Anyway, in case I'm barking up the wrong tree here, this is all the info that I believe is relevant:
First, the relevant parts of the header:
Code: Select all
From - Thu Nov 09 09:31:19 2006
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-Path: <dave@######.org>
Received: from p54800396.dip0.t-ipconnect.de ([84.128.20.132])
by mail.######.org
with hMailServer ; Thu, 9 Nov 2006 09:31:17 -0600
Received: from cusdomain.iinet.net.au (port=12303 helo=wmsffqmhtu)
by p54800396.dip0.t-ipconnect.de with smtp
id 822-1Q66o-f7i
for dave@######.org; Thu, 09 Nov 2006 16:30:59 +0100
Message-ID: <000901c70414$0b50f320$00afaa3c@wmsffqmhtu>
From: "Benjamin Phillips" <yncfgobske@dmecontractors.com.au>
To: dave@######.org
The IP is also has not appeared previously in my greylist (select * from hm_greylisting_triplets where glipaddress=1417680004 reveals nothing; unused records not removed until 1 day and this message was received just a couple hours ago).
Greylist active, 5 minutes to defer delivery attempts, 1 day before removing unused records, 72 to remove used records. Greylisting had been working with 100% success and no false positives before this spammer showed up.
From my log:
Code: Select all
"TCPIP" 3640 "2006-11-09 09:31:15.423" "Created accept socket 2028 on listening socket 1232"
"SMTPD" 3640 4389 "2006-11-09 09:31:15.423" "84.128.20.132" "SENT: 220 mail.######.org ESMTP"
"SMTPD" 3640 4389 "2006-11-09 09:31:15.688" "84.128.20.132" "RECEIVED: EHLO p54800396.dip0.t-ipconnect.de"
"SMTPD" 3640 4389 "2006-11-09 09:31:15.688" "84.128.20.132" "SENT: 250-hmailserver[nl]250-SIZE[nl]250 AUTH LOGIN"
"TCPIP" 3640 "2006-11-09 09:31:15.907" "Created accept socket 1476 on listening socket 1232"
"SMTPD" 3640 4390 "2006-11-09 09:31:15.923" "84.128.20.132" "SENT: 220 mail.######.org ESMTP"
"SMTPD" 3640 4389 "2006-11-09 09:31:15.923" "84.128.20.132" "RECEIVED: MAIL FROM:<dave@######.net>"
"TCPIP" 3640 "2006-11-09 09:31:16.126" "DNS - INAddr lookup: 132.20.128.84.sbl-xbl.spamhaus.org"
"SMTPD" 1968 4390 "2006-11-09 09:31:16.157" "84.128.20.132" "RECEIVED: EHLO p54800396.dip0.t-ipconnect.de"
"SMTPD" 1968 4390 "2006-11-09 09:31:16.157" "84.128.20.132" "SENT: 250-hmailserver[nl]250-SIZE[nl]250 AUTH LOGIN"
"TCPIP" 3640 "2006-11-09 09:31:16.204" "DNSResolver - INAddr Lookup result for 132.20.128.84.sbl-xbl.spamhaus.org: 0 responses"
"TCPIP" 3640 "2006-11-09 09:31:16.204" "DNS - INAddr lookup: 132.20.128.84.relays.ordb.org"
"TCPIP" 3640 "2006-11-09 09:31:16.360" "DNSResolver - INAddr Lookup result for 132.20.128.84.relays.ordb.org: 0 responses"
"TCPIP" 3640 "2006-11-09 09:31:16.360" "DNS - INAddr lookup: 132.20.128.84.bl.spamcop.net"
"SMTPD" 1968 4390 "2006-11-09 09:31:16.423" "84.128.20.132" "RECEIVED: MAIL FROM:<dave@######.org>"
"TCPIP" 1968 "2006-11-09 09:31:16.423" "DNS - INAddr lookup: 132.20.128.84.sbl-xbl.spamhaus.org"
"TCPIP" 1968 "2006-11-09 09:31:16.423" "DNSResolver - INAddr Lookup result for 132.20.128.84.sbl-xbl.spamhaus.org: 0 responses"
"TCPIP" 1968 "2006-11-09 09:31:16.423" "DNS - INAddr lookup: 132.20.128.84.relays.ordb.org"
"TCPIP" 1968 "2006-11-09 09:31:16.423" "DNSResolver - INAddr Lookup result for 132.20.128.84.relays.ordb.org: 0 responses"
"TCPIP" 1968 "2006-11-09 09:31:16.423" "DNS - INAddr lookup: 132.20.128.84.bl.spamcop.net"
"TCPIP" 3640 "2006-11-09 09:31:16.438" "DNSResolver - INAddr Lookup result for 132.20.128.84.bl.spamcop.net: 0 responses"
"SMTPD" 3640 4389 "2006-11-09 09:31:16.454" "84.128.20.132" "SENT: 250 OK"
"TCPIP" 1968 "2006-11-09 09:31:16.516" "DNSResolver - INAddr Lookup result for 132.20.128.84.bl.spamcop.net: 0 responses"
"SMTPD" 1968 4390 "2006-11-09 09:31:16.516" "84.128.20.132" "SENT: 250 OK"
"SMTPD" 3640 4389 "2006-11-09 09:31:16.688" "84.128.20.132" "RECEIVED: RCPT TO:<dave@######.net>"
"SMTPD" 3640 4389 "2006-11-09 09:31:16.688" "84.128.20.132" "SENT: 250 OK"
"SMTPD" 1968 4390 "2006-11-09 09:31:16.735" "84.128.20.132" "RECEIVED: RCPT TO:<dave@######.org>"
"SMTPD" 1968 4390 "2006-11-09 09:31:16.751" "84.128.20.132" "SENT: 250 OK"
"SMTPD" 3640 4389 "2006-11-09 09:31:16.985" "84.128.20.132" "RECEIVED: DATA"
"SMTPD" 3640 4389 "2006-11-09 09:31:16.985" "84.128.20.132" "SENT: 354 OK, send."
"SMTPD" 1968 4390 "2006-11-09 09:31:17.001" "84.128.20.132" "RECEIVED: DATA"
"SMTPD" 1968 4390 "2006-11-09 09:31:17.016" "84.128.20.132" "SENT: 354 OK, send."
"SMTPD" 3640 4389 "2006-11-09 09:31:17.579" "84.128.20.132" "SENT: 250 Queued (0.594 seconds)"
"APPLICATION" 1896 "2006-11-09 09:31:17.595" "SMTPDeliverer - Message 45639: Delivering message from dave@######.net to dave@######.org. File: F:\hMailServer\{36B61447-900A-4B65-B0FE-0F53F50ED21C}.eml"
"SMTPD" 1968 4390 "2006-11-09 09:31:17.845" "84.128.20.132" "SENT: 250 Queued (0.828 seconds)"
"APPLICATION" 1896 "2006-11-09 09:31:17.845" "SMTPDeliverer - Message 45639: Message delivery thread completed."
"APPLICATION" 1896 "2006-11-09 09:31:17.860" "SMTPDeliverer -