Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

We want to create puppets that pull their own strings. -- Ann Marion


computers / news.admin.net-abuse.email / Re: any ideas here?

SubjectAuthor
* any ideas here?jrg
+* any ideas here?Grant Taylor
|`* any ideas here?jrg
| +- addendum Re: any ideas here?jrg
| +* any ideas here?David Ritz
| |`- any ideas here?jrg
| +* any ideas here?Grant Taylor
| |`* any ideas here?jrg
| | `* any ideas here?Grant Taylor
| |  `* any ideas here?Grant Taylor
| |   `* any ideas here?jrg
| |    `- any ideas here?Grant Taylor
| `* any ideas here?Scott Dorsey
|  `* any ideas here?jrg
|   `* any ideas here?Scott Dorsey
|    `- any ideas here?Grant Taylor
`- any ideas here?Bob Milutinovic

1
any ideas here?

<tako56$tdp$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=820&group=news.admin.net-abuse.email#820

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!aioe.org!5i8Ep7ErYoJUgtWmlIInIw.user.46.165.242.75.POSTED!not-for-mail
From: jeff.g.group@att.net (jrg)
Newsgroups: news.admin.net-abuse.email
Subject: any ideas here?
Date: Tue, 12 Jul 2022 14:13:07 -0700
Organization: Aioe.org NNTP Server
Message-ID: <tako56$tdp$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="30137"; posting-host="5i8Ep7ErYoJUgtWmlIInIw.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.5.0
X-Notice: Filtered by postfilter v. 0.9.2
Content-Language: en-US
 by: jrg - Tue, 12 Jul 2022 21:13 UTC

can't grok the issue - been years since I looked at this - now clueless
as to wtf...

https://www.spamcop.net/sc?id=z6765414372z951c9aab132b0e5ee54b6b0bef07d505z

Re: any ideas here?

<takgg2$b97$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=821&group=news.admin.net-abuse.email#821

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.alpha.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Tue, 12 Jul 2022 16:02:44 -0600
Organization: TNet Consulting
Message-ID: <takgg2$b97$1@tncsrv09.home.tnetconsulting.net>
References: <tako56$tdp$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 12 Jul 2022 19:02:26 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="alpha.home.tnetconsulting.net:198.18.18.251";
logging-data="11559"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
In-Reply-To: <tako56$tdp$1@gioia.aioe.org>
Content-Language: en-US
 by: Grant Taylor - Tue, 12 Jul 2022 22:02 UTC

On 7/12/22 3:13 PM, jrg wrote:
> can't grok the issue - been years since I looked at this - now clueless
> as to wtf...

Try starting by asking a question other than implying wtf. ;-)

What are you trying to figure out?

--
Grant. . . .
unix || die

Re: any ideas here?

<tal438$jne$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=822&group=news.admin.net-abuse.email#822

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!aioe.org!5i8Ep7ErYoJUgtWmlIInIw.user.46.165.242.75.POSTED!not-for-mail
From: jeff.g.group@att.net (jrg)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Tue, 12 Jul 2022 17:36:54 -0700
Organization: Aioe.org NNTP Server
Message-ID: <tal438$jne$1@gioia.aioe.org>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: gioia.aioe.org; logging-data="20206"; posting-host="5i8Ep7ErYoJUgtWmlIInIw.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.5.0
X-Notice: Filtered by postfilter v. 0.9.2
Content-Language: en-US
 by: jrg - Wed, 13 Jul 2022 00:36 UTC

On 7/12/22 15:02, Grant Taylor wrote:
> On 7/12/22 3:13 PM, jrg wrote:
>> can't grok the issue - been years since I looked at this - now
>> clueless as to wtf...
>
> Try starting by asking a question other than implying wtf.  ;-)
>
> What are you trying to figure out?
>
>
>
sorry, Grant, I thought the output would be clear to those that
understood this - this isn't to say you don't, its that apparently s/cop
semi-retired before I could learn how they did what they do. I've never
been an admin, just a spam weary user. When I had to change isps, I
wasn't able to change my user name but it worked anyway up to here. So
for me, changing mailhosts is a wtf moment and I don't know if even
possible now.

