Hi,
We received an email feedback report from AOL, we started yesterday receiving a lot of these emails that are coming from AOL. It's indicating to us that we either sending a SPAM email from our exchange servers to an AOL user, or we are used as a mail relay (this won't be the case since we close our mail relay to only known servers)
Here is a header of one example if anybody can make any sense of this , it will be very helpful:
Return-Path: <hxinlet@chunghocomnet.com>
Received: from vm-bosta2k3edge.coganltd.priv (smtp.cogan.com [38.127.66.23])
by mtaiw-aaf01.mx.aol.com (Internet Inbound) with ESMTP id C7ADF70925941 for
<redacted>; Tue, 30 Jun 2015 13:01:31 -0400 (EDT)
Received: from BOSTA2013-CT-2.coganltd.priv (10.0.0.32) by
vm-bosta2k3edge.coganltd.priv (10.0.4.6) with Microsoft SMTP Server (TLS) id
15.0.847.32; Tue, 30 Jun 2015 12:54:55 -0400
Received: from Pickup by BOSTA2013-CT-2.coganltd.priv with Microsoft SMTP
Server id 15.0.847.32; Tue, 30 Jun 2015 16:54:49 +0000
X-GFI-METKTSID: 39d8131e-45e7-471e-a39c-e00a5d207cca
X-GFI-METKTSIG: Yhsm6/GnBynbvswW3Gdl7t90542j6dps6GhSEp2m7EjtM6HqO11A0+zWJKufXjHuSi6HyMNHtXa2L+YKl8PyCCtTBAL73bJtkZFpploVc75O2aH4qXzEGG1UPNfBc/4hbgbg9UMS79Nep5zFdn9jnS23RxOtcoJ0IW91F4KQobY=
X-GFI-ALK: 28e1eb4d-c825-4dec-97ef-cb27812c0666
Received: from BOSTA2013-CT-2.coganltd.priv (10.0.0.32) by
BOSTA2013-CT-2.coganltd.priv (10.0.0.32) with Microsoft SMTP Server (TLS) id
15.0.847.32; Tue, 30 Jun 2015 12:54:47 -0400
Received: from vm-bosta2k3edge.coganltd.priv (10.0.4.6) by
BOSTA2013-CT-2.coganltd.priv (10.0.0.32) with Microsoft SMTP Server (TLS) id
15.0.847.32 via Frontend Transport; Tue, 30 Jun 2015 12:54:47 -0400
Received: from chunghocomnet.com (186.91.126.88) by
vm-bosta2k3edge.coganltd.priv (10.0.4.6) with Microsoft SMTP Server id
15.0.847.32; Tue, 30 Jun 2015 12:54:17 -0400
Received: from sOt.Uc.NVJVf933SE.com (sOt.Uc.NVJVf933SE.com [97.12.103.181])by
redacted@ecogan.com
Received: from [12.111.137.160] by 7075334444.qZmEJC.com (via HTTP)
Subject: Alert from financial department
From: hxinlet <hxinlet@chunghocomnet.com>
To: <redacted@ecogan.com>
MIME-Version: 1.0
Message-ID: <8728b5cf-011e-45df-b57b-ba65a99f7c39@chunghocomnet.com>
Date: Tue, 30 Jun 2015 12:25:28 -0400
Content-Type: multipart/alternative;
boundary="=_------------050905020505060503050808"
Received-SPF: Fail (vm-bosta2k3edge.coganltd.priv: domain of
hxinlet@chunghocomnet.com does not
designate 186.91.126.88 as permitted sender) receiver=vm-bosta2k3edge.coganltd.priv;
client-ip=186.91.126.88; helo=chunghocomnet.com;
X-GFI-SMTP-Submission: 1
X-GFI-SMTP-Submission: 1
X-GFI-SMTP-HelloDomain: vm-bosta2k3edge.coganltd.priv
X-GFI-SMTP-RemoteIP: 10.0.4.6
X-GFIME-MASPAM: SPAM
X-GFI-MOVETOJUNK: 1
Old-Message-ID: <5592CA00.D015B94D@chunghocomnet.com>
x-aol-global-dis
Authentication-Results: mx.aol.com;
spf=temperror (aol.com: while processing the SPF record for chunghocomnet.com we encountered a temporary error.) smtp.mailfrom=chunghocomnet.com;
x-aol-sid: 3039ac1a7f5b5592cb6a5945
X-AOL-IP: 38.127.66.23
X-AOL-SPF: domain : chunghocomnet.com SPF : tem