<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CUcFRXY6eyp7ImA9WhBaEk4.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334</id><updated>2013-05-22T16:30:14.813+02:00</updated><category term="IP reputation" /><category term="ipv4" /><category term="CIDR reputation" /><category term="DNSBL" /><category term="apews" /><category term="CIDR" /><category term="l2.apews.org" /><category term="false positive" /><category term="spam blacklist" /><title>APEWS User</title><subtitle type="html">A place where users can report and comment on usage of the APEWS.ORG blocklist as an antispam measure on email servers. In particular the focus is to publish errors, known as false positives, in response to the decline in usefulness of Usenet where formerly there were "sightings" and "blocklists" newsgroups.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://apews-user.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>33</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/ApewsUser" /><feedburner:info uri="apewsuser" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;Dk8ERH8-cSp7ImA9WhBTEUs.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-923551141228670319</id><published>2013-02-06T16:32:00.003+01:00</published><updated>2013-02-06T16:33:25.159+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-06T16:33:25.159+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #19</title><content type="html">This is the latest false positive that we have, been quite a while now. The user subscribed to a newsletter and found this edition in the spam folder;&lt;br /&gt;
&lt;br /&gt;
Wed 2013-02-06 04:24:19: [710:3560] Accepting SMTP connection from [208.73.5.67]&lt;br /&gt;Wed 2013-02-06 04:24:19: [710:3560] Looking up PTR record for 208.73.5.67 (67.5.73.208.IN-ADDR.ARPA)&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] D=67.5.73.208.IN-ADDR.ARPA TTL=(59) PTR=[mail4598.outdoorhub.mkt5196.com]&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] Gathering A-records for PTR hosts&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] D=mail4598.outdoorhub.mkt5196.com TTL=(60) A=[208.73.5.67]&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon; Wed, 06 Feb 2013 04:24:20&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] &amp;lt;-- EHLO mail4598.outdoorhub.mkt5196.com&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] Performing reverse lookup on mail4598.outdoorhub.mkt5196.com (looking for 208.73.5.67)&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] D=mail4598.outdoorhub.mkt5196.com TTL=(60) A=[208.73.5.67]&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] --&amp;gt; 250-xxx.xxx.xxx Hello mail4598.outdoorhub.mkt5196.com, pleased to meet you&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] --&amp;gt; 250-ETRN&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] --&amp;gt; 250-8BITMIME&lt;br /&gt;Wed 2013-02-06 04:24:20: [710:3560] --&amp;gt; 250 SIZE 0&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] &amp;lt;-- MAIL FROM:&amp;lt;xxx @ bounce.outdoorhub.mkt5196.com&amp;gt; BODY=8BITMIME&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] Performing reverse lookup on bounce.outdoorhub.mkt5196.com (looking for 208.73.5.67)&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] D=bounce.outdoorhub.mkt5196.com TTL=(60) A=[74.121.50.42]&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] P=005 D=bounce.outdoorhub.mkt5196.com TTL=(60) MX=[bounce.outdoorhub.mkt5196.com] {74.121.50.42}&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] Spam Blocker A-record resolution of [67.5.73.208.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] Spam Blocker D=67.5.73.208.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] L2.APEWS.ORG LISTED&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] --&amp;gt; 250 &amp;lt;xxx @ bounce.outdoorhub.mkt5196.com&amp;gt;, Sender ok&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] &amp;lt;-- RCPT TO:&amp;lt;xxx @ xxx.xxx&amp;gt;&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] --&amp;gt; 250 &amp;lt;xxx @ xxx.xxx&amp;gt;, Recipient ok&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] &amp;lt;-- DATA&lt;br /&gt;Wed 2013-02-06 04:24:21: [710:3560] --&amp;gt; 354 Enter mail, end with &amp;lt;CRLF&amp;gt;.&amp;lt;CRLF&amp;gt;&lt;br /&gt;Wed 2013-02-06 04:24:22: [710:3560] --&amp;gt; 250 Ok, message saved &amp;lt;Message-ID: 00000000000000000.JavaMail.app @ xxxx.xxx&amp;gt;&lt;br /&gt;Wed 2013-02-06 04:24:22: [710:3560] &amp;lt;-- QUIT&lt;br /&gt;Wed 2013-02-06 04:24:22: [710:3560] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Wed 2013-02-06 04:24:22: [710:3560] SMTP session successful, 36340 bytes transferred.&lt;br /&gt;Wed 2013-02-06 04:24:22: [710:3560] Shuffling message(s) into proper queue(s)&lt;br /&gt;Wed 2013-02-06 04:24:22: [710:3560] Message received from mail4598.outdoorhub.mkt5196.com [208.73.5.67] &amp;lt;xxx @ bounce.outdoorhub.mkt5196.com&amp;gt; with SMTP for &amp;lt;xxx @ xxx.xxx&amp;gt; [Size 36326] {j:\mdaemon\localq\md0000000.msg}&lt;br /&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/ekFk-wrJzyI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/923551141228670319/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2013/02/l2apewsorg-false-positive-19.html#comment-form" title="65 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/923551141228670319?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/923551141228670319?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/ekFk-wrJzyI/l2apewsorg-false-positive-19.html" title="L2.APEWS.ORG False Positive #19" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>65</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2013/02/l2apewsorg-false-positive-19.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEYBQn04eyp7ImA9WhNWFEw.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-4061162017330097912</id><published>2012-12-13T16:21:00.002+01:00</published><updated>2012-12-13T16:22:33.333+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-13T16:22:33.333+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #18</title><content type="html">Here is the full email header for a newsletter that was found in the junk folder but that the recipient subscribed to;&lt;br /&gt;
&lt;br /&gt;
Thu 2012-12-13 03:14:01: [7552:543] Accepting SMTP connection from [89.31.209.89]&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Thu, 13 Dec 2012 03:14:01 -0100&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] &amp;lt;-- HELO newsletter.gan.co.za&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] --&amp;gt; 250 xxx.xxx.xxx Hello newsletter.gan.co.za, pleased to meet you&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] &amp;lt;-- MAIL FROM:&amp;lt;bounce-00000000-00000000@ newsletter.gan.co.za&amp;gt;&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] Spam Blocker A-record resolution of [89.209.31.89.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] Spam Blocker D=89.209.31.89.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] L2.APEWS.ORG LISTED&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] --&amp;gt; 250 &amp;lt;bounce-00000000-00000000@ newsletter.gan.co.za&amp;gt;, Sender ok&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] &amp;lt;-- RCPT TO:&amp;lt;xxx@ xxx.xxx&amp;gt;&lt;br /&gt;Thu 2012-12-13 03:14:01: [7552:543] --&amp;gt; 250 &amp;lt;xxx@ xxx.xxx&amp;gt;, Recipient ok&lt;br /&gt;Thu 2012-12-13 03:14:02: [7552:543] &amp;lt;-- DATA&lt;br /&gt;Thu 2012-12-13 03:14:02: [7552:543] --&amp;gt; 354 Enter mail, end with &amp;lt;CRLF&amp;gt;.&amp;lt;CRLF&amp;gt;&lt;br /&gt;Thu 2012-12-13 03:14:03: [7552:543] --&amp;gt; 250 Ok, message saved &amp;lt;Message-ID: SUPPORT-00000000-00000000-2012.12.13-00.00.00--xxx#xxx.xxx@ newsletter.gan.co.za&amp;gt;&lt;br /&gt;Thu 2012-12-13 03:14:03: [7552:543] &amp;lt;-- RSET&lt;br /&gt;Thu 2012-12-13 03:14:03: [7552:543] Shuffling message(s) into proper queue(s)&lt;br /&gt;Thu 2012-12-13 03:14:03: [7552:543] Message received from newsletter.gan.co.za [89.31.209.89] &amp;lt;bounce-00000000-00000000@ newsletter.gan.co.za&amp;gt; with SMTP for &amp;lt;xxx@ xxx.xxx&amp;gt; [Size 55311] {j:\localq\0000231504.msg}&lt;br /&gt;Thu 2012-12-13 03:14:03: [7552:543] SMTP session successful, 55322 bytes transferred.&lt;br /&gt;Thu 2012-12-13 03:14:03: [7552:543] --&amp;gt; 250 RSET? Well, ok.&lt;br /&gt;Thu 2012-12-13 03:14:08: [7552:543] &amp;lt;-- QUIT&lt;br /&gt;Thu 2012-12-13 03:14:08: [7552:543] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Thu 2012-12-13 03:14:08: [7552:543] SMTP session successful, 55328 bytes transferred.&lt;br /&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/pW7YGLtsozI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/4061162017330097912/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/12/l2apewsorg-false-positive-18.html#comment-form" title="35 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/4061162017330097912?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/4061162017330097912?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/pW7YGLtsozI/l2apewsorg-false-positive-18.html" title="L2.APEWS.ORG False Positive #18" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>35</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/12/l2apewsorg-false-positive-18.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkMDRn05eip7ImA9WhJbF0U.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-4010998820798709294</id><published>2012-09-28T00:06:00.001+02:00</published><updated>2012-09-28T00:21:17.322+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-28T00:21:17.322+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #17</title><content type="html">Here is a newsletter that our user subscribed to but that ended up in the spam folder. User confirmed consent to receive this so the full email header is provided here for APEWS.org Admins to see and correct if they want to;&lt;br /&gt;
&lt;br /&gt;
Wed 2012-09-26 11:55:27: [180:366] Accepting SMTP connection from [67.222.55.9]&lt;br /&gt;
Wed 2012-09-26 11:55:27: [180:366] Looking up PTR record for 67.222.55.9 (9.55.222.67.IN-ADDR.ARPA)&lt;br /&gt;
Wed 2012-09-26 11:55:28: [180:366] D=9.55.222.67.IN-ADDR.ARPA TTL=(1440) PTR=[oproxy7-pub.bluehost.com]&lt;br /&gt;
Wed 2012-09-26 11:55:28: [180:366] Gathering A-records for PTR hosts&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] D=oproxy7-pub.bluehost.com TTL=(240) A=[67.222.55.9]&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] --&amp;gt; 220 xxx.xxx.xxx ESMTP ; Wed, 26 Sep 2012 11:55:27 -0100&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] &amp;lt;-- HELO oproxy7-pub.bluehost.com&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] Performing reverse lookup on oproxy7-pub.bluehost.com (looking for 67.222.55.9)&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] D=oproxy7-pub.bluehost.com TTL=(239) A=[67.222.55.9]&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] --&amp;gt; 250 xxx.xxx.xxx Hello oproxy7-pub.bluehost.com, pleased to meet you&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] &amp;lt;-- MAIL FROM:&amp;lt;xxx@ box731.bluehost.com&amp;gt;&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] Performing reverse lookup on box731.bluehost.com (looking for 67.222.55.9)&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] D=box731.bluehost.com TTL=(240) A=[66.147.244.231]&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] Spam Blocker A-record resolution of [9.55.222.67.L2.APEWS.ORG] in progress...&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] Spam Blocker D=9.55.222.67.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] L2.APEWS.ORG LISTED&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] --&amp;gt; 250 &amp;lt;xxx@ box731.bluehost.com&amp;gt;, Sender ok&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] &amp;lt;-- RCPT TO:&amp;lt;xxx@ xxx.xxx&amp;gt;&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] 'Recipient unknown' given to divert future spam&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] --&amp;gt; 550 &amp;lt;xxx@ xxx.xxx&amp;gt;, Recipient unknown&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] &amp;lt;-- QUIT&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;
Wed 2012-09-26 11:55:29: [180:366] SMTP session successful, 124 bytes transferred.&lt;br /&gt;
&lt;br /&gt;
Note for other posters here, we operate email servers that receive emails for our users, one has complained to us about this false positive, we are publishing it.&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/GBuI8vmCDyc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/4010998820798709294/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/09/l2apewsorg-false-positive-17.html#comment-form" title="80 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/4010998820798709294?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/4010998820798709294?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/GBuI8vmCDyc/l2apewsorg-false-positive-17.html" title="L2.APEWS.ORG False Positive #17" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>80</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/09/l2apewsorg-false-positive-17.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UCSXo5eip7ImA9WhJbEUw.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-371178558632640517</id><published>2012-09-20T07:33:00.000+02:00</published><updated>2012-09-20T07:34:28.422+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-20T07:34:28.422+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>Still no False Positives</title><content type="html">There simply haven't been any false positives to write about. A lot of people are requesting delisting and removal from Apews.org here but they are all email senders whereas this blog is aimed at receivers of email that use the apews.org data for filtering or blocking.&lt;br /&gt;
&lt;br /&gt;
Anyone wanting a removal would do better to publish the email header from a receiver as we have done.&lt;br /&gt;
&lt;br /&gt;
These days it's all about reputation and permission, even new allocations to existing ISPs that have a bad rep can expect to remain listed. Folks have had enough of snowshoe spamming out of newly acquired IP blocks.&lt;br /&gt;
&lt;br /&gt;
IPv4 address space is nearly all allocated and most of it has been assessed by the apews.org team to great effect. Consistently trapping 95% or more of spam sent with less then 0.5% false positives is a great statistic so there can't be much wrong with the apews.org data. We encourage email receivers to publish errors here, prove the error with the full email headers, munge them for privacy if you want to. That way there is a public record of the error in your view, shame apews.org into fixing that error.&lt;br /&gt;
&lt;br /&gt;
We can see that soon there will be no more IPv4 addresses for spammers to pollute, old existing allocations will have to be cleaned up in order to regain a good rep or stay listed. No residential IP address space needs to send email so outbound connections to port TCP 25 should be disallowed at the ISP firewall and it's so easy to do.&lt;br /&gt;
&lt;br /&gt;
