. com, who was sending "fake" invitations to
join a "friends" group to a bunch of technical mailing lists (at least 4
I susbscribe to in one day) - *AND* their listed contact telephone gave the
messages as listed in the report at rfci;  They do seem to have fixed it:
I check my old phone logs and just called the same number again and now get
a menu system, that while annoying is "compliant" -- Still they are "slime".
You could ask them to request removal from the rfci "whois" list, I only
assign a couple of points for the other entries and they still seem to be
deserving of them, or you could try to find a company thet doesn't collect
and sell email lists!

	Try a Google search on 88puppydog. com, then look at who owns and
operates it (just "whois") and decide for yourself.

http://www.google.com/search?as_q=&num=30&hl=en&btnG=Google+Search&as_epq=88puppydogMUNGE.com&as_oq=&as_eq=&lr=&as_ft=i&as_filetype=&as_qdr=all&as_occt=any&as_dt=i&as_sitesearch=&safe=images

WARNING: remove the MUNGE above

	Anyway, if they get off of whois.rfc-ignorant.org, then your messages
will go through fine - there is no DNS or HELO issue - just a slimy service
provider issue who decided to turn off their contact line while spamming
mailing lists!

	So anyway, there is no DNS, HELO, rDNS or related issue here - just
need to clean my fingers after typing midphase. com too many times.

	Best of luck,

	Paul Shupak
	track@plectere.com

Re: Mail Failure

Posted by ev...@coolrunningconcepts.com.
Everyone else - this may be off-topic, but consider it a lesson on what 
happens
when your spam rules are too intrusive over silly things instead of asking the
question "Is this mail spam?".   The method I proposed earlier is much more
effective at identifying spam than looking at what host has a bad postmaster
policy! and I was even able to recieve mail from a company that was listed as
an open-proxy as long as the mail itself wasn't proxied spam.

Quoting List Mail User <tr...@Plectere.com>:

> You could ask them to request removal from the rfci "whois" list, I only
> assign a couple of points for the other entries and they still seem to be
> deserving of them, or you could try to find a company thet doesn't collect
> and sell email lists!

1 - Which other issues is midphase "deserving" of that you have given them
"points" for?   I'll have them address any issues if they are doing something
wrong.  If its something like a reverse DNS mapping on the mail server - too
bad, it's shared hosting!   No way around it.

2 - Your accusation that midphase.com is collecting and selling email lists is
pretty serious.  Please send proof of such accusations as I will DEFINATELY
take that up with midphase and move myself and all sites I host to another
provider if this is true.

-- Evan



Re: Mail Failure

Posted by ev...@coolrunningconcepts.com.
Quoting List Mail User <tr...@Plectere.com>:

> 	Try a Google search on 88puppydog. com, then look at who owns and
> operates it (just "whois") and decide for yourself.

Midphase is bulk hosting provider for both end-users and resellers.  Nothing
more.   A WHOIS on "CoolRunningConcepts.com" will show you the exact same
information, but I can guarantee you that midphase does not own or operate
CoolRunningConcepts.

> 	Anyway, if they get off of whois.rfc-ignorant.org, then your messages
> will go through fine - there is no DNS or HELO issue - just a slimy service
> provider issue who decided to turn off their contact line while spamming
> mailing lists!

I'll let them know about the issue there, but I still think if your anti-spam
rules think I'm a spammer, then its YOUR rules that are at fault.  Its simply
wrong since my message isn't spam.  Its a false positive.

Second ... Slimy?  I don't know the details of the contact line issue, but I
highly doubt they turned it off so they can send spam.  Midphase is hardly a
spammer - perhaps 88puppydog.com was doing something stupid, but from their
website, it doesn't look like that domain really knew any better.  Looks like
some mom&pop operation to me.  I'm sure if midphase was told what was wrong,
they would have warned the owner of the domain to stop before pulling their
account.  They don't look like a big commercial spam-gang operation to me.

I'm not associated with 88puppydog.com in any way.  Nor am I associated with
midphase.com except that I'm a customer because I can't afford a more 
expensive
hoster right now.

> 	So anyway, there is no DNS, HELO, rDNS or related issue here - just
> need to clean my fingers after typing midphase. com too many times.

I haven't had too many problems with them considering how cheap they are.

-- Evan