Well, the IP addresses I've been seeing are all over the place. I have narrowed one source down to a single IP, but there seems to be no rhyme or reason unless I'm not looking in the right spot.
Here's one of them, and I've substituted <myemailaddress@somewhere.net> in those places where the valid email address shows up. And I've removed the domain name in the Return-Path, but it belongs to an private IP provider, clarity.net
Chris, all of this from the bottom is added…there is no such IP address over 255. 255.255.255 so this is BS [729.6.48.3] pay close attention to RECEIVED FROM: in this case =psmtp.com
http://www.robtex.com/dns/psmtp.com.htmlSun, 09 Nov 2008 08:11:10 PST
X-Originating-IP: [729.6.48.3]
X-Originating-Email: [myemailaddress@somewhere.net]
X-Sender: myemailaddress@somewhere.net
To: <myemailaddress@somewhere.net>
Subject: RE: zr.Doctor Harlan
From: <myemailaddress@somewhere.net>
MIME-Version: 1.0
Importance: High
Content-Type: text/html
X-pstn-levels: (S: 0.00000/86.03780 CV:99.9999 R:95.9108 P:95.9108 M:95.5423 C:98.6951 )
X-pstn-settings: 2 (0.5000:0.5000) s cv gt3 gt2 gt1 r p m c
X-pstn-addresses: from <myemailaddress@somewhere.net> forward (user good) [3996/158]
X-UIDL: "%,!!(c7"!4RN"!jG?"!
Then we come to this where ([64……receives data from ([93……..who happens to be Russian
Received: from source ([93.120.176.55]) by exprod7mx230.postini.com ([64.18.6.14]) with SMTP;
Sun, 09 Nov 2008 08:11:10 PST
inetnum: 93.120.128.0 - 93.120.191.255
netname: DYNAMIC-BRAS-POOL5-NNOVVT
descr: Network for OJSC VolgaTelecom
descr: N.Novgorod Branch BRAS dynamic IP pools
descr: About abuse activity please
descr: e-mail to abuse@nnov.vt.ru
country: RU
admin-c: VT-RU
tech-c: VT-RU
status: ASSIGNED PA
mnt-by: NMTS-MNT
source: RIPE # Filtered
I just checked robtex
http://www.robtex.com/dns/psmtp.com.html and found that psmtp.com= 64.18…..is on the spam list and your filters should be catching this stuff.
NetRange: 64.18.0.0 - 64.18.15.255
CIDR: 64.18.0.0/20