Auto reply spam, how come?

Richard G

Verified User
Joined
Jul 6, 2008
Messages
12,554
Location
Maastricht
We're having issues with 1 customer who has an autoreply active.

Spammers are abusing this and sending him spam mail. Then an autoreply is send, but it looks like the original message is included, because we got a complaint from hotmail with the spam message inside.
It's the same message which we also encouter in de mail queue where some of those messages are frozen.

How is this possible? Because we've got this line already in our /etc/exim.variables.custom.conf present on all servers for a long time:
Code:
bounce_return_message = false
which should prevent original messages to be included in autoreply's.

Please explain because we want to keep our mailsystems as good as they are now.
 
Hello Richard,

Autoreply is not the same as bounce, and bounce is not the same as atuto-reply. They are different.

As far as I know autoreply should not include original body, only a predefined text written by an user.
 
You're correct Alex.

But strangely enough the auto reply did contain part of the original message. Very odd indeed. I removed the autoreply from that user and now the problems are gone.
Very strange.
 
It's good to know that the problem is gone. I haven't used the feature for years, so probably there is an option to include an original body into auto-reply.
 
Well... in fact the problem is not gone, it's gone because I removed the autoreply message from the user.
I couldn't find an option to include an original body into auto-reply until now.

So I'm still thinking where it's coming from. Otherwise it can occur again as soon as spammers find another user with autoreply active.
 
I use the latest exim.conf 4.5.x and on my own server I got it working: autoreply was sent without original body.

But it also produced a bounced message:

- Mail delivery failed: returning message to sender

but it's without original body.
 
Thank you Alex.

Unfortunately the queue is empty now, so I can't post any headers or something anymore.
If it will happen again in the future I will reply to this thread and then I'll make sure I will keep a copy of the message in the queue and the headers.
 
Back
Top