Board logo

Someone's hijacked my email account?
Guinness - 18/2/07 at 05:12 PM

Can any computer geniuses help me out?

I have my own domain name, which was registered with freenetname, but has now transfered to madasafish.

For the last six weeks I get 30-40 emails a day, from other peoples email servers, saying "returned mail" or "delivery status failed" etc etc. Most of them appear to have attachements with them, so they get deleted straight away. The few that haven't had attachements and I have opened say "your email contained a virus and was sent from myatzsv@mikecookson.co.uk or some other random email address on my domain"!

I have phoned and emailed madasafish who suggested I turn off my master email account. I did this and didn't get any emails at all for about 2 weeks. First day I turn it back on I get the returned messages again.

I have a current subscription to McAfee and it says my machine is clean. I have even taken to un plugging my machine from the phone socket when I'm at work and I still get the messages when I get home.

HELP

Mike


wilkingj - 18/2/07 at 05:15 PM

Yep, I get the same with my domain name. I just bin them, as I havent got the time to chase them through.


SDS7 - 18/2/07 at 05:24 PM

It most likely that they are using your domain as the senders origin. Its so that you get the returned to sender mails. They don't even have to get any of your details just the domain name. It a common problem with the email system at anyone can impersonate anyone else. Use specific e-mail accounts and turn off your catch all account. That's all you can do until they use someone else's domain name.
I get the same problem from time to time.


ecosse - 18/2/07 at 05:28 PM

Your SMTP service might be getting spammed, do you send outbound mail go through your domain (i.e. your mail clients send settings will say something like smtp.mikecookson.co.uk for outbound mail), and if so, does it require authentication to send?
If it does then change the password to start with and see if that reduces the NDR's you are seeing,

Cheers

Alex


Catpuss - 18/2/07 at 05:48 PM

Its a common one. They are using your domain/email address as the sent from in the email so you get the anti spam attacks/FOAD messages.

Soemone described it to me as, they address the envelope to the recipient but put your address on the letter head.


Guinness - 18/2/07 at 05:55 PM

Thanks guy's

turned off my catch all accounts and changed my passwords.

will see if that helps.

didn't want to end up in court in america accused of sending tonnes of spam!

thanks

mike


scottc - 18/2/07 at 09:48 PM

Hi Mike,

The problem is that originally with SMTP there is no way to verify who the email is from. Its possible to spoof anyones email address, to make emails appear to be from that person.

unfortunately theres not much you can do about it.

If you look at the error messages you receive you should be able to determine where they were sent from.