Parsing header:
0: Received: from 144.160.244.37 (EHLO alph770.prodigy.net) by
10.213.242.213 with SMTPs (version=TLS1_2
cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256); Tue, 12 Jul 2022 06:55:13
+0000
Hostname verified: alph770.prodigy.net
Possible forgery. Supposed receiving system not associated with any of
your mailhosts
Will not trust this Received line.
Mailhost configuration problem, identified internal IP as source
Mailhost:
Please correct this situation - register every email address where you
receive spam
No source IP address found, cannot proceed.
Add/edit your mailhost configuration
Finding full email headers
Submitting spam via email (may work better)
Example: What spam headers should look like
Nothing to do.

addendum Re: any ideas here?

<tal53b$sqm$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=823&group=news.admin.net-abuse.email#823

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!aioe.org!5i8Ep7ErYoJUgtWmlIInIw.user.46.165.242.75.POSTED!not-for-mail
From: jeff.g.group@att.net (jrg)
Newsgroups: news.admin.net-abuse.email
Subject: addendum Re: any ideas here?
Date: Tue, 12 Jul 2022 17:54:02 -0700
Organization: Aioe.org NNTP Server
Message-ID: <tal53b$sqm$1@gioia.aioe.org>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="29526"; posting-host="5i8Ep7ErYoJUgtWmlIInIw.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.5.0
X-Notice: Filtered by postfilter v. 0.9.2
Content-Language: en-US
 by: jrg - Wed, 13 Jul 2022 00:54 UTC

On 7/12/22 17:36, jrg wrote:

> Mailhost configuration problem, identified internal IP as source
> Mailhost:
> Please correct this situation - register every email address where you
> receive spam
> No source IP address found, cannot proceed.
> Add/edit your mailhost configuration

It seems I have no access to accomplish this, so I guess what I need to
know is if am I spinning my wheels here. Only reason being, I received
2 of these spam same day, one spoofing paypal and one netflix. Curious...

Re: any ideas here?

<85719osq-9nn3-o614-p977-25o65nrp625p@zvaqfcevat.pbz>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=824&group=news.admin.net-abuse.email#824

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: dritz@mindspring.com (David Ritz)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Tue, 12 Jul 2022 21:30:22 -0500
Organization: SpamBusters!
Lines: 77
Message-ID: <85719osq-9nn3-o614-p977-25o65nrp625p@zvaqfcevat.pbz>
References: <tako56$tdp$1@gioia.aioe.org> <takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
X-Trace: individual.net JHnduZoBcU67MWNjjtig0QweM7Dd2v9mFIfWuI/16DOzx/vE/o
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:25dnlgayv1vQrc5u6AHre+ca4LE=
In-Reply-To: <tal438$jne$1@gioia.aioe.org>
OpenPGP: id=9CD055375C05466038D2194852BC29991A12DEEB
X-Comment-1: Spam is bad. <http://trillian.mit.edu/~jc/humor/WhatIsSpam.html>
X-Comment-2: LART a spammer for Dobbs.
X-Comment-3: Invalid assumptions tend to produce invalid conclusions.
X-Comment-4: This message is intended to be read with a monospaced font.
X-Meow: yes
 by: David Ritz - Wed, 13 Jul 2022 02:30 UTC

On Tuesday, 12 July 2022 17:36 -0700,
in article <tal438$jne$1@gioia.aioe.org>,
jrg <jeff.g.group@att.net> wrote:

> On 7/12/22 15:02, Grant Taylor wrote:

> sorry, Grant, I thought the output would be clear to those that
> understood this - this isn't to say you don't, its that apparently
> s/cop semi-retired before I could learn how they did what they do.
> I've never been an admin, just a spam weary user. When I had to
> change isps, I wasn't able to change my user name but it worked
> anyway up to here. So for me, changing mailhosts is a wtf moment
> and I don't know if even possible now.

> Parsing header:
> 0: Received: from 144.160.244.37 (EHLO alph770.prodigy.net) by 10.213.242.213
> with SMTPs (version=TLS1_2 cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256); Tue,
> 12 Jul 2022 06:55:13 +0000
> Hostname verified: alph770.prodigy.net
> Possible forgery. Supposed receiving system not associated with any of your
> mailhosts
> Will not trust this Received line.
> Mailhost configuration problem, identified internal IP as source
> Mailhost:
> Please correct this situation - register every email address where you receive
> spam
> No source IP address found, cannot proceed.
> Add/edit your mailhost configuration
> Finding full email headers
> Submitting spam via email (may work better)
> Example: What spam headers should look like
> Nothing to do.

