Monday, March 10, 2014

one more interesting spam

I read another interesting spam email, from

I write to seek your assistance for safe keeping of two military trunk boxes valuable that will be of great benefit to both of us; I will explain further when you respond to my direct Email:  captcaseythoreen@r7.com Capt Casey Thoreen.
US ARMY IN AFGHANISTAN.

Why is a Captain in Afghanistan using the mailbox of r7 in Brasil?
Trust me, I won't contact you.

Tuesday, March 04, 2014

seriously anti-spam

As I was working on the abuse desk today, I found the following E-mail from a so called

Mrs Jasmine Barber <jas@barberfamily.com>

I am Mrs Jasmine A. Barber,suffering from cancerous ailment.I was married to Mr.Raymond Barber,my husband worked with Chevron/Texaco in the United Kingdom for twenty years before he died in the year 2003.My late husband deposited the sum of 5.3 Million (Five Million Three Hundred Thousand Pounds) with a Bank in United Kingdom.

Recently,my Doctor told me that I have limited days to live due to the stroke and cancerous problems I am suffering from. I have decided to donate this fund to you and want you to use this husbands effort to fund the upkeep of widows and charities worldwide.I took this decision because I do not have any child that will inherit this money and my husband relatives are bourgeois and very wealthy persons and I do not want my husband hard earned money to be misused.

Awaiting your urgent reply via my email.address: jasminebarber@qq.com With God all things are possible.

Your Sister in Christ,
Mrs Jasmine A. Barber

Since when QQ supports the mail address with names?
Thought I missed any changes, but after I checked the SMTP session, I am relaxed :)

SMTP session

[Contacting mx3.qq.com [184.105.206.82]...]
[Connected]
220 newmx31.qq.com MX QQ Mail Server
EHLO mx1.validemail.com
250 newmx31.qq.com
MAIL FROM:<>
550 Error: content rejected.http://mail.qq.com/zh_CN/help/content/rejectedmail.html.
MAIL FROM:<>
550 Error: content rejected.http://mail.qq.com/zh_CN/help/content/rejectedmail.html.
[Unfavorable reply code, cannot continue]
RSET
250 Ok
QUIT
221 Bye.
[Connection closed]
[Contacting mx2.qq.com [103.7.29.244]...]
[Connected]
220 newmx97.qq.com MX QQ Mail Server
EHLO mx1.validemail.com
250-newmx97.qq.com
250-SIZE 73400320
250 OK
MAIL FROM:<>
250 Ok
RCPT TO:<jasminebarber@qq.com>
250 Ok
RSET
250 Ok
QUIT
[Connection closed]
Anyway, pay attention on the mails you got!

blacklisting and the spam filter

I have been asked about the blacklisting and the spam filter recently.
Actually I am working on the topic of spam filters momentary at background.
I am pretty interested and trying to figure out which spam filters are used by whom for most important local ISPs.

SpamAssassin is a spam filter, widely used by middle and small ISPs, who haven’t developed their own filters, like the biggest local provider “webmail.co.za” in South Africa.
So, in my opinion, it’s not less important.
This filter stamps every mail with a score, normally a score less than 50 is qualified as non-spam.
The ISP can change a bit on the matrices to get a better control of the strictness for anti-spamming.

Barracuda is a blacklist as well as a filter.
As a blacklist, Barracuda is not as huge or important as Spamhaus, but we should not over see it.
In some countries, like India, Italy, the local providers look up this list to filter incoming emails.
So it is a so called filter deciding to receive or bounce.

As a spam filter (spam filter decides into inbox or spam folder. With the precondition, the mail is received by ISP), I haven’t seen often. So I suppose, it’s not so important.