PDA

View Full Version : Domain Cloning


Rob
26th August 2005, 10:31
In my in-box today I have recieved approximately 150 e-mails - all spam types - supposedly from my site but with a variety of different addresses eg. mail@smallbusinesssuccess.biz, info@.. admin@ etc etc and subject headings.

A call to my host says there is nothing they can do as my domaon has been cloned and they suggest that I improve my spam filter. Fine but my real concern is do these mails come only to me or do they get mailed everywhere? If they do, and the numbers and frequence increase, will some ISP's take me as a spammer and block all my ligitimate outgoing mail?

I issue a weekly newsletter mainly to UK small biz owners, so getting my mail blocked would be a disaster!

Any comments or experience on this problem?

PS if you have received a note threatening you with suspension, closure of account etc ... it's not me!

bitsnstuff
26th August 2005, 10:52
I, unfortunately, have the same problem with one of my domains. My host said that they can't do anything and that it is one of the unfortunate hazzards of the internet.

I only see the ones that bounce or have spam checkers, so are asking for clarification - I dread to think how many are actually being sent that I don't see.

Kate.

DuaneJackson
26th August 2005, 10:56
Hi Rob,

Technicaly it's not cloning. But anyone can send an email and make it look like it came from any address.

These emails are from a worm (can't remeber which now). Don't worry about getting your domain blacklisted. It wont happen because of this. Only the IP that sent the email will get blacklisted, But as this is someones infected PC as opposed to a mailserver it wont help much.

There are steps your ISP can take to reduce the likelihood of people getting emails that appear to be from your domain but actually aren't. There is a record they can put in your DNS that says which server legit emails will come from and any emails that come from another IP are to be treated as suspect. This will work for people whose mail server bothers to check this record, but not for those that don't.

Hope that helps and didn't confuse you!

bitsnstuff
26th August 2005, 11:06
Yes, my host told me something about IP addresses and that they can block them, so I forward the message I get with the full details showing, so that they can add them to the list.

Kate.

MinuWeb
26th August 2005, 14:27
you can setup spf records in yuor DNS zone that can help

http://spf.pobox.com/

If yuor host doesn't know about spf or won't do it I suggest changing your host :D

bitsnstuff
26th August 2005, 14:34
I mentioned that to my host after seeing it posted here before and they said that they had already done it, but I still get the messages. It it better than before, but not cured.

Kate.

DuaneJackson
26th August 2005, 14:37
Unfortunatley until every mailserver on the 'net uses SPF that's the best you can hope for - less, but not none.