OK, I can't be certain, but it looks like SC is not expecting this
prodigy.net server to be used by your @att.net address. Perhaps, SC
isn't expecting you to be receiving mail at an @att.net, 'cause this
is an AT&T Services, Inc. server, sitting in an AT&T (AMERITECH) /16.

$ whois 144.160.244.37 | grep -iE at.\?t\|^CIDR
CIDR: 144.160.0.0/16
Organization: AT&T Services, Inc. (ATTSE-Z)
OrgName: AT&T Services, Inc.
OrgId: ATTSE-Z
Comment: http://www.att.com
Ref: https://rdap.arin.net/registry/entity/ATTSE-Z
OrgAbuseEmail: abuse@att.net
OrgTechEmail: ew2497@att.com

Additionally, prodigy.net is an AT&T property.

$ whois prodigy.net | grep -iE at.\?t
Registrant Organization: AT&T SERVICES, INC.
Registrant Email: att-domains@att.com
Admin Organization: AT&T SERVICES, INC.
Admin Email: att-domains@att.com
Tech Organization: AT&T SERVICES, INC.
Tech Email: att-domains@att.com

An email originated at an IP address belonging to Apple, 17.57.152.18,
was relayed internally by Apple's 17.58.23.196
(mr85p00im-ztdg06021701.me.com), and delivered to your provider's mail
server, 144.160.244.37 (alph770.prodigy.net). The Apple server was
verified by a yahoo.com server. (Y! used to provide mail services for
AT$T and its subsidiaries.)

Jeff, is your @att.net being forwarded to a Y! address of some sort?
If so, this is likely to cause SC to barf.

If you log into SC, you'll find a Mailhosts tab, between Report Spam
and Statistics. At the bottom of the known hosts, you are offered the
opportunity to add new addresses. Once you jump through the hoops, SC
will recognize the path, even if it is forwarded.

--
David Ritz <dritz@mindspring.com>
Be kind to animals; kiss a shark.

Re: any ideas here?

<tal2c5$tli$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=825&group=news.admin.net-abuse.email#825

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.alpha.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Tue, 12 Jul 2022 21:07:51 -0600
Organization: TNet Consulting
Message-ID: <tal2c5$tli$1@tncsrv09.home.tnetconsulting.net>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Wed, 13 Jul 2022 00:07:33 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="alpha.home.tnetconsulting.net:198.18.18.251";
logging-data="30386"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
In-Reply-To: <tal438$jne$1@gioia.aioe.org>
Content-Language: en-US
 by: Grant Taylor - Wed, 13 Jul 2022 03:07 UTC

On 7/12/22 6:36 PM, jrg wrote:
> sorry, Grant, I thought the output would be clear to those that
> understood this - this isn't to say you don't, its that apparently s/cop
> semi-retired before I could learn how they did what they do.  I've never
> been an admin, just a spam weary user.  When I had to change isps, I
> wasn't able to change my user name but it worked anyway up to here.  So
> for me, changing mailhosts is a wtf moment and I don't know if even
> possible now.

You still haven't asked a question. You've made statements and seem to
be expecting us to infer what your question is.

So it now seems as if you are asking about why SpamCop is responding the
way that they are as opposed to you asking question about the headers.
Is that accurate?

I've not done much with SpamCop in a long time. But when I last did, if
memory serves -- I was forwarding email to them as an attachment. I had
to send the email from an address associated with my SpamCop account and
to a SpamCop address specific to me. Any time that pairing was broken,
for any reason, things did not behave properly.

With that in mind, this hints at the pairing being broken. The pairing
being broken makes sense with your comment about changing ISPs.
(Assuming your registered source address was your address at your old ISP.)

I suspect that you need to follow the "Add/edit your mailhost
configuration" link and update something about your SpamCop account to
properly reflect your new ISP.

If this is not what you're hoping to find an answer for, try asking a
question along the lines of "What does X mean?" or "How do I fix Y?" or
"How do I prevent Z from happening?".

--
Grant. . . .
unix || die

Re: any ideas here?

