Security & Privacy
Spam forgery
Freshness Warning
This blog post is over 17 years old. It's possible that the information you read below isn't current and the links no longer work.
12 Apr 2007
Someone’s sending spam (in Russian and Spanish) using my email address in the To: header of their messages. Not a huge deal, it happens all the time. Anyone charged with defending against spam is savvy to this particular ruse and generally ignores the To header.
But this scumbag is also inserting a forged "Received" header, a message ID, and a return-path header that seems to indicate that my server is sending the spam. It’s all faked, and the server logs show that none of this traffic exists. In fact, the forged headers even specify that I’m using a mail transfer agent that isn’t even installed on the server.
Still, the cleanup from this is a bit of a pain.