Industry guru Dave Taylor answers free tech support questions about a wide variety of business and technical topics, including blogging, Google AdSense, MySpace, Sony PSP, Apple iPod, Mp3 players, management, Linux, SEO, Mac OS X, Facebook, Twitter, LinkedIn and Microsoft Windows.

What's a "joe job" and why are spammers using my domain?

In the past 3 days I've received dozens of returned e-mails that appear to be sent by my domain name but that are not valid email addresses. For example I received a returned e-mail today that was "sent" from nvsnx@mydomainname.com but there is no user "nvsnx". Where did this come from, how do I stop it, and what risk am I at from this happening?


Dave's Answer:

You're a victim of what the spyware / spam community calls a joe job, a deliberate effort to send out spam or other email (often viruses or spyware) masquerading as part of your domain or even as you, rather than having the sender be their own account.

Unfortunately, there's really not much you can do about this sort of problem, though it's definitely important to check and ensure that you don't have an open mail relay or otherwise aren't actually hosting the spam messages being sent out: if your system is compromised, spam being sent might be the least of your problems!

Here's information on how to test for an open relay: quick check for an open mail relay.

If you do find that your site is open or, upon investigation, has been hacked, then I suggest the following sequence of events (and yes, they're painful):

  1. Pull your server off the net completely.
  2. Do a full backup
  3. Reinstall the operating system and all important software (including Web server, common CGI scripts, the SQL database system, etc).
  4. Check your FTP archives to ensure that you aren't inadvertently hosting any porn or warez.
  5. Get help so you can identify how they came in (was it a bad password, a social engineering hack, a known exploit you didn't patch, a poorly written script, or what?) and fix it.
  6. Come back online and carefully monitor attempts to connect to your telnet, ssh and ftp ports.

If you're clean, you're not an open relay and your system hasn't been compromised, then all you can do when you're the victim of a "joe job" is to just wait it out and apologize (and explain) if you get any grumbly email from victims. You can point them to the following Wikipedia page to explain what's happening:

    http://en.wikipedia.org/wiki/Joe_job

Good luck! This is a very frustrating experience, I know.



Help others find this article at Del.icio.us, Digg, Netscape, Reddit, and Simpy.

Subscribe!

Never miss another useful Q&A article again! Subscribe to AskDaveTaylor with Google Reader.

Comments
Rather amazingly, there are no comments on this article yet.

I have a lot to say, but ...
Starbucks coffee cup I have a lot to say, and questions of my own for that matter, but most of all I'd like to say thank you for all your efforts on this Web site by buying you a chai!

I do have a comment, now that you mention it!









Remember personal info?


Please note that I will never send you any unsolicited commercial email. Ever.

While I'm at it, please note that by submitting a question or comment you're agreeing to my terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site.









Uniblue: Free Virus Scan

Search
Find just the answers you seek from among our 1700+ free tech support articles by using our Lijit search engine.


Help!





Subscribe to
Ask Dave Taylor!

Add to Google Reader
Add to My Yahoo!
Subscribe in NewsGator Online

RDF   XML

Free Updates!
Sign up and get free weekly updates and special offers on books, seminars, workshops and more.


Recent Entries
Join the List!
Join my author info mailing list, where you'll learn about my upcoming books, speaking gigs, and more!


Book Links
© 2002 - 2008 by Dave Taylor. All Rights Reserved.

Note: This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this web site or on any linked site.

[whiteboard marker tray]