Right now there needs to be a 2 tier tariff for IP addresses, the price for apews.org listed IP address space should be dirt cheap to rent or even free since there is ad revenue from the http traffic. That is the usual business model, give free access with commercials which cover the costs incurred. ISPs are running all their user traffic through http proxy servers for ad tracking etc, try blocking their http server addresses at your firewall and you will lose your internet connection.&lt;br /&gt;
&lt;br /&gt;
Clean IP address space that never gets listed by blacklists is obviously run professionally and volume email senders do so with the permission of the recipient. Their IP address space should command a premium in value and they deserve to earn more out of their email sending services e.g. providing smart hosts for clients. They won't take dirty email databases though :-) If you're really serious about inboxing then pay for a service from one of these guys.&lt;br /&gt;
&lt;br /&gt;
Nice to see more email servers using the l2.apews.org for blocking as published on NANAE usenet newsgroup recently. Spam is no longer problem. We've had a lot of extra spare time for server maintenance and monitoring the whitelists, user complaints have stopped and the techs are up to date. In our server logs we've seen subscriptions to newsletter being honored, not bounced by using the apews dataset, what more can I say. Once we see the subscription process followed by an acceptance email we whitelist that enews server.&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/KEcRaS6uMtc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/371178558632640517/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/09/still-no-false-positives.html#comment-form" title="18 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/371178558632640517?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/371178558632640517?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/KEcRaS6uMtc/still-no-false-positives.html" title="Still no False Positives" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>18</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/09/still-no-false-positives.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0IMQno9eyp7ImA9WhVaFk4.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-6478292336797942258</id><published>2012-06-14T02:58:00.001+02:00</published><updated>2012-06-14T02:59:43.463+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-14T02:59:43.463+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><title>Some analysis of Apews data</title><content type="html">This has taken a while since there is a lot of it! By comparing our own records with listings that exist in the Apews dataset we have been able to conclude the following;&lt;br /&gt;
&lt;br /&gt;
Single IP addresses that have made a direct connection to our servers in order to send spam email have also been found in C-1, C-2, C-12, C-35C-52, C-53, C-66, C-67, C-73 and C-630.&lt;br /&gt;
&lt;br /&gt;
Mostly /24 listings can mostly be found in C-3, C-11, C-13, C-21, C-36, C-41, C-130, C-1375 and C-1402. These /24 generally include the above single IP addresses suggesting that they are maybe escalations.&lt;br /&gt;
&lt;br /&gt;
Single IP addresses that have done port scanning, SSH probes, attempted PHP or SQL injection, password guessing, hosting landing pages that contain virus, trojan etc have only been found in C-16 and C-86.&lt;br /&gt;
&lt;br /&gt;
CIDR that contain residential customers, typically have no reverse DNS and generic host names (as noted in some records by Apews) have been found in C-22, C-1010 and C-1403. These are often referred to as dynamic since they can be large DHCP pools too. These CIDR would not be RFC compliant for the sending of emails.&lt;br /&gt;
&lt;br /&gt;
Other CIDR, usually larger than /24, can be found in C-14, C-15, C-17, C-18, C-20, C-79, C-258 and C-813.&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/ZEeiCrsraGs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/6478292336797942258/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/06/some-analysis-of-apews-data.html#comment-form" title="38 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/6478292336797942258?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/6478292336797942258?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/ZEeiCrsraGs/some-analysis-of-apews-data.html" title="Some analysis of Apews data" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>38</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/06/some-analysis-of-apews-data.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YGQnkzcSp7ImA9WhVaEEU.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-3952415432138446030</id><published>2012-06-07T16:57:00.003+02:00</published><updated>2012-06-07T16:58:43.789+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-07T16:58:43.789+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #16</title><content type="html">A /19 that was listed back in April caught this recently, definitely a user subscribed newsletter;&lt;br /&gt;
&lt;br /&gt;
Wed 2012-06-06 08:55:21: [140:457] Accepting SMTP connection from [109.123.106.210]&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Looking up PTR record for 109.123.106.210 (210.106.123.109.IN-ADDR.ARPA)&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] D=210.106.123.109.IN-ADDR.ARPA TTL=(1439) PTR=[srv-eight.clevercherry.net]&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Gathering A-records for PTR hosts&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] D=srv-eight.clevercherry.net TTL=(240) A=[109.123.106.210]&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Wed, 06 Jun 2012 08:55:21 -0100&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] &amp;lt;-- EHLO srv-eight.clevercherry.net&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Performing reverse lookup on srv-eight.clevercherry.net (looking for 109.123.106.210)&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] D=srv-eight.clevercherry.net TTL=(240) A=[109.123.106.210]&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250-xxx.xxx.xxx Hello srv-eight.clevercherry.net, pleased to meet you&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250-ETRN&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250-8BITMIME&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250 SIZE 0&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] &amp;lt;-- MAIL FROM:&amp;lt;xxx @ xxx.xxx&amp;gt; SIZE=16289&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Performing reverse lookup on xxx.clevercherry.com (looking for 109.123.106.210)&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] D=xxx.clevercherry.com TTL=(240) A=[109.123.106.210]&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Spam Blocker A-record resolution of [210.106.123.109.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Spam Blocker D=210.106.123.109.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] L2.APEWS.ORG LISTED&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250 &amp;lt;xxx @ xxx.xxx&amp;gt;, Sender ok&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] &amp;lt;-- RCPT TO:&amp;lt;xxx @ xxx.xxx&amp;gt;&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250 &amp;lt;xxx @ xxx.xxx&amp;gt;, Recipient ok&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] &amp;lt;-- DATA&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 354 Enter mail, end with &amp;lt;CRLF&amp;gt;.&amp;lt;CRLF&amp;gt;&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 250 Ok, message saved &amp;lt;Message-ID: E1ScCvc-0005YX-27@srv-eight.clevercherry.net&amp;gt;&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] &amp;lt;-- QUIT&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] SMTP session successful, 15603 bytes transferred.&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Shuffling message(s) into proper queue(s)&lt;br /&gt;Wed 2012-06-06 08:55:21: [140:457] Message received from srv-eight.clevercherry.net [109.123.106.210] &amp;lt;xxx @ xxx.xxx&amp;gt; with SMTP for &amp;lt;xxx @ xxx.xxx&amp;gt; [Size 10502] {j:\localq\6443522.msg}&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/2OmudZ23wQI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/3952415432138446030/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/06/l2apewsorg-false-positive-16.html#comment-form" title="35 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/3952415432138446030?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/3952415432138446030?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/2OmudZ23wQI/l2apewsorg-false-positive-16.html" title="L2.APEWS.ORG False Positive #16" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>35</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/06/l2apewsorg-false-positive-16.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D04ESXg6cSp7ImA9WhVUEUk.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-1086310023974208878</id><published>2012-05-16T07:25:00.000+02:00</published><updated>2012-05-16T07:25:08.619+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-16T07:25:08.619+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>DNS Blacklist Editor</title><content type="html">I came across a useful tool (freeware) at http://www.jhsoft.com/ which is for editing a DNS blacklist. By using RSYNC we got a copy of the APEWS dataset and opened it up using the above tool, great. For some people it might be easier to edit APEWS data for their own purposes in order to reduce false positives or blacklist more IPv4 than APEWS currently covers. There are reports of L2.APEWS.ORG dataset catching between 95% and 99% of all spam so that shouldn't take much editing to tailor it for any one system.&lt;br /&gt;
&lt;br /&gt;
Some DNS blacklist databases separate the type of blacklisting by using a code number in the dns record of the listed IP address e.g. an email spam sender IP might get a DNSBL response of 127.0.0.3, a spam relay IP could show as 127.0.0.4 but a trojan hosting website IP come back with 127.0.0.5. Those different 127.0.0.* IP addresses can be used for filtering email or other traffic by e.g. using the "3" and "4" for an inbound email stream but the "5" for outbound HTTP traffic i.e. preventing users getting to the trojan host. However it looks like APEWS dataset returns just one reply to queries "L2.APEWS.ORG TTL=(35) A=[127.0.0.2]".&lt;br /&gt;
&lt;br /&gt;
Looking through the listings and reviewing the comments that used to be written in the earlier records, we can see some groups of "Cases" that may be useful to some people if C number can be obtained. It should even be possible to extract the relevant data to build smaller datasets specific to a need. The groups of Cases and their text descriptors etc will be published shortly.&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/oyWj8MooKoI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/1086310023974208878/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/05/dns-blacklist-editor.html#comment-form" title="259 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/1086310023974208878?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/1086310023974208878?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/oyWj8MooKoI/dns-blacklist-editor.html" title="DNS Blacklist Editor" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>259</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/05/dns-blacklist-editor.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YGQnkzcCp7ImA9WhVaEEU.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-1311085699608552858</id><published>2012-04-04T17:50:00.002+02:00</published><updated>2012-06-07T16:58:43.788+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-07T16:58:43.788+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #15</title><content type="html">This one is a newsletter and although the listing was showing as /24, it has already been corrected at the time of writing. Posting the error here for archive purposes;&lt;br /&gt;&lt;br /&gt;Wed 2012-04-03 07:50:58: [448:627] Accepting SMTP connection from [24.38.56.81]&lt;br /&gt;Wed 2012-04-03 07:50:58: [448:627] Looking up PTR record for 24.38.56.81 (81.56.38.24.IN-ADDR.ARPA)&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] D=81.56.38.24.IN-ADDR.ARPA TTL=(1439) PTR=[mailb.info.humanevents.com]&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] Gathering A-records for PTR hosts&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] D=mailb.info.humanevents.com TTL=(1440) A=[24.38.56.81]&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Wed, 04 Apr 2012 08:50:59 -0500&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] &amp;lt;-- EHLO mailb.info.humanevents.com&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] Performing reverse lookup on mailb.info.humanevents.com (looking for 24.38.56.81)&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] D=mailb.info.humanevents.com TTL=(1440) A=[24.38.56.81]&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] --&amp;gt; 250-xxx.xxx.xxx Hello mailb.info.humanevents.com, pleased to meet you&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] --&amp;gt; 250-ETRN&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] --&amp;gt; 250-8BITMIME&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] --&amp;gt; 250 SIZE 0&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] &amp;lt;-- MAIL FROM:&lt;gunsandpatriots com=""&gt; BODY=8BITMIME&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] Performing reverse lookup on info.humanevents.com (looking for 24.38.56.81)&lt;br /&gt;Wed 2012-04-03 07:50:59: [448:627] D=info.humanevents.com TTL=(1440) A=[74.201.50.22]&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] P=030 D=info.humanevents.com TTL=(1439) MX=[mx2.info.humanevents.com] {74.201.50.6}&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] P=010 D=info.humanevents.com TTL=(1439) MX=[mx1.info.humanevents.com] {74.201.50.4}&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] Spam Blocker A-record resolution of [81.56.38.24.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] Spam Blocker D=81.56.38.24.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] L2.APEWS.ORG LISTED&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] --&amp;gt; 250 &lt;gunsandpatriots com=""&gt;, Sender ok&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] &amp;lt;-- RCPT TO:&lt;xxx xxx=""&gt;&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] --&amp;gt; 250 &lt;xxx xxx=""&gt;, Recipient ok&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] &amp;lt;-- DATA&lt;br /&gt;Wed 2012-04-03 07:51:00: [448:627] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Wed 2012-04-03 07:51:01: [448:627] --&amp;gt; 250 Ok, message saved &lt;message-id: 1111111="" com=""&gt;&lt;br /&gt;Wed 2012-04-03 07:51:01: [448:627] &amp;lt;-- QUIT&lt;br /&gt;Wed 2012-04-03 07:51:01: [448:627] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Wed 2012-04-03 07:51:01: [448:627] SMTP session successful, 34147 bytes transferred.&lt;br /&gt;Wed 2012-04-03 07:51:01: [448:627] Shuffling message(s) into proper queue(s)&lt;br /&gt;Wed 2012-04-03 07:51:01: [448:627] Message received from mailb.info.humanevents.com [24.38.56.81] &lt;gunsandpatriots@info.humanevents.com&gt; with SMTP for &lt;xxx xxx=""&gt; [Size 3412] {j:\localq\0000000.msg}&lt;br /&gt;Wed 2012-04-03 07:51:01: ----------&lt;br /&gt;&lt;br /&gt;The sending server itself was not listed but the small group listing affected it causing a false positive for us. Resolved already.