<tall5h$29u7n$1@cognicom.eternal-september.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=826&group=news.admin.net-abuse.email#826

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!cognicom.eternal-september.org!.POSTED!not-for-mail
From: cognicom@gmail.com (Bob Milutinovic)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Wed, 13 Jul 2022 15:28:12 +1000
Organization: Cognicom
Lines: 27
Message-ID: <tall5h$29u7n$1@cognicom.eternal-september.org>
References: <tako56$tdp$1@gioia.aioe.org>
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset="utf-8";
reply-type=response
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 13 Jul 2022 05:28:18 -0000 (UTC)
Injection-Info: cognicom.eternal-september.org; posting-host="23fc354cf8f292713a950011244453c3";
logging-data="2423031"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+F1BvMyJqTbTPm17cXpxvMsNlql2B3dvc="
Cancel-Lock: sha1:XvaNA7X06bQ7ktO2xLLF/HBdg7I=
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2900.5931
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6157
 by: Bob Milutinovic - Wed, 13 Jul 2022 05:28 UTC

"jrg" <jeff.g.group@att.net> wrote in message
news:tako56$tdp$1@gioia.aioe.org...
> can't grok the issue - been years since I looked at this - now clueless as
> to wtf...
>
> https://www.spamcop.net/sc?id=z6765414372z951c9aab132b0e5ee54b6b0bef07d505z

You have a gaggle of extraneous information introduced by your local mail
server at 10.213.242.213, which SpamCop refuses to process (as it's not an
internet-routable IP).

The first relevant header is this;

Received: from mr85p00im-ztdg06021701.me.com (mr85p00im-ztdg06021701.me.com
[17.58.23.196])
by alph770.prodigy.net (Inbound 8.15.2/8.15.2) with ESMTPS id
26C6tBM5035139
(version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO)
for <x>; Tue, 12 Jul 2022 02:55:12 -0400

Remove everything above that line, then re-submit it - it should then be
parsed properly.

--
Bob Milutinovic
Cognicom

Re: any ideas here?

<tanh7q$d1b$1@panix2.panix.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=827&group=news.admin.net-abuse.email#827

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!panix!.POSTED.panix2.panix.com!panix2.panix.com!not-for-mail
From: kludge@panix.com (Scott Dorsey)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: 13 Jul 2022 22:33:30 -0000
Organization: Former users of Netcom shell (1989-2000)
Lines: 18
Message-ID: <tanh7q$d1b$1@panix2.panix.com>
References: <tako56$tdp$1@gioia.aioe.org> <takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
Injection-Info: reader2.panix.com; posting-host="panix2.panix.com:166.84.1.2";
logging-data="20007"; mail-complaints-to="abuse@panix.com"
 by: Scott Dorsey - Wed, 13 Jul 2022 22:33 UTC

On 7/12/22 6:36 PM, jrg wrote:
> sorry, Grant, I thought the output would be clear to those that
> understood this - this isn't to say you don't, its that apparently s/cop
> semi-retired before I could learn how they did what they do. I've never
> been an admin, just a spam weary user.  When I had to change isps, I
> wasn't able to change my user name but it worked anyway up to here. So
> for me, changing mailhosts is a wtf moment and I don't know if even
> possible now.

1. Who is "s/cop?"
2. What does changing mailhosts have to do with anything?
3. What is the actual problem?

You don't actually include any spam headers in your messsage.
--scott
--
"C'est un Nagra. C'est suisse, et tres, tres precis."

Re: any ideas here?

<taqdm5$aba$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=828&group=news.admin.net-abuse.email#828

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!aioe.org!5i8Ep7ErYoJUgtWmlIInIw.user.46.165.242.75.POSTED!not-for-mail
From: jeff.g.group@att.net (jrg)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Thu, 14 Jul 2022 17:51:15 -0700
Organization: Aioe.org NNTP Server
Message-ID: <taqdm5$aba$1@gioia.aioe.org>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
<tal2c5$tli$1@tncsrv09.home.tnetconsulting.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: gioia.aioe.org; logging-data="10602"; posting-host="5i8Ep7ErYoJUgtWmlIInIw.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.5.0
X-Notice: Filtered by postfilter v. 0.9.2
Content-Language: en-US
 by: jrg - Fri, 15 Jul 2022 00:51 UTC

