I reserve the right to publish any communication between spammers and me in whole or in part.

These files contain the headers of all spam send to this system over the last couple of decades (the complete spam archive is available to legitimate spam investigators).
Please keep in mind that some of the information, including the sender address, may be forged. If you find that someone has been using your name or email address without your consent, it might be a nice idea to have them prosecuted.
To avoid harvesting, email addresses have been modified; 'Some.User@Some.Domain' has been changed into 'Some.User%40Some%2EDomain'. Message-Ids are unaltered. So anything with an at ('@') in it, is in fact a message-id, not an email address!

Test mails from spammers looking for vulnerable web forms.

Yet an other persistent harasser (Dutch).

Phishes from creeps how claim to be my ISP. This bothered me for years, but I only recently started tracking this.

More recently: a little Exim filter to block this crap; is my ISP. So their hosts are *
Mail sent by XS4ALL to me, will be send to All other mail send by the XS4ALL mailservers should be send to My_Address@My_Domain.
If mail send to does not originate from an email address or not from XS4ALL host, it's a phish.

I use a '.forward' to forward the mail to xs4all@My_Domain. At home, /etc/aliases delivers the mail to My_Address@My_Domain.
By testing the Envelope-to, I can distinguish between forwarded and non forwarded mail.


# Check forward at XS4ALL
  message    = This looks like a phish to me.
  hosts      = * : *
  recipients = xs4all@My_Domain
  senders    = ! : ! *

This checks the envelope-from. This should either be '<>' or an XS4ALL email address.


# Check forward at XS4ALL
  message    = This looks like a phish to me.
  hosts      = * : *
  condition  = ${if match\
  set acl_m7 = ${filter{<\n $rh_received:}{match{$item}\
  {\N^from .*\[([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+|::1|[0-9A-Fa-f]{1,4}:.+)\]\N}}}
  condition  = ${if forany\
    {<\n $acl_m7}{!match{$item}\

All raw header received lines, starting with 'from ' AND containing an IP address are put in 'acl_m7' ('<\n' means delimiter is newline).
'forany' tests all these remaining lines in acl_m7. If any of these lines does not match an IP address used by my ISP (, 194.109.*.*, ::1, 2001:888:*), the mail gets rejected.

Spammers use worms and viruses to send spam and harass anti spam sites.
Below systems that are possibly infected;