&lt;br /&gt;&lt;/xxx&gt;&lt;/gunsandpatriots@info.humanevents.com&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx&gt;&lt;/xxx&gt;&lt;/gunsandpatriots&gt;&lt;/gunsandpatriots&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/W_as9U6rqBY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/1311085699608552858/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/04/l2apewsorg-false-positive-15.html#comment-form" title="74 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/1311085699608552858?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/1311085699608552858?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/W_as9U6rqBY/l2apewsorg-false-positive-15.html" title="L2.APEWS.ORG False Positive #15" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>74</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/04/l2apewsorg-false-positive-15.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YGQnkyeSp7ImA9WhVaEEU.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-5091097112485068996</id><published>2012-04-02T19:03:00.002+02:00</published><updated>2012-06-07T16:58:43.791+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-07T16:58:43.791+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #14</title><content type="html">This one came in over the weekend but has already been delisted by the APEWS Administrators. Just posting the email here for archive etc;&lt;br /&gt;&lt;br /&gt;Sat 2012-03-31 12:30:29: [520:540] Accepting SMTP connection from [178.33.45.10]&lt;br /&gt;Sat 2012-03-31 12:30:29: [520:540] Looking up PTR record for 178.33.45.10 (10.45.33.178.IN-ADDR.ARPA)&lt;br /&gt;Sat 2012-03-31 12:30:30: [520:540] D=10.45.33.178.IN-ADDR.ARPA TTL=(1440) PTR=[18.mo5.mail-out.ovh.net]&lt;br /&gt;Sat 2012-03-31 12:30:30: [520:540] Gathering A-records for PTR hosts&lt;br /&gt;Sat 2012-03-31 12:30:30: [520:540] D=18.mo5.mail-out.ovh.net TTL=(1440) A=[178.33.45.10]&lt;br /&gt;Sat 2012-03-31 12:30:30: [520:540] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Sat, 30 Mar 2012 22:30:30 -0500&lt;br /&gt;Sat 2012-03-31 12:30:30: [520:540] &amp;lt;-- EHLO mo5.mail-out.ovh.net&lt;br /&gt;Sat 2012-03-31 12:30:30: [520:540] Performing reverse lookup on mo5.mail-out.ovh.net (looking for 178.33.45.10)&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] D=mo5.mail-out.ovh.net TTL=(1440) A=[178.32.228.5]&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] --&amp;gt; 250-xxx.xxx.xxx Hello 18.mo5.mail-out.ovh.net (may be forged), pleased to meet you&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] --&amp;gt; 250-ETRN&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] --&amp;gt; 250-8BITMIME&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] --&amp;gt; 250 SIZE 0&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] &amp;lt;-- MAIL FROM:&lt;yyy@yyy.yyy&gt; SIZE=6970&lt;br /&gt;Sat 2012-03-31 12:30:31: [520:540] Performing reverse lookup on yyy.yyy (looking for 178.33.45.10)&lt;br /&gt;Sat 2012-03-31 12:30:32: [520:540] D=yyy.yyy TTL=(1439) A=[213.186.33.5]&lt;br /&gt;Sat 2012-03-31 12:30:32: [520:540] P=100 D=webster.fr TTL=(1440) MX=[mxb.ovh.net]&lt;br /&gt;Sat 2012-03-31 12:30:32: [520:540] P=001 D=webster.fr TTL=(1440) MX=[mx0.ovh.net] {213.186.33.32}&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] D=mxb.ovh.net TTL=(1440) A=[213.186.39.173]&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] Spam Blocker A-record resolution of [10.45.33.178.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] Spam Blocker D=10.45.33.178.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] L2.APEWS.ORG LISTED&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] --&amp;gt; 250 &lt;yyy@yyy.yyy&gt;, Sender ok&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] &amp;lt;-- DATA&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Sat 2012-03-31 12:30:33: [520:540] --&amp;gt; 250 Ok, message saved &lt;message-id: dddddddddddddddd="" com=""&gt;&lt;br /&gt;Sat 2012-03-31 12:30:34: [520:540] &amp;lt;-- QUIT&lt;br /&gt;Sat 2012-03-31 12:30:34: [520:540] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Sat 2012-03-31 12:30:34: [520:540] SMTP session successful, 7307 bytes transferred.&lt;br /&gt;Sat 2012-03-31 12:30:34: [520:540] Shuffling message(s) into proper queue(s)&lt;br /&gt;Sat 2012-03-31 12:30:34: [520:540] Message received from mo5.mail-out.ovh.net [178.33.45.10] &lt;yyy@yyy.yyy&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 796] {j:\localq\md00000000.msg}&lt;br /&gt;&lt;br /&gt;OVH often have mail servers in the top 100 spam sources so no surprise that it was listed.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/yyy@yyy.yyy&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/yyy@yyy.yyy&gt;&lt;/yyy@yyy.yyy&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/Mb3-hJzs7BU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/5091097112485068996/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/04/l2apewsorg-false-positive-14.html#comment-form" title="27 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/5091097112485068996?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/5091097112485068996?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/Mb3-hJzs7BU/l2apewsorg-false-positive-14.html" title="L2.APEWS.ORG False Positive #14" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>27</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/04/l2apewsorg-false-positive-14.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YGQnkyeip7ImA9WhVaEEU.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-8347409142470183440</id><published>2012-03-18T17:19:00.002+01:00</published><updated>2012-06-07T16:58:43.792+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-07T16:58:43.792+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #13</title><content type="html">Typical eh, spoke too soon! Got a user claiming the following shouldn't have been in his junk folder and on further checking we find the IP address to be that of a website offering a newsletter. CIDR seems OK too, here is the email header;&lt;br /&gt;&lt;br /&gt;Sat 2012-03-17 03:26:37: [7708:766] Accepting SMTP connection from [71.19.224.98]&lt;br /&gt;Sat 2012-03-17 03:26:37: [7708:766] Looking up PTR record for 71.19.224.98 (98.224.19.71.IN-ADDR.ARPA)&lt;br /&gt;Sat 2012-03-17 03:26:37: [7708:766] D=98.224.19.71.IN-ADDR.ARPA TTL=(59) PTR=[www3.tiltedpixel.com]&lt;br /&gt;Sat 2012-03-17 03:26:37: [7708:766] Gathering A-records for PTR hosts&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] D=www3.tiltedpixel.com TTL=(240) A=[71.19.224.98]&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Sat, 16 Mar 2012 13:06:38 -0500&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] &amp;lt;-- EHLO www3.tiltedpixel.com&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] Performing reverse lookup on www3.tiltedpixel.com (looking for 71.19.224.98)&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] D=www3.tiltedpixel.com TTL=(240) A=[71.19.224.98]&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250-xxx.xxx.xxx Hello www3.tiltedpixel.com, pleased to meet you&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250-ETRN&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250-8BITMIME&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250 SIZE 0&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] &amp;lt;-- MAIL FROM:&lt;retpower com=""&gt; SIZE=1656&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] Performing reverse lookup on www3.tiltedpixel.com (looking for 71.19.224.98)&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] D=www3.tiltedpixel.com TTL=(239) A=[71.19.224.98]&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] Spam Blocker A-record resolution of [98.224.19.71.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] Spam Blocker D=98.224.19.71.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] L2.APEWS.ORG LISTED&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250 &lt;retpower com=""&gt;, Sender ok&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] &amp;lt;-- DATA&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 250 Ok, message saved &lt;message-id: 000="" com=""&gt;&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] &amp;lt;-- QUIT&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] SMTP session successful, 959 bytes transferred.&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] Shuffling message(s) into proper queue(s)&lt;br /&gt;Sat 2012-03-17 03:26:38: [7708:766] Message received from www3.tiltedpixel.com [71.19.224.98] &lt;retpower com=""&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 948] {j:\localq\md000000.msg}&lt;br /&gt;&lt;br /&gt;Hopefully this one will get resolved shortly too.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/retpower&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/retpower&gt;&lt;/retpower&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/pKXZjy7pXWs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/8347409142470183440/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/03/l2apewsorg-false-positive-13.html#comment-form" title="34 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/8347409142470183440?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/8347409142470183440?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/pKXZjy7pXWs/l2apewsorg-false-positive-13.html" title="L2.APEWS.ORG False Positive #13" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>34</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/03/l2apewsorg-false-positive-13.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UHQHs-eip7ImA9WhVaEEU.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-31692758280197381</id><published>2012-03-16T21:08:00.003+01:00</published><updated>2012-06-07T17:00:31.552+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-07T17:00:31.552+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>Over 1 month without any FP</title><content type="html">As you can see, the last false positive that we found was on Feb 9 and nothing since. We are the only ones to have published email headers in support of those false positives and each one has been delisted by the APEWS.org Administrators. The folks you have seen posting removal requests here are people that believe that their IP addresses should not be listed. We have seen that most, but not all, have been delisted.&lt;br /&gt;&lt;br /&gt;The SPEWS listing model was to use whole CIDR blocks in order to pressure the ISP. It involved listing the entire block without regard for individual IP addresses and therefore there was collateral damage which was not favored by many. In order for that method to work it requires that users tolerate the collateral damage until such time as the ISP cleaned up the CIDR. That method was flawed because users, network Administrators etc, would rather tolerate spam than collateral damage.&lt;br /&gt;&lt;br /&gt;After analysing the APEWS.org data over a period of time we can see that they are no longer following the same model as SPEWS. A few years ago when they first became a replacement for SPEWS, it could have been said that their method was very close if not the same. However, the fact that false positives have reduced dramatically and having probed the listed CIDR, APEWS.org seem to be cutting holes in CIDR for trusted senders and accordingly reducing collateral damage leaving a binary reputation index.&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/LG8-Zm0ds4g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/31692758280197381/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/03/over-1-month-without-any-fp.html#comment-form" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/31692758280197381?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/31692758280197381?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/LG8-Zm0ds4g/over-1-month-without-any-fp.html" title="Over 1 month without any FP" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>8</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/03/over-1-month-without-any-fp.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcGRn0-eyp7ImA9WhRaE04.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-996610094486397841</id><published>2012-02-10T16:29:00.002+01:00</published><updated>2012-02-15T21:33:47.353+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-15T21:33:47.353+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #12</title><content type="html">This is another from the travel and tourism newsletters, not sure yet if the listing is tied to the recent "infomercials". We will check the listing, and delisting if it occurs, in due course. The email header follows;&lt;br /&gt;&lt;br /&gt;Thur 2012-02-09 16:47:29: [60:170] Accepting SMTP connection from [98.158.230.106]&lt;br /&gt;Thur 2012-02-09 16:47:29: [60:170] Looking up PTR record for 98.158.230.106 (106.230.158.98.IN-ADDR.ARPA)&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] D=106.230.158.98.IN-ADDR.ARPA TTL=(59) PTR=[business-travelupdate.com]&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] Gathering A-records for PTR hosts&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] D=business-travelupdate.com TTL=(1440) A=[98.158.230.106]&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Thur, 09 Feb 2012 16:47:30 -0500&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] &amp;lt;-- EHLO business-travelupdate.com&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] Performing reverse lookup on business-travelupdate.com (looking for 98.158.230.106)&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] D=business-travelupdate.com TTL=(1440) A=[98.158.230.106]&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] --&amp;gt; 250-xxx.xxx.xxx Hello business-travelupdate.com, pleased to meet you&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] --&amp;gt; 250-ETRN&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] --&amp;gt; 250-8BITMIME&lt;br /&gt;Thur 2012-02-09 16:47:30: [60:170] --&amp;gt; 250 SIZE 0&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] &amp;lt;-- MAIL FROM:&lt;news com=""&gt;&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] Performing reverse lookup on business-travelupdate.com (looking for 98.158.230.106)&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] D=business-travelupdate.com TTL=(1439) A=[98.158.230.106]&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] Spam Blocker A-record resolution of [106.230.158.98.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] Spam Blocker D=106.230.158.98.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] L2.APEWS.ORG LISTED&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] --&amp;gt; 250 &lt;news com=""&gt;, Sender ok&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] &amp;lt;-- DATA&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] --&amp;gt; 250 Ok, message saved &lt;message-id: 00="" com=""&gt;&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] &amp;lt;-- QUIT&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] SMTP session successful, 1453 bytes transferred.