We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28042 ☆ A M B ☆
    • 24,524 Posts
    I’m beginning to suspect somebody is sending spam from my sottwell.com mail server. It’s a virtual private server with Clook, with several MODx installations, and I’m getting their support people to help me pin it down. I seriously doubt it’s coming through any of the MODx mailer features, but I thought I’d mention it just in case, and will update this when I have more information.
      Studying MODX in the desert - http://sottwell.com
      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
      Join the Slack Community - http://modx.org
      • 31337
      • 258 Posts
      Post some of the spams here with full headers -- let’s see if we can help you track it down.
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        It’s not what I’m getting, it’s that I’m getting bounce messages, and so far two people have not been getting my mail from that address, although even that is under questionable circumstances.

        According to my host’s support
        This is more than likely because of a catch-all account (default address) you should create POP accounts and set your catch-all to :fail: and this issue will not occur.

        The issue you are encountering is known as reverse NDR attacks which is where a spammer sends an email to your catch-all and spoofs the reply-to field.
        However, looking at my logs I’m suspecting something more along the lines of the eForm bug that sends an empty email to the submitter of the contact form; I am going to have to do something with those forms like set up the "I am a spambot/I am a real person" radio buttons. I really despise the graphical "captcha" things.
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org