Quantcast
Channel: General — LowEndTalk
Viewing all articles
Browse latest Browse all 22721

Snowshow spammers and "low end" server providers

$
0
0

I've been operating a mailserver for a small tech company since 1999. Naturally we have many email addresses that have become defunct over the years, and both these and most of our current active addresses have been circulating in various spamer's lists for years.

My approach to spam blocking is that upon receipt of a spam from, say, 1.2.3.4, I will search our server's logs for any evidence that a valid or "good" email has ever been received from 1.2.0.0/16. If not, I will add 1.2.0.0/16 to my server's blocking list - regardless of how that /16 is allocated or subdivided. I am blocking about 80 /8 "A-classes", and in total I'm probably blocking 70% of all IPv4 IP space.

Yesterday I noticed in our logs a persistent IP that was attempting SMTP contact, but was being rejected by our server. The IP was 107.182.132.149. The rDNS indicated the domain "queryfoundry.net" - which doesn't seem to operate a website for for which a web search returns nothing useful about that entity. Whois information links that IP to Cloudshards (or Cloud Shards).

A websearch for Cloud Shards / Query Foundary led me to this "low end talk" forum, where (apparently) someone who owns, runs, or works for that entity has posted here.

I just wanted to inform this community, and that person, that according to my own experience (as the repeated, rejected SMTP connection attempts by one of your servers) and Spamhaus entry for 107.182.132.149 confirms that you are indeed hosting a snowshoe spammer, and what-ever claims you are making or have made on this forum that you run a clean operation seems to be false.


Viewing all articles
Browse latest Browse all 22721

Trending Articles