&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] Shuffling message(s) into proper queue(s)&lt;br /&gt;Thur 2012-02-09 16:47:31: [60:170] Message received from business-travelupdate.com [98.158.230.106] &lt;news com=""&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 1419] {j:\localq\500019.msg}&lt;br /&gt;&lt;br /&gt;You may see fluctuations in your statistics which could be due to the rotation between IP addresses that some newsletter senders do. Where one IP address is listed and another is not, the newsletter will alternate between the spam folder and the inbox unless you have the IP address in your whitelist and/or a filter to move mis-placed emails.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/news&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/news&gt;&lt;/news&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/dQD0L80o2uQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/996610094486397841/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/02/l2apewsorg-false-positive-12.html#comment-form" title="88 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/996610094486397841?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/996610094486397841?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/dQD0L80o2uQ/l2apewsorg-false-positive-12.html" title="L2.APEWS.ORG False Positive #12" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>88</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/02/l2apewsorg-false-positive-12.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcGRn0-fCp7ImA9WhRaE04.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-3419107699569527395</id><published>2012-01-28T22:38:00.000+01:00</published><updated>2012-02-15T21:33:47.354+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-15T21:33:47.354+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #11</title><content type="html">First one this month so far, not bad going. This is another of the sending servers for the travel industry, some of our users found this in their spam folder, incorrectly. It must have been recently listed, I haven't checked as yet what the listing says but as far as we are concerned here, the IP is a trusted source. Here is the email header;&lt;br /&gt;&lt;br /&gt;Fri 2012-01-27 16:33:25: [6810:112] Accepting SMTP connection from [205.201.136.59]&lt;br /&gt;Fri 2012-01-27 16:33:25: [6810:112] Looking up PTR record for 205.201.136.59 (59.136.201.205.IN-ADDR.ARPA)&lt;br /&gt;Fri 2012-01-27 16:33:25: [6810:112] D=59.136.201.205.in-addr.arpa TTL=(1440) PTR=[mail59.us4.mandrillapp.com]&lt;br /&gt;Fri 2012-01-27 16:33:25: [6810:112] Gathering A-records for PTR hosts&lt;br /&gt;Fri 2012-01-27 16:33:25: [6810:112] D=mail59.us4.mandrillapp.com TTL=(1440) A=[205.201.136.59]&lt;br /&gt;Fri 2012-01-27 16:33:25: [6810:112] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Fri, 27 Jan 2012 16:33:25 -0500&lt;br /&gt;Fri 2012-01-27 16:33:25: [6810:112] &amp;lt;-- EHLO mail59.us4.mandrillapp.com&lt;br /&gt;Fri 2012-01-27 16:33:25: [6810:112] Performing reverse lookup on mail59.us4.mandrillapp.com (looking for 205.201.136.59)&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] D=mail59.us4.mandrillapp.com TTL=(1440) A=[205.201.136.59]&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 250-xxx.xxx.xxx Hello mail59.us4.mandrillapp.com, pleased to meet you&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 250-ETRN&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 250-8BITMIME&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 250 SIZE 0&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] &amp;lt;-- MAIL FROM:&lt;bounce-???????@xxx.xxx@mail59.us4.mandrillapp.com&gt; BODY=8BITMIME&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] Performing reverse lookup on mail59.us4.mandrillapp.com (looking for 205.201.136.59)&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] D=mail59.us4.mandrillapp.com TTL=(1439) A=[205.201.136.59]&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] Spam Blocker A-record resolution of [59.136.201.205.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] Spam Blocker D=59.136.201.205.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] L2.APEWS.ORG LISTED&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 250 &lt;bounce-???????@xxx.xxx@mail59.us4.mandrillapp.com&gt;, Sender ok&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] &amp;lt;-- DATA&lt;br /&gt;Fri 2012-01-27 16:33:26: [6810:112] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Fri 2012-01-27 16:33:27: [6810:112] --&amp;gt; 250 Ok, message saved &lt;message-id: com=""&gt;&lt;br /&gt;Fri 2012-01-27 16:33:27: [6810:112] &amp;lt;-- QUIT&lt;br /&gt;Fri 2012-01-27 16:33:27: [6810:112] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Fri 2012-01-27 16:33:27: [6810:112] SMTP session successful, 30303 bytes transferred.&lt;br /&gt;Fri 2012-01-27 16:33:27: [6810:112] Shuffling message(s) into proper queue(s)&lt;br /&gt;Fri 2012-01-27 16:33:27: [6810:112] Message received from mail59.us4.mandrillapp.com [205.201.136.59] &lt;bounce-???????@xxx.xxx@mail59.us4.mandrillapp.com&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 32292] {j:\localq\0005140404.msg}&lt;br /&gt;&lt;br /&gt;We will check this and report back in due course.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/bounce-???????@xxx.xxx@mail59.us4.mandrillapp.com&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/bounce-???????@xxx.xxx@mail59.us4.mandrillapp.com&gt;&lt;/bounce-???????@xxx.xxx@mail59.us4.mandrillapp.com&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/72Fs8gBjaFw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/3419107699569527395/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2012/01/l2apewsorg-false-positive-11.html#comment-form" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/3419107699569527395?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/3419107699569527395?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/72Fs8gBjaFw/l2apewsorg-false-positive-11.html" title="L2.APEWS.ORG False Positive #11" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>8</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2012/01/l2apewsorg-false-positive-11.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcGRn0-fCp7ImA9WhRaE04.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-8241252291511121397</id><published>2011-12-25T23:17:00.002+01:00</published><updated>2012-02-15T21:33:47.354+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-15T21:33:47.354+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #10</title><content type="html">Just over a week since the last one, found this which is the tenth in as many weeks, not bad. We know that the email sent by the server was solicited as it was a response to a web purchase, i.e. server generated receipt;&lt;br /&gt;&lt;br /&gt;Sat 2011-12-24 06:53:43: [916:2344] Accepting SMTP connection from [83.223.106.9]&lt;br /&gt;Sat 2011-12-24 06:53:43: [916:2344] Looking up PTR record for 83.223.106.9 (9.106.223.83.IN-ADDR.ARPA)&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] D=9.106.223.83.IN-ADDR.ARPA TTL=(1440) PTR=[fusion.bpweb.net]&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] Gathering A-records for PTR hosts&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] D=fusion.bpweb.net TTL=(120) A=[83.223.106.9]&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Sun, 25 Dec 2011 06:53:44 -0500&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] &amp;lt;-- EHLO fusion.bpweb.net&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] Performing reverse lookup on fusion.bpweb.net (looking for 83.223.106.9)&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] D=fusion.bpweb.net TTL=(120) A=[83.223.106.9]&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] --&amp;gt; 250-xxx.xxx.xxx Hello fusion.bpweb.net, pleased to meet you&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] --&amp;gt; 250-ETRN&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] --&amp;gt; 250-8BITMIME&lt;br /&gt;Sat 2011-12-24 06:53:44: [916:2344] --&amp;gt; 250 SIZE 0&lt;br /&gt;Sat 2011-12-24 06:53:45: [916:2344] &amp;lt;-- MAIL From:&lt;noreply uk=""&gt; SIZE=112236&lt;br /&gt;Sat 2011-12-24 06:53:45: [916:2344] Performing reverse lookup on londonmagicstore.co.uk (looking for 83.223.106.9)&lt;br /&gt;Sat 2011-12-24 06:53:45: [916:2344] D=londonmagicstore.co.uk TTL=(119) A=[87.117.239.236]&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] P=050 D=londonmagicstore.co.uk TTL=(120) MX=[aspmx3.googlemail.com] {74.125.127.27}&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] P=040 D=londonmagicstore.co.uk TTL=(120) MX=[aspmx2.googlemail.com] {74.125.43.27}&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] P=030 D=londonmagicstore.co.uk TTL=(120) MX=[alt2.aspmx.l.google.com]&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] P=020 D=londonmagicstore.co.uk TTL=(120) MX=[alt1.aspmx.l.google.com]&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] P=010 D=londonmagicstore.co.uk TTL=(120) MX=[aspmx.l.google.com]&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] D=alt2.aspmx.l.google.com TTL=(4) A=[74.125.65.26]&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] D=alt1.aspmx.l.google.com TTL=(4) A=[209.85.225.26]&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] D=aspmx.l.google.com TTL=(4) A=[74.125.127.26]&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] Spam Blocker A-record resolution of [9.106.223.83.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] Spam Blocker D=9.106.223.83.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] L2.APEWS.ORG LISTED&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] --&amp;gt; 250 &lt;noreply uk=""&gt;, Sender ok&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] &amp;lt;-- RCPT To:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Sat 2011-12-24 06:53:46: [916:2344] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Sat 2011-12-24 06:53:47: [916:2344] &amp;lt;-- DATA&lt;br /&gt;Sat 2011-12-24 06:53:47: [916:2344] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Sat 2011-12-24 06:53:49: [916:2344] --&amp;gt; 250 Ok, message saved &lt;message-id: 14767=""&gt;&lt;br /&gt;Sat 2011-12-24 06:53:49: [916:2344] &amp;lt;-- QUIT&lt;br /&gt;Sat 2011-12-24 06:53:49: [916:2344] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Sat 2011-12-24 06:53:49: [916:2344] SMTP session successful, 113812 bytes transferred.&lt;br /&gt;Sat 2011-12-24 06:53:49: [916:2344] Shuffling message(s) into proper queue(s)&lt;br /&gt;Sat 2011-12-24 06:53:49: [916:2344] Message received from fusion.bpweb.net [83.223.106.9] &lt;noreply uk=""&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 113801] {j:\localq\md0000000.msg}&lt;br /&gt;&lt;br /&gt;As before, we will report back if this gets de-listed.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/noreply&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/noreply&gt;&lt;/noreply&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/KIhjUkRxOAM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/8241252291511121397/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-10.html#comment-form" title="11 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/8241252291511121397?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/8241252291511121397?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/KIhjUkRxOAM/l2apewsorg-false-positive-10.html" title="L2.APEWS.ORG False Positive #10" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>11</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-10.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoyfCp7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-5596853226617780835</id><published>2011-12-24T21:01:00.002+01:00</published><updated>2011-12-24T21:30:29.494+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.494+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>Comparison of some DNSBL results</title><content type="html">No false positives to report this week, great because email was up to nearly double with all the Xmas communications including contacts so nice that it went smoothly. Use the spare time to put some usage statistics together;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 9"&gt;&lt;meta name="Originator" content="Microsoft Word 9"&gt;&lt;link rel="File-List" href="file:///C:/Users/Phil/AppData/Local/Temp/msoclip1/02/clip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:donotoptimizeforbrowser/&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */ @font-face  {font-family:"Arial Unicode MS";  panose-1:2 11 6 4 2 2 2 2 2 4;  mso-font-charset:128;  mso-generic-font-family:swiss;  mso-font-pitch:variable;  mso-font-signature:-1 -369098753 63 0 4129023 0;} @font-face  {font-family:"\@Arial Unicode MS";  panose-1:2 11 6 4 2 2 2 2 2 4;  mso-font-charset:128;  mso-generic-font-family:swiss;  mso-font-pitch:variable;  mso-font-signature:-1 -369098753 63 0 4129023 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin:0in;  margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-fareast-font-family:"Times New Roman";} @page Section1  {size:8.5in 11.0in;  margin:1.0in 1.25in 1.0in 1.25in;  mso-header-margin:.5in;  mso-footer-margin:.5in;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt; &lt;/style&gt;  &lt;table style="width: 228pt; border-collapse: collapse;" border="0" cellpadding="0" cellspacing="0" width="304"&gt;  &lt;tbody&gt;&lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border: 0.5pt solid windowtext; padding: 0.75pt 0.75pt 0in; width: 143pt; height: 15.75pt;" valign="bottom" width="191" nowrap="nowrap"&gt;&lt;div style="text-align: center;"&gt;   &lt;/div&gt;&lt;p style="text-align: center;" class="MsoNormal"&gt;DNSBL&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; border-width: 0.5pt 0.5pt 0.5pt medium; padding: 0.75pt 0.75pt 0in; width: 43pt; height: 15.75pt;" valign="bottom" width="57" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; border-width: 0.5pt 0.5pt 0.5pt medium; padding: 0.75pt 0.75pt 0in; width: 42pt; height: 15.75pt;" valign="bottom" width="56" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;Errors&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;l2.apews.org&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="94.6" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;95 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;0.5%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;b.barracudacentral.org&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="93.6" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;94 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;* uceprotect.net 1,2 &amp;amp; 3&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="91.3" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;91 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.2%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;zen.spamhaus.org&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="90.57" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;91 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;ip.v4bl.org&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="67.81" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;68 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;cbl.abuseat.org&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="67.8" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;68 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;spam.dnsbl.sorbs.