On 7/12/22 20:07, Grant Taylor wrote:
> On 7/12/22 6:36 PM, jrg wrote:
>> sorry, Grant, I thought the output would be clear to those that
>> understood this - this isn't to say you don't, its that apparently
>> s/cop semi-retired before I could learn how they did what they do.
>> I've never been an admin, just a spam weary user.  When I had to
>> change isps, I wasn't able to change my user name but it worked anyway
>> up to here.  So for me, changing mailhosts is a wtf moment and I don't
>> know if even possible now.
>
> You still haven't asked a question.  You've made statements and seem to
> be expecting us to infer what your question is.
>
> So it now seems as if you are asking about why SpamCop is responding the
> way that they are as opposed to you asking question about the headers.
> Is that accurate?

yessir, silly of me to do so, but I assumed, and that was an oops...
>
> I've not done much with SpamCop in a long time.  But when I last did, if
> memory serves -- I was forwarding email to them as an attachment.  I had
> to send the email from an address associated with my SpamCop account and
> to a SpamCop address specific to me.  Any time that pairing was broken,
> for any reason, things did not behave properly.
>

I have done that once or twice, forget why but have mostly pasted source
into the sc window and got report immediately.

> With that in mind, this hints at the pairing being broken.  The pairing
> being broken makes sense with your comment about changing ISPs.
> (Assuming your registered source address was your address at your old ISP.)
> inally

This is the gist of it - when I last tried to edit/add addresses, sc
seemed to balk and refuse to accept anything but my original addy BUT it
accepted input from my att address.. Since my spam dropped dramatically
at some point, probably due to att filters (I like to think they had to
do something what with their rep), my reporting dropped to nil. Now
seems to be coming back with netflix, paypal, etc spoofs replacing
viagra and nigerians.

> I suspect that you need to follow the "Add/edit your mailhost
> configuration" link and update something about your SpamCop account to
> properly reflect your new ISP.

The problem seems to be the "something" - I don't grok some of the host
entries.
>
> If this is not what you're hoping to find an answer for, try asking a
> question along the lines of "What does X mean?" or "How do I fix Y?" or
> "How do I prevent Z from happening?".
>

I'd like to dump the cox entries since they are history but sc balks at
my changing id.
Thank you for your time - I'll see if David's reply gives me an inkling.

Re: any ideas here?

<taqelv$iq9$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=829&group=news.admin.net-abuse.email#829

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!aioe.org!5i8Ep7ErYoJUgtWmlIInIw.user.46.165.242.75.POSTED!not-for-mail
From: jeff.g.group@att.net (jrg)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Thu, 14 Jul 2022 18:08:13 -0700
Organization: Aioe.org NNTP Server
Message-ID: <taqelv$iq9$1@gioia.aioe.org>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
<tanh7q$d1b$1@panix2.panix.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: gioia.aioe.org; logging-data="19273"; posting-host="5i8Ep7ErYoJUgtWmlIInIw.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.5.0
Content-Language: en-US
X-Notice: Filtered by postfilter v. 0.9.2
 by: jrg - Fri, 15 Jul 2022 01:08 UTC

On 7/13/22 15:33, Scott Dorsey wrote:
> On 7/12/22 6:36 PM, jrg wrote:
>> sorry, Grant, I thought the output would be clear to those that
>> understood this - this isn't to say you don't, its that apparently s/cop
>> semi-retired before I could learn how they did what they do. I've never
>> been an admin, just a spam weary user.  When I had to change isps, I
>> wasn't able to change my user name but it worked anyway up to here. So
>> for me, changing mailhosts is a wtf moment and I don't know if even
>> possible now.
>
>
> 1. Who is "s/cop?"

spamcop

> 2. What does changing mailhosts have to do with anything?

spamcop reporting service

> 3. What is the actual problem?

changing mailhosts in this instance is problematic.
>
> You don't actually include any spam headers in your messsage.

I had in original post, just trimmed down to problem lines since it was
a large pos (piece of shit) and was replying to Grant. It would appear
to be a problem somewhere with at&t, yahoo, and cox. I lost my s/cop
manual (joke).

Thanks for asking.

> --scott

Re: any ideas here?

