Need some help here. One of the user has received one spam mail without sender email stated. I tend to block the email/domain name but I'm not sure which is the one. Below is the message log.
Is it the mail.tteia.org.tw I have highlighted in Bold? But how come there are 2 different IPs? (66.154.98.234 and 211.20.132.239)Return-Path:
X-Spam-Checker-Version: SpamAssassin 3.4.1 (2015-04-28) on GCF
X-Spam-Flag: YES
X-Spam-Level: *****
X-Spam-Status: Yes, score=5.1 required=5.0 tests=BAYES_50,DATE_IN_PAST_12_24, FROM_NO_USER,HTML_FONT_LOW_CONTRAST,HTML_MESSAGE,URIBL_BLOCKED,
URI_WP_HACKED_2 autolearn=no autolearn_force=no version=3.4.1
X-Spam-Report: * 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. *
See http://wiki.apache.org/spamassassin/Dns ... nsbl-block *
for more information. * [URIs: mydomain.com] * 0.8 FROM_NO_USER
From: has no local-part before @ sign * 1.0 DATE_IN_PAST_12_24 Date: is
12 to 24 hours before Received: date * 0.0 HTML_MESSAGE BODY: HTML
included in message * 0.8 BAYES_50 BODY: Bayes spam probability is 40 to
60% * [score: 0.5000] * 0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font
color similar or identical to * background * 2.5 URI_WP_HACKED_2 URI
for compromised WordPress site, possible malware
Received: from mx.mail (mail.tteia.org.tw [211.20.132.239]) by mydomain.com with
ESMTP ; Thu, 26 Jul 2018 14:59:37 +0800
Received: by mx.mail (Postfix, from userid 2002) id D2F4A1634BE; Thu, 26 Jul 2018 10:29:39
+0800 (CST)
Received: from [66.154.98.234] (unknown [66.154.98.234]) by mx.mail (Postfix) with
ESMTPA id 26449162EC0 for <user email account>; Thu, 26 Jul 2018
09:20:04 +0800 (CST)
Content-Type: multipart/alternative; boundary="===============0652816647=="
MIME-Version: 1.0
Subject: [SPAM] [5.1] =?utf-8?B?5pyA5b6M5LiA5qyh6K2m5ZGK77yB5oKo55qE6YO1566x5bey6LaF6YGO6YWN?=
=?utf-8?B?6aGN56uL5Y2z5Y2H57Sa5oiW5Lif5aSx6YO1566xIG1heXZpcw==?=.
To: user email account
From: "EMAIL ADMIN" <>
Date: Wed, 25 Jul 2018 03:56:32 -0700
Message-Id: <20180726022939.D2F4A1634BE@mx.mail>
X-Spam-Prev-Subject: =?utf-8?b?5pyA5b6M5LiA5qyh6K2m5ZGK77yB5oKo55qE6YO1566x5bey6LaF6YGO6YWN?=
X-hMailServer-Spam: YES
X-hMailServer-Reason-1: The host name specified in HELO does not match IP address. - (Score: 2)
X-hMailServer-Reason-2: Tagged as Spam by SpamAssassin - (Score: 5)
X-hMailServer-Reason-Score: 7
X-hMailServer-LoopCount: 1
Please help.