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="65.1" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;65 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;dnsbl-2.uceprotect.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="62.9" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;63 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;dnsbl-3.uceprotect.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="62.7" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;63 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.2%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;hostkarma.junkemailfilter.com&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="62.35" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;62 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;bl.tiopan.com&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="60.95" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;61 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;dnsbl-1.uceprotect.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="51.3" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;51 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;bl.mailspike.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="44.69" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;45 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;ix.dnsbl.manitu.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="44.2" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;44 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;1.5&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;truncate.gbudb.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="43.1" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;43 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;bl.spameatingmonkey.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="38.25" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;38 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;blackholes.five-ten-sg.com&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="37.02" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;37 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;bl.spamcop.net&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="30.5" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;31 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;psbl.surriel.com&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="18.4" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;18 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;db.upbl.info&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="14" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;14 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;dnsbl.imps.de&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="8.16" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;8 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;no-more-funn.moensted.dk&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="7.4" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;7 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid; border-color: -moz-use-text-color windowtext; border-width: medium 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;bl.spamcannibal.org&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="2.98" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;3 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid none none; border-color: -moz-use-text-color windowtext -moz-use-text-color -moz-use-text-color; border-width: medium 0.5pt medium medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 0.5pt 0.5pt; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;spam.spamrats.com&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 0.5pt 0.5pt medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" num="1.7" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;2 &lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 0.5pt 0.5pt medium; padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&amp;lt;0.1%&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15.75pt;"&gt;   &lt;td colspan="3" style="padding: 0.75pt 0.75pt 0in; height: 15.75pt;" valign="bottom" nowrap="nowrap"&gt;   &lt;p class="MsoNormal"&gt;* does not exist as a single dnsbl, use 3 lists&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt; &lt;br /&gt;That accords with our findings too, very respectable error rates before the use of a whitelist. Only Barracuda's system comes close and they require a free registration before you can access their data. You can use a combined result from all 3 lists at UCEProtect.net to achieve similar results though they do have lower error rates.&lt;br /&gt;&lt;br /&gt;There are websites that offer a one-stop lookup service, like dnsbl.info, where you can input an IP address and see which blacklists have it listed. In their case, dnsbl.info test 80+ blacklists but do not include l2.apews.org which seems odd when you see the results above. Yet they show the results from other blacklists with more than double the error rate, odd that.&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/TPGoqLX-1yM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/5596853226617780835/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/comparison-of-some-dnsbl-results.html#comment-form" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/5596853226617780835?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/5596853226617780835?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/TPGoqLX-1yM/comparison-of-some-dnsbl-results.html" title="Comparison of some DNSBL results" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>8</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/comparison-of-some-dnsbl-results.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoyfSp7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-1792608195750027544</id><published>2011-12-19T16:44:00.002+01:00</published><updated>2011-12-24T21:30:29.495+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.495+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>Antihosts.exe trojan</title><content type="html">Ended up having to fix a client computer over the weekend, Windows 7 with a failed Messenger and Windows Live problems. The trojan had replaced the "hosts" file and replaced it with this version;&lt;br /&gt;&lt;br /&gt;191.164.12.1 zuleica&lt;br /&gt;191.162.91.2 tarantula&lt;br /&gt;19.251.32.13 ariranha&lt;br /&gt;112.158.12.22 leandrino&lt;br /&gt;132.168.7.42 zecurlano&lt;br /&gt;121.91.41.151 cotidiano&lt;br /&gt;&lt;br /&gt;121.15.12.137 www.banespa.com.br # GbPluguin&lt;br /&gt;121.15.12.137 banespa.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.santander.com.br # GbPluguin&lt;br /&gt;121.15.12.137 santander.com.br # GbPluguin&lt;br /&gt;121.15.12.137 caixa.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.cef.gov.br # GbPluguin&lt;br /&gt;121.15.12.137 cef.gov.br # GbPluguin&lt;br /&gt;121.15.12.137 www.cef.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.caixa.gov.br # GbPluguin&lt;br /&gt;121.15.12.137 caixa.gov.br # GbPluguin&lt;br /&gt;121.15.12.137 www.caixa.com.br # GbPluguin&lt;br /&gt;209.94.172.28 live.com  # GbPluguin&lt;br /&gt;209.94.172.28 www.live.com  # GbPluguin&lt;br /&gt;209.94.172.28 www.msn.com  # GbPluguin&lt;br /&gt;121.15.12.137 cef.com.br # GbPluguin&lt;br /&gt;121.15.12.137 internetbanking.caixa.gov.br # GbPluguin&lt;br /&gt;121.15.12.137 internetbanking.caixa.com.br # GbPluguin&lt;br /&gt;121.15.12.137 internetbanking.cef.gov.br # GbPluguin&lt;br /&gt;121.15.12.137 internetbanking.cef.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.e-gold.com.br # GbPluguin&lt;br /&gt;121.15.12.137 e-gold.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.e-gold.com # GbPluguin&lt;br /&gt;121.15.12.137 e-gold.com # GbPluguin&lt;br /&gt;121.15.12.137 www.bradescoprime.com.br  # GbPluguin&lt;br /&gt;121.15.12.137 www.cetelem.com.br # GbPluguin&lt;br /&gt;121.15.12.137 cetelem.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.cartaoaura.com.br # GbPluguin&lt;br /&gt;209.94.172.28 msn.com  # GbPluguin&lt;br /&gt;209.94.172.28 www.msn.com.br  # GbPluguin&lt;br /&gt;209.94.172.28 login.live.com  # GbPluguin&lt;br /&gt;121.15.12.137 cartaoaura.com.br # GbPluguin&lt;br /&gt;121.15.12.137 bradescoprime.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.itaupersonnalite.com.br  # GbPluguin&lt;br /&gt;121.15.12.137 itaupersonnalite.com.br # GbPluguin&lt;br /&gt;121.15.12.137 americanexpress.com.br  # GbPluguin&lt;br /&gt;121.15.12.137 www.sicredi.com.br # GbPluguin&lt;br /&gt;121.15.12.137 sicredi.com.br # GbPluguin&lt;br /&gt;121.15.12.137 portal.sicredi.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.realsecureweb.com.br # GbPluguin&lt;br /&gt;121.15.12.137 realsecureweb.com.br # GbPluguin&lt;br /&gt;209.94.172.28 www.hotmail.com  # GbPluguin&lt;br /&gt;209.94.172.28 hotmail.com  # GbPluguin&lt;br /&gt;121.15.12.137 www.americanexpress.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.americanexpress.com # GbPluguin&lt;br /&gt;121.15.12.137 www.real.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.bancoreal.com.br # GbPluguin&lt;br /&gt;121.15.12.137 real.com.br # GbPluguin&lt;br /&gt;121.15.12.137 bancoreal.com.br # GbPluguin&lt;br /&gt;209.94.172.28 www.hotmail.com.br  # GbPluguin&lt;br /&gt;209.94.172.28 hotmail.com.br  # GbPluguin&lt;br /&gt;121.15.12.137 itau.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.itau.com # GbPluguin&lt;br /&gt;121.15.12.137 itau.com # GbPluguin&lt;br /&gt;121.15.12.137 imagem.caixa.gov.br # GbPluguin&lt;br /&gt;121.15.12.137 imagem.caixa.com.br # GbPluguin&lt;br /&gt;121.15.12.137 imagem.cef.gov.br # GbPluguin&lt;br /&gt;121.15.12.137 imagem.cef.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.bradesco.com.br # GbPluguin&lt;br /&gt;121.15.12.137 bradesco.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.bradesco.com # GbPluguin&lt;br /&gt;121.15.12.137 bradesco.com # GbPluguin&lt;br /&gt;121.15.12.137 www.itau.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.realsecureweb.com.br # GbPluguin&lt;br /&gt;121.15.12.137 santanderempresarial.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.santanderempresarial.com.br # GbPluguin&lt;br /&gt;121.15.12.137 santanderempresarial.com # GbPluguin&lt;br /&gt;121.15.12.137 www.santanderempresarial.com # GbPluguin&lt;br /&gt;121.15.12.137 www.citibank.com.br # GbPluguin&lt;br /&gt;121.15.12.137 citibank.com.br # GbPluguin&lt;br /&gt;121.15.12.137 www.citibank.com # GbPluguin&lt;br /&gt;121.15.12.137 citibank.com # GbPluguin&lt;br /&gt;&lt;br /&gt;32.19.12.1 ezekien.lorena&lt;br /&gt;22.93.11.98 marcos.gladiador&lt;br /&gt;11.12.44.1 zumbi.palmares&lt;br /&gt;81.55.12.4 arthur.erculando&lt;br /&gt;&lt;br /&gt;Interesting that some USA Department Of Defense IP addresses are referred to as is a Ford Motor Company one too. The others are in South Korea, France, Australia and China. The trojan is capturing user names and passwords for the above mentioned banks etc.&lt;br /&gt;&lt;br /&gt;The infection arrived in a spam email from a known-to-the-user Hotmail email address, probably a compromised account, with a link to a video about pedofilia. Clicking the link caused the trojan to install and make various changes including the above hosts file replacement.&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/gx-EAQ9Qin4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/1792608195750027544/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/antihostsexe-trojan.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/1792608195750027544?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/1792608195750027544?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/gx-EAQ9Qin4/antihostsexe-trojan.html" title="Antihosts.exe trojan" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/antihostsexe-trojan.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoyfSp7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-2792426463587705487</id><published>2011-12-19T16:38:00.002+01:00</published><updated>2011-12-24T21:30:29.495+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.495+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>Spammers ignore 550 command</title><content type="html">Having written about the effectiveness for blocking, we have a spammer that is still trying to send emails to the same email address, on a different server and after a failed previous attempt where a 550 no suvh user was given;&lt;br /&gt;&lt;br /&gt;Sat 2011-12-17 05:43:06: [468:256] Accepting SMTP connection from [67.159.33.100]&lt;br /&gt;Sat 2011-12-17 05:43:06: [468:256] Looking up PTR record for 67.159.33.100 (100.33.159.67.IN-ADDR.ARPA)&lt;br /&gt;Sat 2011-12-17 05:43:21: [468:256] The name server reports that it is having technical problems.&lt;br /&gt;Sat 2011-12-17 05:43:21: [468:256] --&amp;gt; 220 xxx1.xxx.xxx ESMTP MDaemon 6.7.9; Sat, 17 Dec 2011 04:43:21 -0500&lt;br /&gt;Sat 2011-12-17 05:43:21: [468:256] &amp;lt;-- EHLO super.jbcapacitacionempresarial.com&lt;br /&gt;Sat 2011-12-17 05:43:21: [468:256] Performing reverse lookup on super.jbcapacitacionempresarial.com (looking for 67.159.33.100)&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] D=super.jbcapacitacionempresarial.com TTL=(240) A=[67.159.33.100]&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] --&amp;gt; 250-xxx1.xxx.xxx Hello super.jbcapacitacionempresarial.com, pleased to meet you&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] --&amp;gt; 250-ETRN&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] --&amp;gt; 250-8BITMIME&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] --&amp;gt; 250 SIZE 0&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] &amp;lt;-- MAIL FROM:&lt;bouncer com=""&gt; SIZE=48915&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] Performing reverse lookup on jbcapacitacionempresarial.com (looking for 67.159.33.100)&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] D=jbcapacitacionempresarial.com TTL=(240) A=[67.159.33.101]&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] P=010 D=jbcapacitacionempresarial.com TTL=(240) MX=[mail.jbcapacitacionempresarial.com] {67.159.33.101}&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] Spam Blocker A-record resolution of [100.33.159.67.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.3)...&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] Spam Blocker D=100.33.159.67.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] L2.APEWS.ORG LISTED&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] --&amp;gt; 250 &lt;bouncer com=""&gt;, Sender ok&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] 'Recipient unknown' given to divert future spam&lt;br /&gt;Sat 2011-12-17 05:43:22: [468:256] --&amp;gt; 550 &lt;xxx@xxx.xxx&gt;, Recipient unknown&lt;br /&gt;Sat 2011-12-17 05:43:23: [468:256] &amp;lt;-- QUIT&lt;br /&gt;Sat 2011-12-17 05:43:23: [468:256] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Sat 2011-12-17 05:43:23: [468:256] SMTP session successful, 154 bytes transferred.&lt;br /&gt;&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/bouncer&gt;&lt;/bouncer&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/StHIHNzvDXk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/2792426463587705487/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/spammers-ignore-550-command.