<taqk2c$6m8$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=830&group=news.admin.net-abuse.email#830

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!aioe.org!5i8Ep7ErYoJUgtWmlIInIw.user.46.165.242.75.POSTED!not-for-mail
From: jeff.g.group@att.net (jrg)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Thu, 14 Jul 2022 19:40:09 -0700
Organization: Aioe.org NNTP Server
Message-ID: <taqk2c$6m8$1@gioia.aioe.org>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
<85719osq-9nn3-o614-p977-25o65nrp625p@zvaqfcevat.pbz>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="6856"; posting-host="5i8Ep7ErYoJUgtWmlIInIw.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.5.0
Content-Language: en-US
X-Notice: Filtered by postfilter v. 0.9.2
 by: jrg - Fri, 15 Jul 2022 02:40 UTC

On 7/12/22 19:30, David Ritz wrote:

<snip>

> Jeff, is your @att.net being forwarded to a Y! address of some sort?
> If so, this is likely to cause SC to barf.

roger that, this just to ack your reply and thank you - I intuitively
thought this but cox/prodigy was getting in the way and SC shows a bunch
of mailhosts, but the genetic relationships need analysis - after the
comet...

jg

Re: any ideas here?

<taqdim$65d$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=831&group=news.admin.net-abuse.email#831

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.alpha.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Thu, 14 Jul 2022 21:49:48 -0600
Organization: TNet Consulting
Message-ID: <taqdim$65d$1@tncsrv09.home.tnetconsulting.net>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
<tal2c5$tli$1@tncsrv09.home.tnetconsulting.net> <taqdm5$aba$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Fri, 15 Jul 2022 00:49:26 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="alpha.home.tnetconsulting.net:198.18.18.251";
logging-data="6317"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
In-Reply-To: <taqdm5$aba$1@gioia.aioe.org>
Content-Language: en-US
 by: Grant Taylor - Fri, 15 Jul 2022 03:49 UTC

On 7/14/22 6:51 PM, jrg wrote:
> yessir, silly of me to do so, but I assumed, and that was an oops...

No apology necessary. I'm fairly sure that we all make innocent and
unintentional mistakes at one point or another in our lives.

> I have done that once or twice, forget why but have mostly pasted source
> into the sc window and got report immediately.

Ah. The last time I used SpamCop, I was forwarding messages (as
attachments to preserve headers) to my personal SpamCop reporting
address. That communications channel /requires/ that the source address
match what they have on file.

> This is the gist of it - when I last tried to edit/add addresses, sc
> seemed to balk and refuse to accept anything but my original addy BUT it
> accepted input from my att address..  Since my spam dropped dramatically
> at some point, probably due to att filters (I like to think they had to
> do something what with their rep), my reporting dropped to nil.  Now
> seems to be coming back with netflix, paypal, etc spoofs replacing
> viagra and nigerians.

I know it's not proper, but I wonder if you could sign up for a new
account with SpamCop using your new address and regain proper access.

> The problem seems to be the "something" - I don't grok some of the host
> entries.

Please clarify if you're talking about (Received:) headers (in what you
linked to) in your original message or something in the SpamCop web
interface for editing hosts?

> I'd like to dump the cox entries since they are history but sc balks at
> my changing id.

I take it that this is a reference to something in the SpamCop web
interface as I don't see (case insensitive) "cox" anywhere (...) in your
original message.

I have refreshed my SpamCop account credentials and am looking at the
Mailhosts (2nd from the left) tab.

I'll do some homework on my end if you'll please explain what you are
seeing and what is causing you to pause. Hopefully together we can get
this to work for you. :-)

> Thank you for your time - I'll see if David's reply gives me an inkling.

You're welcome.

--
Grant. . . .
unix || die

Re: any ideas here?

<taqfl6$p6m$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=833&group=news.admin.net-abuse.email#833

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.alpha.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Thu, 14 Jul 2022 22:25:16 -0600
Organization: TNet Consulting
Message-ID: <taqfl6$p6m$1@tncsrv09.home.tnetconsulting.net>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
<tal2c5$tli$1@tncsrv09.home.tnetconsulting.net> <taqdm5$aba$1@gioia.aioe.org>
<taqdim$65d$1@tncsrv09.home.tnetconsulting.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Fri, 15 Jul 2022 01:24:54 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="alpha.home.tnetconsulting.net:198.18.18.251";
logging-data="25814"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
In-Reply-To: <taqdim$65d$1@tncsrv09.home.tnetconsulting.net>
Content-Language: en-US
 by: Grant Taylor - Fri, 15 Jul 2022 04:25 UTC

On 7/14/22 9:49 PM, Grant Taylor wrote:
> I'll do some homework on my end if you'll please explain what you are
> seeing and what is causing you to pause.  Hopefully together we can get
> this to work for you.  :-)

Well, it seems as if SpamCop has refactored things significantly since I
last used them. They are migrating to a new method that /requires/ mail
host registration / configuration with them.

