RÉSOLU: Redirection mail fantôme

Réception en continu de mails d'avertissement d'erreur d'envoi
Il y a un peu plus de deux ans, je gérais le domaine isnd-d1.be hébergé par OVH. Ce nom de domaine a, depuis, été abandonné. Il est actuellement sans propriétaire.
> $ whois isnd-d1.be
> …
> …
> % By submitting the query you agree to abide by this policy and accept that
> % DNS Belgium can take measures to limit the use of its whois services in order to
> % protect the privacy of its registrants or the integrity of the database.
> %

> Domain: isnd-d1.be
> Status: AVAILABLE

À l'époque, j'avais créé une redirection mail
jsparrow1234@isnd-d1.be (qui n'existe donc plus) vers mon adresse mail ymairesse@sio2.be (qui existe bel et bien). Tout mail envoyé à la première adresse arrivait donc vers la deuxième.
C'était il y a un bon deux ans.
Ces jours-ci, je reçois, environ tous les 1/4h sur mon mail un message d'erreur du type

> Hi. This is the qmail-send program at mx1.ovh.net.
> I'm afraid I wasn't able to deliver your message to the following addresses.
> This is a permanent error; I've given up. Sorry it didn't work out.

> :
> qmail-remote crashed.
> I'm not going to try again; this message has been in the queue too long.

> — Below this line is a copy of the message.

> Return-Path:
> Received: from localhost (HELO queue) (127.0.0.1)
> by localhost with SMTP; 7 Nov 2023 08:36:39 +0200
> Delivered-To: sio2.be-ymairesse@sio2.be

Les adresses IP d'origine de ces envois sont exotiques (Ouzbekistan, Iran,…). Pour information, le "vrai" contenu du mail est un spam me demandant de payer pour que des images compromettantes ne soient pas mises en ligne.

Ma question: est-il possible que cette ancienne redirection depuis un domaine qui n'existe plus soit encore active? Sinon, d'où viennent ces mails (au-delà de Tashkent ou Téhéran)?

Merci de m'avoir lu.


Pour information, le "vrai" contenu du mail est un spam me demandant de payer pour que des images compromettantes ne soient pas mises en ligne.



est-il possible que cette ancienne redirection depuis un domaine qui n'existe plus soit encore active


Bonjour,

C'est très bizarre votre truc, là.

Les spammeurs utilisent peut-être des informations DNS mises en cache quelque part afin qu'on ne puisse pas les repérer en temps réel lorsqu'ils lancent leur campagne de spam.

Si votre ousbèque de spammeur contacte le serveur SMTP d'OVH, OVH rejette le mail. Ce qui est d'autant plus incompréhensible. `554 5.7.1 : Relay access denied`

Les adresses IP d'origine de ces envois sont exotiques


On peut voir les en-têtes complets d'un de ces mails ?
Volontiers...<br /><br /><br /><br />Hi. This is the qmail-send program at mx1.ovh.net.<br />I&#39;m afraid I wasn&#39;t able to deliver your message to the following addresses.<br />This is a permanent error; I&#39;ve given up. Sorry it didn&#39;t work out.<br /><br />:<br />qmail-remote crashed.<br />I&#39;m not going to try again; this message has been in the queue too long.<br /><br />--- Below this line is a copy of the message.<br /><br />Return-Path: <br />Received: from localhost (HELO queue) (127.0.0.1)<br />	by localhost with SMTP; 7 Nov 2023 09:00:24 &#43;0200<br />Delivered-To: sio2.be-ymairesse@sio2.be<br />Received: from localhost (HELO queue) (127.0.0.1)<br />	by localhost with SMTP; 7 Nov 2023 09:00:24 &#43;0200<br />Received: from unknown (HELO output43.mail.ovh.net) (192.168.13.28)<br />  by 192.168.9.47 with AES256-GCM-SHA384 encrypted SMTP; 7 Nov 2023 09:00:24 &#43;0200<br />Received: from vr39.mail.ovh.net (unknown [10.101.8.39])<br />	by out43.mail.ovh.net (Postfix) with ESMTP id 4SPfHX1qSSzWxxrjv<br />	for ; Tue,  7 Nov 2023 07:00:24 &#43;0000 (UTC)<br />Received: from in44.mail.ovh.net (unknown [10.101.4.44])<br />	by vr39.mail.ovh.net (Postfix) with ESMTP id 4SPfHX0Dt0z3pg03<br />	for ; Tue,  7 Nov 2023 07:00:24 &#43;0000 (UTC)<br />Received-SPF: Softfail (mailfrom) identity&#61;mailfrom; client-ip&#61;197.218.241.234; helo&#61;[197.218.241.234]; envelope-from&#61;ymairesse@sio2.be; receiver&#61;ymairesse@sio2.be <br />Authentication-Results: in44.mail.ovh.net; dkim&#61;none; dkim-atps&#61;neutral<br />Received: from [197.218.241.234] (unknown [197.218.241.234])<br />	by in44.mail.ovh.net (Postfix) with SMTP id 4SPfHT0SDrz2RmcBm<br />	for ; Tue,  7 Nov 2023 07:00:20 &#43;0000 (UTC)<br />Received: from tznbczs ([205.225.177.2]) by 81442.com with MailEnable ESMTP; Tue, 7 Nov 2023 09:00:22 &#43;0200<br />Received: (qmail 13516 invoked by uid 135); 7 Nov 2023 09:00:20 &#43;0200<br />From: ymairesse@sio2.be<br />To: ymairesse@sio2.be<br />Subject: [SPAM] I RECORDED YOU!<br />Date: Tue, 7 Nov 2023 09:00:22 &#43;0200<br />Message-ID: &lt;135162.135162@81442.com&gt;<br />Mime-Version: 1.0<br />Content-type: text/plain;<br />X-OVH-Remote: 197.218.241.234 ([197.218.241.234])<br />X-Ovh-Tracer-Id: 16178900187743968219<br />X-VR-SPAMSTATE: SPAM<br />X-VR-SPAMSCORE: 500<br />X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgedvkedrudduhedguddttdcutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecuogfhohhrsghiugguvghntehlphhhrgfuuhgsjhgvtghtucdlhedttddmnecujfgurhephffvufffkfggtgesthdttddttddttdenucfhrhhomhephihmrghirhgvshhsvgesshhiohdvrdgsvgenucggtffrrghtthgvrhhnpeejieeuhfeuhfehgfetleekheefgeeifefhheelteekuedvgedvtefgudeikeffteenucffohhmrghinheptggvgidrihhopdhnvgigohdrtghomhdpsghithhprgihrdgtohhmpdhprgihsghishdrtghomhdpihhnvhhithihrdhiohenucfkphepudeljedrvddukedrvdeguddrvdefgedpvddthedrvddvhedrudejjedrvdenucfhohhrsghiugguvghntehlphhhrgfuuhgsjhgvtghtpehirhgvtghorhguvgguhihouhenucfuphgrmhgfrhhlpehhthhtphhsmedssdgtvgigrdhiohdssghuhidqsghithgtohhinhhspdhhthhtphhsmedssdhprgihsghishdrtghomhdsnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepudeljedrvddukedrvdeguddrvdefgedpmhgrihhlfhhrohhmpeeohihmrghirhgvshhsvgesshhiohdvrdgsvgeqpdhnsggprhgtphhtthhopedupdhrtghpthhtohephihmrghirhgvshhsvgesshhiohdvrdgsvgdpoffvtefjohhsth<br /> epvhhrfeelpdgukhhimhepphgrshhspdhgvghokffrpefokgdprhgvvhfkrfepugihnhgrmhhitgdqrggushhlrdhmohhvihhtvghlrdgtohdrmhii<br />X-Ovh-Spam-Status: SPAM<br />X-Ovh-Spam-Reason: vr: SPAM; dkim: disabled; spf: disabled<br />X-Ovh-Message-Type: SPAM<br />X-Spam-Tag: YES<br /><br />Hello there!<br /><br />Unfortunately, there are some bad news for you.<br /><br />Some time ago your device was infected with my private trojan, R.A.T (Remote Administration Tool), if you want to find out more about it simply use Google.<br />......
Un autre? :)<br />Mine de rien, ça me fait voyager.<br /><br /><br />Hi. This is the qmail-send program at mx1.ovh.net.<br />I&#39;m afraid I wasn&#39;t able to deliver your message to the following addresses.<br />This is a permanent error; I&#39;ve given up. Sorry it didn&#39;t work out.<br /><br />:<br />qmail-remote crashed.<br />I&#39;m not going to try again; this message has been in the queue too long.<br /><br />--- Below this line is a copy of the message.<br /><br />Return-Path: <br />Received: from localhost (HELO queue) (127.0.0.1)<br />	by localhost with SMTP; 7 Nov 2023 10:04:18 &#43;0200<br />Delivered-To: sio2.be-ymairesse@sio2.be<br />Received: from localhost (HELO queue) (127.0.0.1)<br />	by localhost with SMTP; 7 Nov 2023 10:04:18 &#43;0200<br />Received: from unknown (HELO output52.mail.ovh.net) (192.168.13.112)<br />  by 192.168.9.46 with AES256-GCM-SHA384 encrypted SMTP; 7 Nov 2023 10:04:18 &#43;0200<br />Received: from vr50.mail.ovh.net (unknown [10.101.8.50])<br />	by out52.mail.ovh.net (Postfix) with ESMTP id 4SPgjG02CJzX1RmVB<br />	for ; Tue,  7 Nov 2023 08:04:18 &#43;0000 (UTC)<br />Received: from in56.mail.ovh.net (unknown [10.101.4.56])<br />	by vr50.mail.ovh.net (Postfix) with ESMTP id 4SPgjF4X6dz3bTXLn<br />	for ; Tue,  7 Nov 2023 08:04:17 &#43;0000 (UTC)<br />Received-SPF: Softfail (mailfrom) identity&#61;mailfrom; client-ip&#61;83.221.222.62; helo&#61;[83.221.222.62]; envelope-from&#61;ymairesse@sio2.be; receiver&#61;ymairesse@sio2.be <br />Authentication-Results: in56.mail.ovh.net; dkim&#61;none; dkim-atps&#61;neutral<br />Received: from [83.221.222.62] (unknown [83.221.222.62])<br />	by in56.mail.ovh.net (Postfix) with SMTP id 4SPgjC38glz2Rl7q8<br />	for ; Tue,  7 Nov 2023 08:04:15 &#43;0000 (UTC)<br />Received: from nmfookm ([183.147.27.164]) by 51642.com with MailEnable ESMTP; Tue, 7 Nov 2023 11:04:17 &#43;0300<br />Received: (qmail 54362 invoked by uid 543); 7 Nov 2023 11:04:15 &#43;0300<br />From: ymairesse@sio2.be<br />To: ymairesse@sio2.be<br />Subject: [SPAM] I RECORDED YOU!<br />Date: Tue, 7 Nov 2023 11:04:17 &#43;0300<br />Message-ID: &lt;543624.543624@51642.com&gt;<br />Mime-Version: 1.0<br />Content-type: text/plain;<br />X-OVH-Remote: 83.221.222.62 ([83.221.222.62])<br />X-Ovh-Tracer-Id: 17258075248520453083<br />X-VR-SPAMSTATE: SPAM<br />X-VR-SPAMSCORE: 500<br />X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgedvkedrudduhedgudduvdcutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecuogfhohhrsghiugguvghntehlphhhrgfuuhgsjhgvtghtucdlhedttddmnecujfgurhephffvufffkfggtgesthdttddttddttdenucfhrhhomhephihmrghirhgvshhsvgesshhiohdvrdgsvgenucggtffrrghtthgvrhhnpeejieeuhfeuhfehgfetleekheefgeeifefhheelteekuedvgedvtefgudeikeffteenucffohhmrghinheptggvgidrihhopdhnvgigohdrtghomhdpsghithhprgihrdgtohhmpdhprgihsghishdrtghomhdpihhnvhhithihrdhiohenucfkphepkeefrddvvddurddvvddvrdeivddpudekfedrudegjedrvdejrdduieegnecuhfhorhgsihguuggvnhetlhhphhgrufhusghjvggtthepihhrvggtohhruggvugihohhunecuufhprghmfghrlhephhhtthhpshemsddstggvgidrihhosdgsuhihqdgsihhttghoihhnshdphhhtthhpshemsddsphgrhigsihhsrdgtohhmsdenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeekfedrvddvuddrvddvvddriedvpdhmrghilhhfrhhomhepoeihmhgrihhrvghsshgvsehsihhovddrsggvqedpnhgspghrtghpthhtohepuddprhgtphhtthhopeihmhgrihhrvghsshgvsehsihhovddrsggvpdfovfetjfhoshhtpehvrh<br /> ehtddpughkihhmpehprghsshdpghgvohfkrfeptfgfpdhrvghvkffrpeeivddrvddvvddrvddvuddrkeefrdguohhnphgrtgdrrhhu<br />X-Ovh-Spam-Status: SPAM<br />X-Ovh-Spam-Reason: vr: SPAM; dkim: disabled; spf: disabled<br />X-Ovh-Message-Type: SPAM<br />X-Spam-Tag: YES<br /><br />Hello there!<br />........

Received-SPF: Softfail (mailfrom) identity=mailfrom; client-ip=197.218.241.234; helo=[197.218.241.234]; envelope-from=ymairesse@sio2.be; receiver=ymairesse@sio2.be
Authentication-Results: in44.mail.ovh.net; dkim=none; dkim-atps=neutral
Received: from [197.218.241.234] (unknown [197.218.241.234])
by in44.mail.ovh.net (Postfix) with SMTP id 4SPfHT0SDrz2RmcBm
for ymairesse@sio2.be; Tue, 7 Nov 2023 07:00:20 +0000 (UTC)


C'est ceci qui nous intéresse.
Le coupable (une ligne ADSL au mozambique) 197.218.241.234
s'est fait passer pour vous ymairesseXsio2.be
Je suppose que vous avez une redirection (**ou une règle de renvoi avec des filtres**) de sio2 vers isnd-d1 -> la livraison du spam échoue
le message d'erreur vous est renvoyé à sio2 puisque le coupable s'est fait passer pour vous -> il est aussi renvoyé vers isnd-d1 -> il échoue aussi

Effectivement, c'est l'une des premières idées que j'ai eue. Mais non, il n'y a pas de redirection dans le sens ymairesse#sio2.be vers isnd-d1.be

Et le souci n'est pas qu'au Mozambique. J'en tiens aussi:
83.221.222.62 de Krasnodar (RU)
178.90.162.58 de Almati (KZ: Kazakhstan)
29.114.226.243 de Columbus (US)
et des tas d'autres.

Tout se passe comme si le Bot utilisait mon adresse mail pour spammer jsparrow1234@isnd-d1.be
J'ai, bien sûr, changé le mot de passe de mon mail. Aucun effet.

Je continue de chercher.


il n'y a pas de redirection dans le sens ymairesse#sio2.be vers isnd-d1.be


Je vous demandais aussi s'il n'y a pas une règle conditionnelle (par exemple sur le sujet ou l'expéditeur)

Merci de vous acharner.
Règle conditionnelle? C'est possible chez OVH?
Sinon, il n'y en a pas sur mon Thunderbird.


Règle conditionnelle? C'est possible chez OVH?


Sur les anciens hébergements (avec Roundcube)
Voyez ceci dans votre espace client:

avec action: rediriger ...

Bingo!!! Bravo.

Et un tout grand merci pour cette splendide démonstration de compétence!


Bingo!!!!


Et maintenant modifier votre SPF (remplacer ~all par -all) pour bloquer ces pourritures.
Les mails de votre domaine doivent provenir des serveurs d'OVH et pas du Mozambique.