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/2792426463587705487?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/2792426463587705487?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/StHIHNzvDXk/spammers-ignore-550-command.html" title="Spammers ignore 550 command" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/spammers-ignore-550-command.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoyfip7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-41732099950486632</id><published>2011-12-13T04:15:00.002+01:00</published><updated>2011-12-24T21:30:29.496+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.496+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #9</title><content type="html">For those that are receiving the newsletters from the folks doing the dolphin watch documentary etc, Ocean Preservation Society, this latest false positive would have been serious. OPS have used CreateSend.com for their newsletter and the subscriber user on our network found it in the spam folder. Shame, lets hope that like with the previous ones, putting it here gets the server IP delisted;&lt;br /&gt;&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Accepting SMTP connection from [184.106.86.136]&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Looking up PTR record for 184.106.86.136 (136.86.106.184.IN-ADDR.ARPA)&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] D=136.86.106.184.IN-ADDR.ARPA TTL=(5) PTR=[mr136.createsend.com]&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Gathering A-records for PTR hosts&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] D=mr136.createsend.com TTL=(120) A=[184.106.86.136]&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Sat, 10 Dec 2011 15:07:33 -0500&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] &amp;lt;-- EHLO mr136.createsend.com&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Performing reverse lookup on mr136.createsend.com (looking for 184.106.86.136)&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] D=mr136.createsend.com TTL=(119) A=[184.106.86.136]&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250-xxx.xxx.xxx Hello mr136.createsend.com, pleased to meet you&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250-ETRN&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250-8BITMIME&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250 SIZE 0&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] &amp;lt;-- MAIL FROM:&lt;oceanicpreservationsociety-iyidlyk1mkttttrhu1r com=""&gt; BODY=8BITMIME&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Performing reverse lookup on createsend3.com (looking for 184.106.86.136)&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] D=createsend3.com TTL=(720) A=[27.126.145.32]&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] P=010 D=createsend3.com TTL=(240) MX=[mx1.createsend3.com] {27.126.144.2}&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Spam Blocker A-record resolution of [136.86.106.184.l2.apews.org] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Spam Blocker D=136.86.106.184.l2.apews.org TTL=(35) A=[127.0.0.2]&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] APEWS listed, 99.7% certain it is spam&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250 &lt;oceanicpreservationsociety-iyidlyk1mkttttrhu1r com=""&gt;, Sender ok&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] &amp;lt;-- DATA&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 250 Ok, message saved &lt;message-id: r="" com=""&gt;&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] &amp;lt;-- QUIT&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] SMTP session successful, 26599 bytes transferred.&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Shuffling message(s) into proper queue(s)&lt;br /&gt;Sat 2011-12-10 15:07:33: [968:7309] Message received from mr136.createsend.com [184.106.86.136] &lt;oceanicpreservationsociety-iyidlyk1mkttttrhu1r com=""&gt;with SMTP for &lt;xxx@xxx.xxx&gt; [Size 26584] {j:\localq\md00000000.msg}&lt;br /&gt;&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/oceanicpreservationsociety-iyidlyk1mkttttrhu1r&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/oceanicpreservationsociety-iyidlyk1mkttttrhu1r&gt;&lt;/oceanicpreservationsociety-iyidlyk1mkttttrhu1r&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/e557rjCBKN4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/41732099950486632/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-9.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/41732099950486632?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/41732099950486632?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/e557rjCBKN4/l2apewsorg-false-positive-9.html" title="L2.APEWS.ORG False Positive #9" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>5</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-9.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoyfip7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-6826167228316412847</id><published>2011-12-10T19:30:00.002+01:00</published><updated>2011-12-24T21:30:29.496+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.496+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>Whois utility SamSpade</title><content type="html">Do you often get IP addresses connecting to your email server and you wonder who the **** is that? The answer is that there is a "Whois" of that information, and for Windows users there is a small well-written program that is very helpful. A visit to SamSpage.org shows "back soon" but the program can still be found for download at;&lt;br /&gt;&lt;br /&gt;http://majorgeeks.com/Sam_Spade_d594.html&lt;br /&gt;&lt;br /&gt;At just over a Mb it certainly isn't bloated with anything! Once installed it can be opened to reveal a simpe gray window. Put the unknown IP address in the top left box, for this example we will use the spammer just referred to, at 67.159.33.100;&lt;br /&gt;&lt;br /&gt;The main registers for IP address ranges are;&lt;br /&gt;ARIN, North American continent&lt;br /&gt;RIPE, European continent and Middle East&lt;br /&gt;LACNIC, Central and South America&lt;br /&gt;APNIC, Asia, Pacific, Far East and Oceana&lt;br /&gt;AFRINIC, Africa&lt;br /&gt;&lt;br /&gt;Top center of SamSpade you will see a choice box, select whois.arin.net and then look to the left, down a little you will see an icon for "whois". Click on that and you get the following in your SamSpade window;&lt;br /&gt;&lt;br /&gt;NetRange: 67.159.0.0 - 67.159.63.255&lt;br /&gt;CIDR: 67.159.0.0/18&lt;br /&gt;OriginAS:&lt;br /&gt;NetName: FDCSERVERS&lt;br /&gt;NetHandle: NET-67-159-0-0-1&lt;br /&gt;Parent: NET-67-0-0-0-0&lt;br /&gt;NetType: Direct Allocation&lt;br /&gt;RegDate: 2004-10-12&lt;br /&gt;Updated: 2006-12-27&lt;br /&gt;&lt;br /&gt;OrgName: FDCservers.net&lt;br /&gt;OrgId: FDCSE&lt;br /&gt;Address: 141 w jackson blvd.&lt;br /&gt;Address: suite #1135&lt;br /&gt;City: Chicago&lt;br /&gt;StateProv: IL&lt;br /&gt;PostalCode: 60604&lt;br /&gt;Country: US&lt;br /&gt;RegDate: 2003-05-20&lt;br /&gt;Updated: 2011-03-28&lt;br /&gt;&lt;br /&gt;In our experience FDCServers do not have a good reputation and quite often have their IP addresses listed in the top 100 spam senders at any one time. Probably not too caring about the spam problem.&lt;br /&gt;&lt;br /&gt;Another test that you can perform is from the top toolbar, the button called "Basics". Click on that and second one down on the list is NSLOOKUP, a test for finding the DNS name recorded for the IP address or domain name. For 67.159.33.100 we get the following result;&lt;br /&gt;&lt;br /&gt;"nslookup 67.159.33.100&lt;br /&gt;No reverse DNS (WSANO_DATA)"&lt;br /&gt;&lt;br /&gt;Very impressive, there isn't one. FDCServers have an IP address pumping out emails with no reverse DNS set. The spammer therefore can set the HELO/EHLO server name to what ever he likes and change it whenever he likes. FDC should write the server name in their DNS and setup the PTR record so that it accords with the A record, therefore permitting real-time reverse DNS (rDNS) tests to succeed. You will note that our email server timed out trying to get that IP address DNS record. Failing to do so is open to abuse as we have seen, yet it is so easy to do, it literally takes 5 minutes to edit the DNS and only needs doing once.&lt;br /&gt;&lt;br /&gt;Email servers can send emails for and on behalf of numerous domain names and this does not affect the name of the server in DNS, it's reverse DNS record or the HELO/EHLO used.&lt;br /&gt;&lt;br /&gt;To get another opinion about IP addresses, networks, network providerss and server hosting businesses, try the following;&lt;br /&gt;&lt;br /&gt;http://www.senderbase.org/&lt;br /&gt;&lt;br /&gt;Over on the right of the home page you will see a box for "reputation lookup", insert 67.159.33.100 and click the button underneath. The window shows results for the IP address and associated email senders of the same domain name and IP addresses (in this case 67.159.33.0/24). Note the results;&lt;br /&gt;&lt;br /&gt;67.159.33.33 is shown as "neutral" written in black text&lt;br /&gt;67.159.33.100 is shown as "neutral" written in black text&lt;br /&gt;67.159.33.101 is shown as "good" written in &lt;span style="color: rgb(51, 255, 51);"&gt;green&lt;/span&gt; text but&lt;br /&gt;67.159.33.100 is shown as "poor" written in &lt;span style="color: rgb(255, 0, 0);"&gt;red&lt;/span&gt; text&lt;br /&gt;&lt;br /&gt;Now change the address block to be /18 as the Whois tells us, FDCServers have an IP address block of that size, click "Go";&lt;br /&gt;&lt;br /&gt;At the time of writing there are nearly 400 detected email senders from that /18 IP block and there is a lot of &lt;span style="color: rgb(255, 0, 0);"&gt;red&lt;/span&gt;! This second opinion of FDC agrees with our own experience.&lt;br /&gt;&lt;br /&gt;Top center of the SenderBase.org web page is a button called "Top Senders", choose "Top Spam Senders" to see a recent report and the same old names.&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/vYV1261JAs4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/6826167228316412847/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/whois-utility-samspade.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/6826167228316412847?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/6826167228316412847?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/vYV1261JAs4/whois-utility-samspade.html" title="Whois utility SamSpade" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/whois-utility-samspade.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoyfip7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-8612226596914276923</id><published>2011-12-10T17:39:00.002+01:00</published><updated>2011-12-24T21:30:29.496+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.496+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG for blocking works great</title><content type="html">We've seen a lot of comments on the internet, especially in Usenet net-abuse newsgroups, that Apews.org has no users, false positives are huge and that it is unfit for outright blocking. Alterior motives? Who are these people and why aren't they in here filling up the pages with their tons of test results?&lt;br /&gt;&lt;br /&gt;We have been showing all the false positives that we receive on some commercial email servers that receive global email flows. The average FP rate is going to be about one, yes one, email per week! None of them were critical, more inconvenient than anything and in a couple of cases, they were possible FP only that were actually correct in identifying spam.&lt;br /&gt;&lt;br /&gt;Are email server Administrators so lazy or incapable that they can't sort out one email a week for a user? And why can't they run a whitelist, I mean, no sane email Administrator would run an email server without one, right?&lt;br /&gt;&lt;br /&gt;Here is evidence of a spammer having delivery denied, and you are going to ask how do I know it was spam if delivery was denied? Well, we have setup secondary and tertiary MX servers operating the exact same configuration as the primary servers but with blocking in place, not insert an X-Header for listed IP addresses of senders. The spammer delivered a copy of the same spam to an alternate server and was blocked from delivering on another server, so in that way we were able to see and check the spam to confirm.&lt;br /&gt;&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] Accepting SMTP connection from [67.159.33.100]&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] Looking up PTR record for 67.159.33.100 (100.33.159.67.IN-ADDR.ARPA)&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] 3 second wait for DNS response exceeded&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Sat, 10 Dec 2011 4:29:07 -0200&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] &amp;lt;-- EHLO super.jbcapacitacionempresarial.com&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] Performing reverse lookup on super.jbcapacitacionempresarial.com (looking for 67.159.33.100)&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] D=super.jbcapacitacionempresarial.com TTL=(240) A=[67.159.33.100]&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 250-xxx.xxx.xxx Hello super.jbcapacitacionempresarial.com, pleased to meet you&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 250-ETRN&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 250-8BITMIME&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 250 SIZE 0&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] &amp;lt;-- MAIL FROM:&lt;bouncer com=""&gt; SIZE=38288&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] Performing reverse lookup on jbcapacitacionempresarial.com (looking for 67.159.33.100)&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] D=jbcapacitacionempresarial.com TTL=(240) A=[67.159.33.101]&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] P=010 D=jbcapacitacionempresarial.com TTL=(240) MX=[mail.jbcapacitacionempresarial.com] {67.159.33.101}&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] Spam Blocker A-record resolution of [100.33.159.67.l2.apews.org] in progress (DNS Server: 192.168.1.1)...&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] Spam Blocker D=100.33.159.67.l2.apews.org TTL=(35) A=[127.0.0.2]&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] APEWS.ORG listed, 99.7% certain it is spam&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 250 &lt;bouncer com=""&gt;, Sender ok&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] 'Recipient unknown' given to divert future spam&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 550 &lt;xxx@xxx.xxx&gt;, Recipient unknown&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] &amp;lt;-- QUIT&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Sat 2011-12-10 4:29:07: [1234:787] SMTP session successful, 154 bytes transferred.&lt;br /&gt;&lt;br /&gt;The spammer was given a "550" user unknown reply and that should get the email address removed from the sender's database however, these days 550 get ignored and spammers keep trying to deliver to all email servers that they can get access to.