While poking around in their forums, actually searching the forums for
"mailhost" I found the following link which seems extremely germane to
(what you linked to) your original message.

Link -
Mailhost configuration problem, identified internal IP as source. Please
correct this situation
-
https://forum.spamcop.net/topic/47474-mailhost-configuration-problem-identified-internal-ip-as-source-please-correct-this-situation/#comment-159771

N.B. I don't know if this link is publicly available or if you need to
be signed into SpamCop to access it.

It seems like this is a common symptom when Mailhost(s) isn't (aren't)
configured.

I've added my primary and secondary MX but I don't have any spam at the
moment to test. (I recently purged my junk folder.)

I did receive multiple error reports when I tried to forward the
confirmation messages (as attachments) back to the unique address, along
with one success message. So, I deleted the configured mailhost(s) and
re-did the confirmation using the web form link in the confirmation
emails. (Email's plural b/c of primary and secondary MX.)

--
Grant. . . .
unix || die

Re: any ideas here?

<tark14$39u$1@panix2.panix.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=834&group=news.admin.net-abuse.email#834

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!panix!.POSTED.panix2.panix.com!panix2.panix.com!not-for-mail
From: kludge@panix.com (Scott Dorsey)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: 15 Jul 2022 11:45:40 -0000
Organization: Former users of Netcom shell (1989-2000)
Lines: 22
Message-ID: <tark14$39u$1@panix2.panix.com>
References: <tako56$tdp$1@gioia.aioe.org> <tal438$jne$1@gioia.aioe.org> <tanh7q$d1b$1@panix2.panix.com> <taqelv$iq9$1@gioia.aioe.org>
Injection-Info: reader2.panix.com; posting-host="panix2.panix.com:166.84.1.2";
logging-data="3273"; mail-complaints-to="abuse@panix.com"
 by: Scott Dorsey - Fri, 15 Jul 2022 11:45 UTC

In article <taqelv$iq9$1@gioia.aioe.org>, jrg <jeff.g.group@att.net> wrote:
>
>Thanks for asking.

You don't need any of this. Pull the headers up, start with the first received
line. That's where your mail server got the message from. Go to the next
received line. That's where that server got it from.

Now, you know a lot more than Spamcop does. You know what your ISP is and
that your mail was forwarded from a different ISP, so you can skip over the
received lines relating to those.

The FIRST received line that you see on the way down which doesn't show
something coming from one of your ISPs is trustworthy. All the lines below
that are not reliable.

Ignore all the DKIM stuff. It just clutters everything up. Look at the
first received line that isn't showing the source as one of the ISPs you
are using and THAT source is the place to complain to.
--scott
--
"C'est un Nagra. C'est suisse, et tres, tres precis."

Re: any ideas here?

<tas32b$18fa$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=835&group=news.admin.net-abuse.email#835

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!aioe.org!5i8Ep7ErYoJUgtWmlIInIw.user.46.165.242.75.POSTED!not-for-mail
From: jeff.g.group@att.net (jrg)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Fri, 15 Jul 2022 09:02:11 -0700
Organization: Aioe.org NNTP Server
Message-ID: <tas32b$18fa$1@gioia.aioe.org>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
<tal2c5$tli$1@tncsrv09.home.tnetconsulting.net> <taqdm5$aba$1@gioia.aioe.org>
<taqdim$65d$1@tncsrv09.home.tnetconsulting.net>
<taqfl6$p6m$1@tncsrv09.home.tnetconsulting.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="41450"; posting-host="5i8Ep7ErYoJUgtWmlIInIw.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.5.0
Content-Language: en-US
X-Notice: Filtered by postfilter v. 0.9.2
 by: jrg - Fri, 15 Jul 2022 16:02 UTC

On 7/14/22 21:25, Grant Taylor wrote:

<snip>

> While poking around in their forums, actually searching the forums for
> "mailhost" I found the following link which seems extremely germane to
> (what you linked to) your original message.

germane, indeed...

