How to block an IP from sending you email?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ChrisTech
    Senior Member
    • Mar 2004
    • 530

    #1

    How to block an IP from sending you email?

    I'm getting a flow of netsky.p viruses from 168.215.220.18

    I want to block 168.215.* from my domain. Is it possible to do that with spam assassin? Normally I just filter on my side, but this one is causin me a headache and I'd love to just blackhole the little *****. I dont know anyone from that area, so its no skin off my back.

    Name: 168-215-220-18.gen.twtelecom.net
    IP Address: 168.215.220.18
    Location: San Diego (32.722N, 117.172W)
    Network: TWTELECOM-COM
    Hosting at Dathorn since March 2003!

    My Interwebs speed on Charter Cable!
  • sdjl
    Senior Member
    • Mar 2004
    • 502

    #2
    Um, i'm not sure we have access to block emails by IP address.
    I know you can deny access to your website via IP, but as far as i'm aware you'd have to have root access to do it for emails.

    I could be wrong.

    David
    -----
    Do you fear the obsolescence of the metanarrative apparatus of legitimation?

    Comment

    • ChrisTech
      Senior Member
      • Mar 2004
      • 530

      #3
      Originally posted by sdjl
      Um, i'm not sure we have access to block emails by IP address.
      I know you can deny access to your website via IP, but as far as i'm aware you'd have to have root access to do it for emails.

      I could be wrong.

      David

      I'm too used to just doing

      route add -host (someipaddy) 127.0.0.1 -blackhole

      Didn't know if there was a way in cpanel or not or spam assassin.
      Hosting at Dathorn since March 2003!

      My Interwebs speed on Charter Cable!

      Comment

      • sdjl
        Senior Member
        • Mar 2004
        • 502

        #4
        Yeah, that would be nice here. I get lots of spam based HTTP requests which would be nice to blackhole
        -----
        Do you fear the obsolescence of the metanarrative apparatus of legitimation?

        Comment

        • ChrisTech
          Senior Member
          • Mar 2004
          • 530

          #5
          gah


          Return-path: <timsfm@gmail.com>
          Envelope-to: xxxxxxxxxx@mydomain.com
          Delivery-date: Mon, 07 Feb 2005 09:52:16 -0600
          Received: from me by cpanel08.gzo.com with local-bsmtp (Exim 4.43)
          id 1CyBBQ-0008UV-DW
          for xxxxxxxx@mydomain; Mon, 07 Feb 2005 09:52:16 -0600
          Received: from [168.215.220.18] (helo=mydomain.com)
          by cpanel08.gzo.com with esmtp (Exim 4.43)
          id 1CyBBP-0008UI-H9
          for xxxxxxxxxx@mydomain.com; Mon, 07 Feb 2005 09:52:16 -0600
          From: timsfm@gmail.com
          To: xxxxxxxxxx@mydomain.com
          Subject: Re: Bad Request
          Date: Mon, 7 Feb 2005 07:52:29 -0800
          MIME-Version: 1.0
          Content-Type: multipart/mixed;
          boundary="----=_NextPart_000_0016----=_NextPart_000_0016"
          X-Priority: 3
          X-MSMail-Priority: Normal
          X-Spam-Status: No, score=1.5 required=4.2 tests=MIME_BOUND_NEXTPART,
          MISSING_MIMEOLE,NO_REAL_NAME,PRIORITY_NO_NAME autolearn=no
          version=3.0.2
          X-Spam-Level: *
          X-Spam-Checker-Version: SpamAssassin 3.0.2 (2004-11-16) on cpanel08.gzo.com
          Message-Id: <E1CyBBQ-0008UV-DW@cpanel08.gzo.com>

          gah Netsky.P everytime I check my pop3 email for my one account I have one, and it hangs out OE. Even checking webmail is proving to be difficult. Anyone have any suggestions? It's the same IP everytime. I've emailed the ISP but so far no luck in obtaining a response.
          Hosting at Dathorn since March 2003!

          My Interwebs speed on Charter Cable!

          Comment

          • sdjl
            Senior Member
            • Mar 2004
            • 502

            #6
            Does using email filters not help at all?
            You could tell it to ignore all messages with that IP in the headers?

            David
            -----
            Do you fear the obsolescence of the metanarrative apparatus of legitimation?

            Comment

            • Buddha
              Senior Member
              • Mar 2004
              • 825

              #7
              You could set a regular express for any header using E-mail filtering.
              "Whatcha mean I shouldn't be rude to my clients?! If you want polite then there will be a substantial fee increase." - Buddha

              Comment

              • Roman
                Junior Member
                • Apr 2004
                • 7

                #8
                Originally posted by Buddha
                You could set a regular express for any header using E-mail filtering.
                Yeah, but I simply did "Add Filter" then "Any Header", "Contains", and then the IP Address, which in my case was "216.43.223.229". The rule came out looking like:
                Code:
                $message_headers contains "216.43.223.229"
                It's been working great!

                Comment

                • ChrisTech
                  Senior Member
                  • Mar 2004
                  • 530

                  #9
                  Originally posted by Roman
                  Yeah, but I simply did "Add Filter" then "Any Header", "Contains", and then the IP Address, which in my case was "216.43.223.229". The rule came out looking like:
                  Code:
                  $message_headers contains "216.43.223.229"
                  It's been working great!
                  My emails finally got some attention @ their ISP (I sent it to every email address they had listed everytime I got the virus). I don't think they liked that.
                  Hosting at Dathorn since March 2003!

                  My Interwebs speed on Charter Cable!

                  Comment

                  • sixfortyfive
                    Junior Member
                    • Apr 2004
                    • 21

                    #10
                    I was just looking for this information! I'm getting repeated spam from the same IP, and wanted to block it. I'll try adding a mail filter like you mentioned.

                    Comment

                    • goose
                      Junior Member
                      • Mar 2004
                      • 17

                      #11
                      Originally posted by ChrisTech
                      I'm getting a flow of netsky.p viruses from 168.215.220.18

                      I want to block 168.215.* from my domain. Is it possible to do that with spam assassin? Normally I just filter on my side, but this one is causin me a headache and I'd love to just blackhole the little *****. I dont know anyone from that area, so its no skin off my back.

                      Name: 168-215-220-18.gen.twtelecom.net
                      IP Address: 168.215.220.18
                      Location: San Diego (32.722N, 117.172W)
                      Network: TWTELECOM-COM
                      168-215-220-18.gen.twtelecom.net. Than why not just report it to twtelecom.net? Might work!

                      Comment

                      • Roman
                        Junior Member
                        • Apr 2004
                        • 7

                        #12
                        Originally posted by goose
                        168-215-220-18.gen.twtelecom.net. Than why not just report it to twtelecom.net? Might work!
                        You must have missed reading post #5 and #9 where he talks about that.

                        Comment

                        • ChrisTech
                          Senior Member
                          • Mar 2004
                          • 530

                          #13
                          Originally posted by goose
                          168-215-220-18.gen.twtelecom.net. Than why not just report it to twtelecom.net? Might work!
                          Try actually reading the posts next time. Took almost 60+ emails to get someone's attention. Made a group for them in my address book, and just forwarded the email (virus attachement and all) to every address they had listed for support, sales, president, ect. It finally caught their attention.
                          Hosting at Dathorn since March 2003!

                          My Interwebs speed on Charter Cable!

                          Comment

                          Working...