&lt;br /&gt;&lt;br /&gt;Email servers that send solicited emails do so by checking their cache or public DNS to find where to deliver an email. They try the first MX listed and only try the second or third if delivery was not possible and the retry period exhausted depending on the configuration chosen by the email Administrator of that server. Outbound email servers are typically not listed in DNS as MX i.e. senders and so even though they listen on TCP port 25, they should never receive emails.&lt;br /&gt;&lt;br /&gt;Even domain delivery receipts and recipient display or read receipts use the same MX servers in the order of priority MX1, MX2, MX3 etc as configured in DNS by the Administrator for each domain name. Spammers ignore that and just send to all and any servers listening on TCP port 25. L2.Apews.org is therefore excellent for use in blocking and denying delivery on such servers if not other MX servers depending on the ability of the email Administrator.&lt;br /&gt;&lt;br /&gt;Look again at the false positives that we have listed here, had we been blocking from day 1 then each of these would not have been allowed delivery into the network. See anything mission critical there? With a decent whitelist those FP would have been even fewer or zero. Why pay for a spam solution? Surely anyone making money out of spam solutions is part of the problem, they wouldn't want to give up their income. Needless to say, good email Administrators are worth their weight in gold, better to pay them than pay for anti-spam services or "solutions".&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/bouncer&gt;&lt;/bouncer&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/xhe-qs27zYI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/8612226596914276923/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/l2apewsorg-for-blocking-works-great.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/8612226596914276923?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/8612226596914276923?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/xhe-qs27zYI/l2apewsorg-for-blocking-works-great.html" title="L2.APEWS.ORG for blocking works great" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/l2apewsorg-for-blocking-works-great.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoyfyp7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-5224843548911173163</id><published>2011-12-10T17:28:00.003+01:00</published><updated>2011-12-24T21:30:29.497+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.497+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #8</title><content type="html">This one refers back to L2.APEWS.ORG False Positive #4, if you recall the MTV newsletter was found by our user in his spam folder. Having published that here and checking the IP address a day or two later, it was found to be delisted, so then why is another MTV newsletter again in the spam folder? Well, the MTV newsletter didn't come from the same IP address which means that Apews.org had more than one IP address listed in the previous listing. Here is the false positive;&lt;br /&gt;&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] Accepting SMTP connection from [129.228.5.20]&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Thu, 08 Dec 2011 08:10:27 -0500&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] &amp;lt;-- EHLO mtv-newsletter1.mms.mtv.com&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 250-xxx.xxx.xxx Hello mtv-newsletter1.mms.mtv.com, pleased to meet you&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 250-ETRN&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 250-8BITMIME&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 250 SIZE 0&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] &amp;lt;-- MAIL FROM:&lt;bounce com=""&gt;&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] Spam Blocker A-record resolution of [20.5.228.129.l2.apews.org] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] Spam Blocker D=20.5.228.129.l2.apews.org TTL=(35) A=[127.0.0.2]&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] APEWS listed, 99.7% certain it is spam&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 250 &lt;bounce com=""&gt;, Sender ok&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] &amp;lt;-- DATA&lt;br /&gt;Thu 2011-12-08 08:10:27: [1112:6566] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Thu 2011-12-08 08:10:28: [1112:6566] --&amp;gt; 250 Ok, message saved &lt;message-id: 1297931="" com=""&gt;&lt;br /&gt;Thu 2011-12-08 08:10:28: [1112:6566] &amp;lt;-- QUIT&lt;br /&gt;Thu 2011-12-08 08:10:28: [1112:6566] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Thu 2011-12-08 08:10:28: [1112:6566] SMTP session successful, 20649 bytes transferred.&lt;br /&gt;Thu 2011-12-08 08:10:28: [1112:6566] Shuffling message(s) into proper queue(s)&lt;br /&gt;Thu 2011-12-08 08:10:28: [1112:6566] Message received from mtv-newsletter1.mms.mtv.com [129.228.5.20] &lt;bounce com=""&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 20634] {j:\localq\md00000.msg}&lt;br /&gt;&lt;br /&gt;After some further checking, it turns out that MTV have 4 consecutive IP addresses in Viacom address space, namely 129.228.5.20-129.228.5.23 so you might want to whitelist those. We have never had any problem with the MTV servers, check e.g. whitelist DNSWL.org for other trustworthy IP addresses in the same neighborhood as those.&lt;br /&gt;&lt;br /&gt;At the time of writing this, none of those 4 IP addresses are showing as listed so it seems that Apews.org have corrected the MTV newsletter issue.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/bounce&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/bounce&gt;&lt;/bounce&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/nV0pGfVW1gA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/5224843548911173163/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-8.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/5224843548911173163?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/5224843548911173163?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/nV0pGfVW1gA/l2apewsorg-false-positive-8.html" title="L2.APEWS.ORG False Positive #8" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-8.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoyfyp7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-942540411671594711</id><published>2011-12-08T14:54:00.002+01:00</published><updated>2011-12-24T21:30:29.497+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.497+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #7</title><content type="html">This is another example of a possible false positive because it will depend on your client base and email flow.&lt;br /&gt;&lt;br /&gt;Wed 2011-12-07 03:59:15: [1144:6063] Accepting SMTP connection from [61.135.132.132]&lt;br /&gt;Wed 2011-12-07 03:59:15: [1144:6063] Looking up PTR record for 61.135.132.132 (132.132.135.61.IN-ADDR.ARPA)&lt;br /&gt;Wed 2011-12-07 03:59:17: [1144:6063] D=132.132.135.61.IN-ADDR.ARPA TTL=(59) PTR=[websmtp.sohu.com]&lt;br /&gt;Wed 2011-12-07 03:59:17: [1144:6063] Gathering A-records for PTR hosts&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] D=websmtp.sohu.com TTL=(10) A=[61.135.132.204]&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Wed, 07 Dec 2011 03:59:18 -0500&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] &amp;lt;-- EHLO websmtp.sohu.com&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] Performing reverse lookup on websmtp.sohu.com (looking for 61.135.132.132)&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] D=websmtp.sohu.com TTL=(9) A=[61.135.132.204]&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] --&amp;gt; 250-xxx.xxx.xxx Hello websmtp.sohu.com (may be forged), pleased to meet you&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] --&amp;gt; 250-ETRN&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] --&amp;gt; 250-8BITMIME&lt;br /&gt;Wed 2011-12-07 03:59:18: [1144:6063] --&amp;gt; 250 SIZE 0&lt;br /&gt;Wed 2011-12-07 03:59:20: [1144:6063] &amp;lt;-- MAIL FROM:&lt;zhenglutl5222 com=""&gt; SIZE=574602&lt;br /&gt;Wed 2011-12-07 03:59:20: [1144:6063] Performing reverse lookup on sohu.com (looking for 61.135.132.132)&lt;br /&gt;Wed 2011-12-07 03:59:20: [1144:6063] D=sohu.com TTL=(10) A=[61.135.181.175]&lt;br /&gt;Wed 2011-12-07 03:59:20: [1144:6063] P=010 D=sohu.com TTL=(10) MX=[sohumx.h.a.sohu.com]&lt;br /&gt;Wed 2011-12-07 03:59:20: [1144:6063] P=005 D=sohu.com TTL=(10) MX=[sohumx1.sohu.com] {61.135.132.110}&lt;br /&gt;Wed 2011-12-07 03:59:21: [1144:6063] D=sohumx.h.a.sohu.com TTL=(5) A=[61.135.132.110]&lt;br /&gt;Wed 2011-12-07 03:59:21: [1144:6063] Spam Blocker A-record resolution of [132.132.135.61.l2.apews.org] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Wed 2011-12-07 03:59:21: [1144:6063] Spam Blocker D=132.132.135.61.l2.apews.org TTL=(35) A=[127.0.0.2]&lt;br /&gt;Wed 2011-12-07 03:59:21: [1144:6063] APEWS listed, 99.7% certain it is spam&lt;br /&gt;Wed 2011-12-07 03:59:21: [1144:6063] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Wed 2011-12-07 03:59:21: [1144:6063] --&amp;gt; 250 &lt;zhenglutl5222 com=""&gt;, Sender ok&lt;br /&gt;Wed 2011-12-07 03:59:22: [1144:6063] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Wed 2011-12-07 03:59:22: [1144:6063] Can't accept or relay message.&lt;br /&gt;Wed 2011-12-07 03:59:22: [1144:6063] Sender not authenticated or from trusted domain/IP and recipient not a valid local account.&lt;br /&gt;Wed 2011-12-07 03:59:22: [1144:6063] --&amp;gt; 550 &lt;xxx@xxx.xxx&gt;, Recipient unknown&lt;br /&gt;Wed 2011-12-07 03:59:22: [1144:6063] &amp;lt;-- RSET&lt;br /&gt;Wed 2011-12-07 03:59:22: [1144:6063] --&amp;gt; 250 RSET? Well, ok.&lt;br /&gt;Wed 2011-12-07 03:59:23: [1144:6063] &amp;lt;-- QUIT&lt;br /&gt;Wed 2011-12-07 03:59:23: [1144:6063] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Wed 2011-12-07 03:59:23: [1144:6063] SMTP session successful, 126 bytes transferred.&lt;br /&gt;&lt;br /&gt;In this case the sender is a spammer that is using the free webmail service to send crap. The email address that the spammer tried to send to was stolen from a web page that no human being would see. That is what happens spammers use automated software called robots to routinely scan IP addresses for web servers hosting web pages that contain email addresses and scraping them into their databases.&lt;br /&gt;&lt;br /&gt;You have decide for yourself on the ratio of spam versus solicited emails via the Sohu servers.  Your server, your rules. Looking at the Apews.org website, this is the text that they show for the Sohu IP address;&lt;br /&gt;&lt;br /&gt;Entry matching your Query: E-492519&lt;br /&gt;61.135.132.204 CASE: C-1&lt;br /&gt;Compromised or insecure MTA&lt;br /&gt;Criminal abusers have user access&lt;br /&gt;SysAdmin not closing abusive accounts&lt;br /&gt;No or inadequate outbound mail filter&lt;br /&gt;Special Reason: List washing dirty email address database&lt;br /&gt;History: Entry created 2011-09-29&lt;br /&gt;&lt;br /&gt;So it seems they are still doing the same more than 2 months after Apews recorded their entry.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/zhenglutl5222&gt;&lt;/zhenglutl5222&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/y8IGFaMRdvI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/942540411671594711/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-7.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/942540411671594711?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/942540411671594711?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/y8IGFaMRdvI/l2apewsorg-false-positive-7.html" title="L2.APEWS.ORG False Positive #7" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-7.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoycCp7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-149771169420214391</id><published>2011-12-01T16:24:00.002+01:00</published><updated>2011-12-24T21:30:29.498+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.498+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #6</title><content type="html">This is another possible false positive, as with #5 it depends on your email flow, user requirements etc. Not everyone has the same geographic distribution of email senders, however, let us take a look;&lt;br /&gt;&lt;br /&gt;Wed 2011-11-30 22:47:41: [948:3883] Accepting SMTP connection from [121.101.151.212]&lt;br /&gt;Wed 2011-11-30 22:47:41: [948:3883] Looking up PTR record for 121.101.151.212 (212.151.101.121.IN-ADDR.ARPA)&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] D=212.151.101.121.IN-ADDR.ARPA TTL=(29) PTR=[nm3-vm0.bullet.mail.in.yahoo.com]&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] Gathering A-records for PTR hosts&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] D=nm3-vm0.bullet.mail.in.yahoo.com TTL=(30) A=[121.101.151.212]&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Wed, 30 Nov 2011 22:47:42 -0500&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] &amp;lt;-- HELO nm3-vm0.bullet.mail.in.yahoo.com&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] Performing reverse lookup on nm3-vm0.bullet.mail.in.yahoo.com (looking for 121.101.151.212)&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] D=nm3-vm0.bullet.mail.in.yahoo.com TTL=(30) A=[121.101.151.212]&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] --&amp;gt; 250 xxx.xxx.xxx Hello nm3-vm0.bullet.mail.in.yahoo.com, pleased to meet you&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] &amp;lt;-- MAIL FROM:&lt;cwkpaola1972 com=""&gt;&lt;br /&gt;Wed 2011-11-30 22:47:42: [948:3883] Performing reverse lookup on yahoo.com (looking for 121.101.151.212)&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] D=yahoo.com TTL=(60) A=[72.30.2.43]&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] P=001 D=yahoo.com TTL=(30) MX=[mta7.am0.yahoodns.net] {98.139.175.225}&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] P=001 D=yahoo.com TTL=(30) MX=[mta6.am0.yahoodns.net] {74.6.136.244}&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] P=001 D=yahoo.com TTL=(30) MX=[mta5.am0.yahoodns.net] {66.94.237.139}&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] Spam Blocker A-record resolution of [212.151.101.121.l2.apews.org] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] Spam Blocker D=212.151.101.121.l2.apews.org TTL=(35) A=[127.0.0.2]&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] APEWS listed, 99.7% certain it is spam&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] --&amp;gt; 250 &lt;cwkpaola1972 com=""&gt;, Sender ok&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Wed 2011-11-30 22:47:43: [948:3883] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Wed 2011-11-30 22:47:44: [948:3883] &amp;lt;-- DATA&lt;br /&gt;Wed 2011-11-30 22:47:44: [948:3883] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Wed 2011-11-30 22:47:44: [948:3883] --&amp;gt; 250 Ok, message saved &lt;message-id: xxxxxxxxxxxxxxxxxxxxxxx=""&gt;&lt;br /&gt;Wed 2011-11-30 22:47:45: [948:3883] &amp;lt;-- QUIT&lt;br /&gt;Wed 2011-11-30 22:47:45: [948:3883] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Wed 2011-11-30 22:47:45: [948:3883] SMTP session successful, 2254 bytes transferred.