Linux – Kept getting “Returned Email” but I didn’t send out anything

email-bounceslinux

This might have something to do with a server that I have set the root user with a forward rule to send me emails. But I am not sure and I can't figure out why… Is it possible that my server has been used by other people to do spamming? My server is in a local network by the way.

Based on the returned content of the email, it's for several spam emails. Pure spam. And the sender is not even ME, not even a proper address (some random name). That's why I think it feels like someone seems relaying emails (spam) through my server. And I got all the returned emails back. My email server (a very good company) didn't treat this as spam. They normally help me block tons of spam automatically.

For example

The original message was received at Sun, 26 Jan 2014 05:05:40 -0700
from m50-134.163.com [123.125.50.134]

   ----- The following addresses had permanent fatal errors -----
<bighyde@myldsmail.net>
    (reason: 550-5.1.1 The email account that you tried to reach does not exist. Please try)

   ----- Transcript of session follows -----
... while talking to aspmx.l.google.com.:
>>> DATA
<<< 550-5.1.1 The email account that you tried to reach does not exist. Please try
<<< 550-5.1.1 double-checking the recipient's email address for typos or
<<< 550-5.1.1 unnecessary spaces. Learn more at
<<< 550 5.1.1 http://support.google.com/mail/bin/answer.py?answer=6596 ha7si10821727icc.12 - gsmtp
550 5.1.1 <bighyde@myldsmail.net>... User unknown
<<< 503 5.5.1 RCPT first. ha7si10821727icc.12 - gsmtp

priearl2003 is the spammer I think.

Content-Type: Message/delivery-status
Content-Description: Delivery error report

Final-Recipient: rfc822; kingston_boy@hotmail.com
Action: failed
Status: 5.0.0
Diagnostic-Code: SMTP; SMTP error, DOT: 550 5.7.0 (SNT0-MC4-F26) Message could not be delivered. Please ensure the message is RFC 5322 compliant..(SMTP&nbsp;error,&nbsp;DOT:&nbsp;550&nbsp;5.7.0&nbsp;(SNT0-MC4-F26)&nbsp;Message&nbsp;could&nbsp;not&nbsp;be&nbsp;delivered.&nbsp;Please&nbsp;ensure&nbsp;the&nbsp;message&nbsp;is&nbsp;RFC&nbsp;5322&nbsp;compliant.)
--------------Boundary-00=_MQ805PDL3A1S4OLBH890
Content-Type: Message/Rfc822
Content-Description: Undelivered Message
Content-Transfer-Encoding: 8bit

Received: from mycomputer (unknown [91.124.65.192])
    by smtp4 (Coremail) with SMTP id DtGowECZB0Ue6ORSchJSDQ--.24287S3;
    Sun, 26 Jan 2014 18:49:20 +0800 (CST)
From: "markp markp" <priearl2003>
To: "keacyking" <keacyking@yahoo.com>, "KC" <kingston_boy@hotmail.com>,
 "sexy kio kyle hot7187493825" <kiozy29@yahoo.com>,
 "rod isreal" <jrskupla@yahoo.com>,
 "korey 3369724167" <sunkillastyle@yahoo.com>,
 "junglefever 04" <junglefever_04@yahoo.com>, "Keino" <keino99@yahoo.com>,
 "Y U WANNA KNOW autour detroit" <mister_kalamazoo@yahoo.com>,
 "Kennen butler buffalo" <luvableguy87@yahoo.com>,
 "=?ISO-8859-1?Q?Charles_Knowles=2C_Jr?=" <charles_r_knowles@yahoo.com>
Subject: markp markp
Date: Sat, 26 Jan 2014 11:49:14 +0100
MIME-Version: 1.0
X-mailer: Microsoft Office Outlook, Build 11.0.5510
Reply-To: priearl2003
Content-type: Multipart/mixed; boundary="3E762EB7_62CA3E41_boundary"
Content-Description: Multipart message
X-CM-TRANSID:DtGowECZB0Ue6ORSchJSDQ--.24287S3
X-Coremail-Antispam: 1Uf129KBjDUn29KB7ZKAUJUUUUU529EdanIXcx71UUUUU7v73
    VFW2AGmfu7bjvjm3AaLaJ3UbIYCTnIWIevJa73UjIFyTuYvjxUa038UUUUU
X-Originating-IP: [91.124.65.192]

--3E762EB7_62CA3E41_boundary
Content-type: text/html; charset=UTF-8
Content-Transfer-Encoding: Quoted-printable
Content-Disposition: inline
Content-Description: HTML text

=EF=BB=BF<html><head><meta http-equiv=3D"content-type" content: text/html;=
 charset=
=3DUTF-8></head><body>http://atasehiringilizcekurslari.org/vhwk/jgmbsvgubadcgt=
ecpios.dcgpurxvlyoigqhfjgxeg</body></html>
--3E762EB7_62CA3E41_boundary--

Best Answer

Based on the information you've provided, this is almost certainly not coming from your server unless you run an open relay. The message originated in China:

inetnum:        123.112.0.0 - 123.127.255.255
netname:        UNICOM-BJ
descr:          China Unicom Beijing province network
descr:          China Unicom
country:        CN
admin-c:        CH1302-AP
tech-c:         SY21-AP
mnt-by:         APNIC-HM
mnt-lower:      MAINT-CNCGROUP-BJ
mnt-routes:     MAINT-CNCGROUP-RR
mnt-irt:        IRT-CU-CN
status:         ALLOCATED PORTABLE

(I got this information from APNIC, after checking ARIN first.)

The most common reason for you to get those emails is that spammers have spoofed your domain ("backscatter," as Marki said). There's not a whole lot you can do about that, but, on the up side, it's unlikely to get you on blocklists, either.

Edit in response to your edit: The second IP listed is from the Ukraine. You can find that number in RIPE.

I suspect that what you're looking at is backscatter from a spambot network that spoofed an address in your domain.

Related Topic