I have noticed that my email account has sent out messages that are bounced from other firewalls. The messages are sent from a ficticious account with my domain name and the emails are the general spam variety. When I do a virus search, nothing comes up. How do I find and clean the virus? I use a G4 powerbook with OS X. Many thanks.

Dani AI

Generated

Most likely this is spoofing/backscatter — not a virus inside Entourage. As and suggested, spammers commonly forge the From: address so you receive bounce messages for mail you never sent; that behaviour is called backscatter. Read the short explanation of backscatter for context. (spamhaus.org)

Quick checks that will tell you which problem you actually have (use ’s test as an example): open your account in webmail (not Entourage) and look in Sent; if webmail shows no outgoing spam then your address is being forged. Open a bounced message’s full headers / “original” and look for the Received: chain and for spf=, dkim= or dmarc= results — that will show which server tried to deliver or bounced the message. Cloudflare’s guide explains how SPF/DKIM/DMARC results appear in headers and what to look for. (cloudflare.com)

If you discover messages were actually sent via your account or server, act immediately: change the account password, revoke app-specific passwords, sign out all devices, remove unknown forwarding rules, enable two‑factor auth, and ask your mail/hosting provider for SMTP logs (they’ll show which IPs authenticated). To reduce future spoofing/backscatter at the domain level, publish SPF and DKIM and deploy DMARC (start with p=none for monitoring, then move to quarantine/reject). RFCs and practical guides explain the standards and rollout steps. If you use shared hosting or run web forms, check web scripts for compromise. ()

Practical checklist

  • Check Sent on webmail (not just Entourage).
  • View full headers of a bounce to trace the origin.
  • Change password, enable 2FA, revoke app passwords / sessions.
  • Disable unknown forwards/filters and scan any web apps on the same domain.
  • Ask your host for SMTP/auth logs; if your server sent mail, they’ll show it.
  • Publish SPF/DKIM and add DMARC reporting; move to enforcement once reports look clean. (cloudflare.com)

If after these steps you still see unexplained outgoing mail, include one bounce (with full headers) when you contact your provider or a helper so they can trace the sending IP and stop the abuse.

Recommended Answers

All 5 Replies

I highly doubt that you have a virus on entourage. It's more likely that someone is sending email from their account, with your return address, effectively spoofing. Then you recieve the bounced emails that you never sent. I cannot find any reports of a Entourage virus on OS X.

I to am having that problem, do you know how I can stop the spoofing?

I to am having that problem, do you know how I can stop the spoofing?

You can't really. The spammer's servers can append any email address they choose, so you don't have any control. However, you can send a polite email to the servers that are bouncing the mail asking them to stop it - as you're not really sending them. Usually the return addresses from the firewalls/servers are no-reply, so you'll often have to visit their website to get the webmaster's email address.

Hope this helps

I have noticed that my email account has sent out messages that are bounced from other firewalls. The messages are sent from a ficticious account with my domain name and the emails are the general spam variety. When I do a virus search, nothing comes up. How do I find and clean the virus? I use a G4 powerbook with OS X. Many thanks.

I have the same problem! I tested my theory that Entourage was involved by changing my password (for the second time) but this time not using my iPhone nor Entourage to access my e-mail. I accessed it through my webmail server on the Internet and after a day of old kickbacks my e-mail address isn't being used for SPAM. My only problem now is how do I go back to using Entourage without starting up the SPAM problem again?

It is almost guarantee that you do not have a virus. The fact is that you can send emails that look like they come from anyone you want, it's great fun. SMTP and POP have no authentication of senders, there are protocols that do but their use is not widespread. If the message is actually coming from your computer then you probably should delete the application data of the app that is sending it.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.