>How can I determine what the real domain or IP is a recieved email address? >I have recieved spam that I want to block but no domain is listed. look in your logs:
12:12 00:00 SMTPD(3F7B0174) [212.73.210.73] connect 212.73.210.75 port 2603 12:12 00:00 SMTPD(3F7B0174) [212.73.210.75] HELO mgw1.MEIway.com 12:12 00:00 SMTPD(3F7B0174) [212.73.210.75] MAIL FROM:<owner-postfix-users@postfix.org> 12:12 00:00 SMTPD(3F7B0174) [212.73.210.75] RCPT TO:<lconrad@Go2France.com>
The "connect" ip is the sending machine, your best item to block. Assume ehlo/helo hostname, "mail from: sender@senderdomain" to be bogus.
Len
http://BIND8NT.MEIway.com : Binary for ISC BIND 8.2.3 T9B for NT4 & W2K http://IMGate.MEIway.com : Build free, hi-perf, anti-spam mail gateways