
Yi7El32waoPt+hdET元RRAP+sIIg1m+3T2an0Ts9ybQrzyFygMSn3StJK50BmlD9JLWdf8yRczvV TOsr9R6TCnLTT8PwEDyL6LyGnzWx+EiemIutea2IJQq0ZjJqeuAN+/vR8pMOKmomCMlZ8XB0XSkAĥGB2HyQGwYsg0faMr1GOKMHj4lOXsOmkK0wAsBhrlPKBuifGyW9kD2SVB9isqXmmicT/K97EzVEtĭomainKey-Signature: a=rsa-sha1 c=nofws q=dns s=2014 d= ī=7iJ8c9LGnHx41HeXBDcF+BfOo00JISLpAXWCgjb8gMsx3IMl3d3XmuQq1WjJUJMcv0F8elpyhlqx H=Reply-To:From:To:Subject:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Date ī=zuzPWcZK9atz/EzVmI0P28AMPvfOAw5fH7Mj2hzZeay+OtI+x1baocpgNetYrmxUWOxmV224xLjsģ+hcllzUdQx+KGbnhbKjbL4TPqnnawzZT7MVEpx+圎upvFr6lHbsko0RHmo3PELQx2g36f1W20p7 They come with an attachment, here is what is contained in that: DKIM-Signature: v=1 a=rsa-sha1 c=relaxed/relaxed s=2014 d= Notification (DSN) report in standard format, as well as the headersĭelivery failed will not continue tryingĥ.3.2 (system not accepting network messages) Remote-MTA: dns (68.87.20.5) Diagnostic-Code: smtp 554 Of the affected recipients also attached is a Delivery Status I am sending you this message to inform you on the delivery status ofĪ message you previously sent. They always seem to be related to Comcast, as if a user on that ISP is trying to spam via us as a relay, to our own ourmailer acronym on the domain. Here is the contents of one of the emails received this morning.

I have performed 3 server audits to make sure nothing is up, but I can't help feeling like I missed something or that they have found a way to userp their way into the chain somehow. They are always trying to send via the un-used address.

Over the last few months, we have began to notice a lot of strange bounce mails going straight to spam that seem to be fakes.

Instead, mail for each domain fires off into that inbox, and we are able to use each domain address normally. For the sake of example, let's call it although that address is never used. There is 1 domain for which Gmail manages a POP for the the rest of them are just forwarders into Gmail as an alias. We run a server with multiple domains which have all the classic email addresses such as managed by a team inbox under a non-masked gmail account. Are spam messages labeled by Gmail as "Fake Bounce Emails" really that fake in all cases? Is there a way they could actually be legit?