The forum link on s/c mailhost page (for me) is
http://forum.spamcop.net/forums/index.php?showforum=7
which returns

"The page you requested does not exist "

with a link to sign in, which I couldn't do from there with my original
ID. So something is amiss and maybe an id-ectomy is in order. Aside,
error in above link was "index.php?showforum=7" - so its a bad link, I
guess.
Went back to the error page and noticed a "Home" button on the left
which appeared to be grayed out - that took me to the forum, huh..
1st thing I recognized was Wazoo's name - haven't seen it in over 12 years.

So now, I went to try your link, tyvm, and in the spamcop reporting help
section was a post which had the following bit -
"...getting a waiver from the op because something was not working
using the regular way of setting mailhost." I had had to get a waiver
once long ago, but totally forget why.

be back...

Re: any ideas here?

<tarv1d$moh$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=836&group=news.admin.net-abuse.email#836

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.alpha.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Fri, 15 Jul 2022 11:53:55 -0600
Organization: TNet Consulting
Message-ID: <tarv1d$moh$1@tncsrv09.home.tnetconsulting.net>
References: <tako56$tdp$1@gioia.aioe.org>
<takgg2$b97$1@tncsrv09.home.tnetconsulting.net> <tal438$jne$1@gioia.aioe.org>
<tal2c5$tli$1@tncsrv09.home.tnetconsulting.net> <taqdm5$aba$1@gioia.aioe.org>
<taqdim$65d$1@tncsrv09.home.tnetconsulting.net>
<taqfl6$p6m$1@tncsrv09.home.tnetconsulting.net>
<tas32b$18fa$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Fri, 15 Jul 2022 14:53:33 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="alpha.home.tnetconsulting.net:198.18.18.251";
logging-data="23313"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
In-Reply-To: <tas32b$18fa$1@gioia.aioe.org>
Content-Language: en-US
 by: Grant Taylor - Fri, 15 Jul 2022 17:53 UTC

On 7/15/22 10:02 AM, jrg wrote:
> germane, indeed...

:-)

> The forum link on s/c mailhost page ... returns
>
> "The page you requested does not exist "

Ya, I saw a similar error.

> with a link to sign in, which I couldn't do from there with my original
> ID.  So something is amiss and maybe an id-ectomy is in order.

It sounds like you are finding little errors to chip away at in the
hopes of getting things working.

> Aside, error in above link was "index.php?showforum=7" - so its a
> bad link, I guess.

I don't know the current state of SpamCop. It seems as if their refresh
may be taking a little longer than might have originally been planed.
Or at least that's the impression that I got when I looked at things.

> be back...

Good luck.

I hope that things start working better and better for you.

--
Grant. . . .
unix || die

Re: any ideas here?

<tarv7d$uj5$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=837&group=news.admin.net-abuse.email#837

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.alpha.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: any ideas here?
Date: Fri, 15 Jul 2022 11:57:07 -0600
Organization: TNet Consulting
Message-ID: <tarv7d$uj5$1@tncsrv09.home.tnetconsulting.net>
References: <tako56$tdp$1@gioia.aioe.org> <tal438$jne$1@gioia.aioe.org>
<tanh7q$d1b$1@panix2.panix.com> <taqelv$iq9$1@gioia.aioe.org>
<tark14$39u$1@panix2.panix.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Fri, 15 Jul 2022 14:56:45 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="alpha.home.tnetconsulting.net:198.18.18.251";
logging-data="31333"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
In-Reply-To: <tark14$39u$1@panix2.panix.com>
Content-Language: en-US
 by: Grant Taylor - Fri, 15 Jul 2022 17:57 UTC

On 7/15/22 5:45 AM, Scott Dorsey wrote:
> You don't need any of this.

Eh....

There are a lot of things that we don't /need/ to survive. But having
them sure does make life a lot easier or enjoyable.

> Ignore all the DKIM stuff. It just clutters everything up. Look at
> the first received line that isn't showing the source as one of the
> ISPs you are using and THAT source is the place to complain to.

This is what SpamCop is hoping to automate. This is also why SpamCop
needs to know about your email path. They are trying to automate the
manual algorithm that you described so that it can be done in mass.

They are trying to ground / crowd source believed to be spam and apply
logic to it.

--
Grant. . . .
unix || die

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor