From: Jorey Bump (no email)
Date: Mon Aug 01 2005 - 10:37:51 EDT
Cami wrote:
> Here is another example/reason of a legitimate MTA's
> using different HELO identifies behind one IP address.
>
> +----------------+----------------------+------------+
> | _host | _helo | _expire |
> +----------------+----------------------+------------+
> | 63.251.223.186 | lists.develooper.com | 1122893358 |
> | 63.251.223.186 | x6.develooper.com | 1122897803 |
> +----------------+----------------------+------------+
>
> lists.develooper.com has address 216.52.237.161
> x6.develooper.com has address 63.251.223.186
There are mass mailing applications that will make direct connections to
the MX host. They can be used for good or evil. Do the headers of the
list messages give any clue to the application used?
|
|
|