&lt;br /&gt;Wed 2011-11-30 22:47:45: [948:3883] Shuffling message(s) into proper queue(s)&lt;br /&gt;Wed 2011-11-30 22:47:45: [948:3883] Message received from nm3-vm0.bullet.mail.in.yahoo.com [121.101.151.212] &lt;cwkpaola1972 com=""&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 2245] {j:\localq\x00000000000.msg}&lt;br /&gt;&lt;br /&gt;The connecting IP address belongs to Yahoo India and is listed as a CIDR [group of IP addresses] 121.101.150.0/23 within CIDR 121.101.144.0/20. In one of the earlier posts we were talking about setup and that the free webmail providers like Yahoo, Hotmail and Google are not listed in Apews but not to mark their servers as trusted or whitelisted, simply let them connect and go through the full SMTP process on your server including rDNS / PTR lookup as you feel necessary.&lt;br /&gt;&lt;br /&gt;This listing is therefore a contradiction and surprises us a little, hmmm... requires some further research. Email delivery involves a dialog between two email servers resulting in some lines of text referred to as the email header. A lot of spam comes from a connecting IP address that sends data showing that it received the email from one or more email servers prior. In most cases this information can not be trusted as spam software is known to deliberately falsify the information in order to mislead the recipient in gaining a more trustworthy reputation. The exceptions to this are the professional email senders referred to in an earlier post and the free webmail providers like Yahoo, Hotmail and Google. Whilst they may hide or omit useful sender identifiable data, to our knowledge they don't deliberately falsify it.&lt;br /&gt;&lt;br /&gt;In order to further examine this possible false positive, a copy of the actual email was obtained from the recipient. The email client program revealed further headers;&lt;br /&gt;&lt;br /&gt;&amp;gt;from [127.0.0.1] by smtp107.mail.in.yahoo.com with NNFMP; 01 Dec 2011 03:49:03 -0000&lt;br /&gt;&amp;gt;from [121.101.151.237] by nm3.bullet.mail.in.yahoo.com with NNFMP; 01 Dec 2011 03:49:03 -0000&lt;br /&gt;&amp;gt;from [202.86.5.94] by tm2.bullet.mail.in.yahoo.com with NNFMP; 01 Dec 2011 03:49:29 -0000&lt;br /&gt;&amp;gt;from zsdguhzdpyqlnviqt (cwkpaola1972@201.241.150.55 with login) by smtp107.mail.in.yahoo.com with SMTP; 01 Dec 2011 09:19:02 +0530 IST&lt;br /&gt;&lt;br /&gt;We are almost certain that the email was passed between the Yahoo email servers as listed above. Working down the list we see that the Yahoo server named smtp107.mail.in.yahoo.com (IP address 202.86.5.94 checks out) was the one that received the email from a computer with IP address 201.241.150.55, which belongs to VTR, an ISP in Chile. At the time of writing, IP address 201.241.150.55 has named pc-55-150-241-201.cm.vtr.net, a format usually used for dynamic IP allocations, certainly not a commercial server.&lt;br /&gt;&lt;br /&gt;Now let us look at the content of the email, just one line of text;&lt;br /&gt;&lt;br /&gt;ZMLNIGXGCOBMThe_Electronic-Payments-Associationě&lt;br /&gt;&lt;br /&gt;with a link to the following website http :// goo.gl / 5z4hU.&lt;br /&gt;&lt;br /&gt;It seems suspicious that an email sender with a Chilean IP address would login to a Yahoo India webmail server to send only one email to the user on our network who does not know the sender. The content of the email is spam and quite rightly ended up in the spam folder.&lt;br /&gt;&lt;br /&gt;You will need to judge for yourselves whether the Yahoo India email servers send mostly solicited emails or mostly spam. In recent weeks we have noticed a huge rise in the volume of spam being delivered by the free webail providers especially AOL.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/cwkpaola1972&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/cwkpaola1972&gt;&lt;/cwkpaola1972&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/UmBdbpNieoo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/149771169420214391/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-6.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/149771169420214391?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/149771169420214391?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/UmBdbpNieoo/l2apewsorg-false-positive-6.html" title="L2.APEWS.ORG False Positive #6" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-6.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoycCp7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-932446488045615978</id><published>2011-12-01T15:14:00.002+01:00</published><updated>2011-12-24T21:30:29.498+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.498+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #5</title><content type="html">Found another possible false positive. I say possible because it would depend on your email flow, server policies, user requirements etc. This one is a free email service in China so the probability is that there are mostly Chinese senders which may or may not be necessary to your network and users.&lt;br /&gt;&lt;br /&gt;Wed 2011-11-30 22:46:47: [688:3882] Accepting SMTP connection from [60.28.228.177]&lt;br /&gt;Wed 2011-11-30 22:46:47: [688:3882] Looking up PTR record for 60.28.228.177 (177.228.28.60.IN-ADDR.ARPA)&lt;br /&gt;Wed 2011-11-30 22:46:48: [688:3882] D=177.228.28.60.IN-ADDR.ARPA TTL=(1440) PTR=[mail228-177.sinamail.sina.com.cn]&lt;br /&gt;Wed 2011-11-30 22:46:48: [688:3882] Gathering A-records for PTR hosts&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] D=mail228-177.sinamail.sina.com.cn TTL=(1) A=[60.28.228.177]&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Wed, 30 Nov 2011 22:46:49 -0500&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] &amp;lt;-- EHLO mail228-177.sinamail.sina.com.cn&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] Performing reverse lookup on mail228-177.sinamail.sina.com.cn (looking for 60.28.228.177)&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] D=mail228-177.sinamail.sina.com.cn TTL=(0) A=[60.28.228.177]&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] --&amp;gt; 250-xxx.xxx.xxx Hello mail228-177.sinamail.sina.com.cn, pleased to meet you&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] --&amp;gt; 250-ETRN&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] --&amp;gt; 250-8BITMIME&lt;br /&gt;Wed 2011-11-30 22:46:49: [688:3882] --&amp;gt; 250 SIZE 0&lt;br /&gt;Wed 2011-11-30 22:46:50: [688:3882] &amp;lt;-- MAIL FROM:&lt;xxx com=""&gt; SIZE=23421&lt;br /&gt;Wed 2011-11-30 22:46:50: [688:3882] Performing reverse lookup on sina.com (looking for 60.28.228.177)&lt;br /&gt;Wed 2011-11-30 22:46:50: [688:3882] D=sina.com TTL=(1) A=[12.130.132.30]&lt;br /&gt;Wed 2011-11-30 22:46:51: [688:3882] P=010 D=sina.com TTL=(0) MX=[freemx3.sinamail.sina.com.cn]&lt;br /&gt;Wed 2011-11-30 22:46:51: [688:3882] P=010 D=sina.com TTL=(0) MX=[freemx2.sinamail.sina.com.cn] {218.30.115.106}&lt;br /&gt;Wed 2011-11-30 22:46:51: [688:3882] P=010 D=sina.com TTL=(0) MX=[freemx1.sinamail.sina.com.cn]&lt;br /&gt;Wed 2011-11-30 22:46:51: [688:3882] P=005 D=sina.com TTL=(0) MX=[freemx.sinamail.sina.com.cn]&lt;br /&gt;Wed 2011-11-30 22:46:51: [688:3882] D=freemx3.sinamail.sina.com.cn TTL=(30) A=[60.28.2.248]&lt;br /&gt;Wed 2011-11-30 22:46:52: [688:3882] D=freemx1.sinamail.sina.com.cn TTL=(30) A=[202.108.3.242]&lt;br /&gt;Wed 2011-11-30 22:46:52: [688:3882] D=freemx.sinamail.sina.com.cn TTL=(0) A=[202.108.3.242]&lt;br /&gt;Wed 2011-11-30 22:46:52: [688:3882] Spam Blocker A-record resolution of [177.228.28.60.l2.apews.org] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Wed 2011-11-30 22:46:52: [688:3882] Spam Blocker D=177.228.28.60.l2.apews.org TTL=(35) A=[127.0.0.2]&lt;br /&gt;Wed 2011-11-30 22:46:52: [688:3882] APEWS listed, 99.7% certain it is spam&lt;br /&gt;Wed 2011-11-30 22:46:52: [688:3882] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Wed 2011-11-30 22:46:52: [688:3882] --&amp;gt; 250 &lt;xxx com=""&gt;, Sender ok&lt;br /&gt;Wed 2011-11-30 22:46:53: [688:3882] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Wed 2011-11-30 22:46:53: [688:3882] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Wed 2011-11-30 22:46:53: [688:3882] &amp;lt;-- DATA&lt;br /&gt;Wed 2011-11-30 22:46:53: [688:3882] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Wed 2011-11-30 22:47:05: [688:3882] --&amp;gt; 250 Ok, message saved &lt;message-id: 0000="" cn=""&gt;&lt;br /&gt;Wed 2011-11-30 22:47:05: [688:3882] &amp;lt;-- QUIT&lt;br /&gt;Wed 2011-11-30 22:47:05: [688:3882] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Wed 2011-11-30 22:47:05: [688:3882] SMTP session successful, 23613 bytes transferred.&lt;br /&gt;Wed 2011-11-30 22:47:05: [688:3882] Shuffling message(s) into proper queue(s)&lt;br /&gt;Wed 2011-11-30 22:47:05: [688:3882] Message received from mail228-177.sinamail.sina.com.cn [60.28.228.177] &lt;xxx com=""&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 23602] {j:\localq\md00000000000.msg}&lt;br /&gt;&lt;br /&gt;As before, any news will be reported here.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx&gt;&lt;/xxx&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/oMOoP1Y70IU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/932446488045615978/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-5.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/932446488045615978?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/932446488045615978?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/oMOoP1Y70IU/l2apewsorg-false-positive-5.html" title="L2.APEWS.ORG False Positive #5" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/12/l2apewsorg-false-positive-5.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEGSHoycCp7ImA9WhRXF0g.&quot;"><id>tag:blogger.com,1999:blog-6812673166339829334.post-8563919790909236019</id><published>2011-11-30T14:17:00.002+01:00</published><updated>2011-12-24T21:30:29.498+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T21:30:29.498+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="CIDR reputation" /><category scheme="http://www.blogger.com/atom/ns#" term="spam blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="apews" /><category scheme="http://www.blogger.com/atom/ns#" term="ipv4" /><category scheme="http://www.blogger.com/atom/ns#" term="l2.apews.org" /><category scheme="http://www.blogger.com/atom/ns#" term="DNSBL" /><category scheme="http://www.blogger.com/atom/ns#" term="false positive" /><title>L2.APEWS.ORG False Positive #4</title><content type="html">This is only the fourth false positive in as many weeks, and it wasn't listed before as the client said it used to be in the inbox;&lt;br /&gt;&lt;br /&gt;Mon 2011-11-28 17:33:49: [672:3108] Accepting SMTP connection from [129.228.5.23]&lt;br /&gt;Mon 2011-11-28 17:33:49: [672:3108] Looking up PTR record for 129.228.5.23 (23.5.228.129.IN-ADDR.ARPA)&lt;br /&gt;Mon 2011-11-28 17:33:49: [672:3108] D=23.5.228.129.in-addr.arpa TTL=(60) PTR=[mtv-newsletter4.mms.mtv.com]&lt;br /&gt;Mon 2011-11-28 17:33:49: [672:3108] Gathering A-records for PTR hosts&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] D=mtv-newsletter4.mms.mtv.com TTL=(1440) A=[129.228.5.23]&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] --&amp;gt; 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Mon, 28 Nov 2011 17:33:50 -0500&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] &amp;lt;-- EHLO mtv-newsletter4.mms.mtv.com&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] Performing reverse lookup on mtv-newsletter4.mms.mtv.com (looking for 129.228.5.23)&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] D=mtv-newsletter4.mms.mtv.com TTL=(1440) A=[129.228.5.23]&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] --&amp;gt; 250-xxx.xxx.xxx Hello mtv-newsletter4.mms.mtv.com, pleased to meet you&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] --&amp;gt; 250-ETRN&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] --&amp;gt; 250-AUTH=LOGIN&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] --&amp;gt; 250-AUTH LOGIN CRAM-MD5&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] --&amp;gt; 250-8BITMIME&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] --&amp;gt; 250 SIZE 0&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] &amp;lt;-- MAIL FROM:&lt;bounce com=""&gt;&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] Performing reverse lookup on mms.mtv.com (looking for 129.228.5.23)&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] D=mms.mtv.com TTL=(1440) A=[129.228.5.22]&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] P=010 D=mms.mtv.com TTL=(1440) MX=[mailin.strongmail.west.mtvi.com] {129.228.1.185}&lt;br /&gt;Mon 2011-11-28 17:33:50: [672:3108] Spam Blocker A-record resolution of [23.5.228.129.l2.apews.org] in progress (DNS Server: 192.168.1.2)...&lt;br /&gt;Mon 2011-11-28 17:33:51: [672:3108] Spam Blocker D=23.5.228.129.l2.apews.org TTL=(35) A=[127.0.0.2]&lt;br /&gt;Mon 2011-11-28 17:33:51: [672:3108] APEWS listed, 99.7% certain it is spam&lt;br /&gt;Mon 2011-11-28 17:33:51: [672:3108] Message will be accepted and X-RBL-Warning: header will be inserted.&lt;br /&gt;Mon 2011-11-28 17:33:51: [672:3108] --&amp;gt; 250 &lt;bounce com=""&gt;, Sender ok&lt;br /&gt;Mon 2011-11-28 17:33:51: [672:3108] &amp;lt;-- RCPT TO:&lt;xxx@xxx.xxx&gt;&lt;br /&gt;Mon 2011-11-28 17:33:51: [672:3108] --&amp;gt; 250 &lt;xxx@xxx.xxx&gt;, Recipient ok&lt;br /&gt;Mon 2011-11-28 17:33:51: [672:3108] &amp;lt;-- DATA&lt;br /&gt;Mon 2011-11-28 17:33:51: [672:3108] --&amp;gt; 354 Enter mail, end with &lt;crlf&gt;.&lt;crlf&gt;&lt;br /&gt;Mon 2011-11-28 17:33:52: [672:3108] --&amp;gt; 250 Ok, message saved &lt;message-id: 1191829="" com=""&gt;&lt;br /&gt;Mon 2011-11-28 17:33:52: [672:3108] &amp;lt;-- QUIT&lt;br /&gt;Mon 2011-11-28 17:33:52: [672:3108] --&amp;gt; 221 See ya in cyberspace&lt;br /&gt;Mon 2011-11-28 17:33:52: [672:3108] SMTP session successful, 10320 bytes transferred.&lt;br /&gt;Mon 2011-11-28 17:33:52: [672:3108] Shuffling message(s) into proper queue(s)&lt;br /&gt;Mon 2011-11-28 17:33:52: [672:3108] Message received from mtv-newsletter4.mms.mtv.com [129.228.5.23] &lt;bounce com=""&gt; with SMTP for &lt;xxx@xxx.xxx&gt; [Size 10309] {j:\localq\md00000000000.msg}&lt;br /&gt;Mon 2011-11-28 17:33:52: ----------&lt;br /&gt;&lt;br /&gt;As you can see from the headers, this is MTV's newsletter. Well, watch this space, we'll check in a day or two and report back.&lt;br /&gt;&lt;/xxx@xxx.xxx&gt;&lt;/bounce&gt;&lt;/message-id:&gt;&lt;/crlf&gt;&lt;/crlf&gt;&lt;/xxx@xxx.xxx&gt;&lt;/xxx@xxx.xxx&gt;&lt;/bounce&gt;&lt;/bounce&gt;&lt;img src="http://feeds.feedburner.com/~r/ApewsUser/~4/qjqxCBe7BWY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://apews-user.blogspot.com/feeds/8563919790909236019/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://apews-user.blogspot.com/2011/11/l2apewsorg-false-positive-4.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/8563919790909236019?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6812673166339829334/posts/default/8563919790909236019?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApewsUser/~3/qjqxCBe7BWY/l2apewsorg-false-positive-4.html" title="L2.APEWS.ORG False Positive #4" /><author><name>Administrator</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://apews-user.blogspot.com/2011/11/l2apewsorg-false-positive-4.html</feedburner:origLink></entry></feed>
