Re: Spamcop failing to detect true originating IP
wskrispy <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.help |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
Ellen wrote: > "wskrispy" <[email protected]> wrote in message > news:[email protected]... > >>N. Miller wrote: >> >>Hold on a sec Ellen and N. Miller-- if you look at the entire message at >>tracker >> > > http://www.spamcop.net/sc?id=z785186974zfb5c4d04f5694f362a90b200bac251bfz;action=display > >> you will see that in the header block below the SA Content Analysis >>there is a third Received header which does in fact identify the >>connecting IP (85.40.108.210). Why didn't Spamcop use this and proceed? >> >>Ellen said "For some reason and for some spams, your server will print 2 >>received headers as above rather than showing the connecting IP as it >>does for other spams". This is not so. All these spams have this header >>block eventually showing the connecting IP. >> > > > > I know what the problem is - there are two ways that an admin can set up SA. > In one method, all the original headers are preserved in their normal order > and the SA stuff is added as X-headers. SC handles this fine. In the second > method, SA adds that block of text and then stuffs the original email into > the message body. SC does not handle spams which have been processed thru SA > in that mode. Either turn off SA or get it set to handle inbound mail > analysis by the other method. > > Ellen > > Ok I'll try the other mode (no way am I turning SA off, my users would instantly be buried under piles of spam dwarfing Mt. Everest). Thanks very much Ellen. -- wsk