There was a problem a while ago with a guy making an account and then using the email button next to members' names to send them spam. Those emails come from bay12forums.com because the forum sends them. To prevent getting those, you'd have to go into your profile and make yourself un-emailable. That time, the "
qezetn@dwxjhn.com" part let me find out who it was and ban them. This time, I can't find a member with that name/email, so they were either one of the several spammers whose accounts I deleted today, or it is indeed a security problem that allows people to send mail from my server. At this point I don't know which one.
edit:
The last one looked like this:
Delivered-To: <email>
Return-Path: <www-data@bay12forums.com>
Received: from mail.bay12forums.com (bay12forums.com [97.107.128.126])
Received-SPF: pass (google.com: best guess record for domain of www-data@bay12forums.com designates 97.107.128.126 as permitted sender) client-ip=97.107.128.126;
Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of www-data@bay12forums.com designates 97.107.128.126 as permitted sender) smtp.mail=www-data@bay12forums.com
Received: by mail.bay12forums.com (Postfix, from userid 33)
id 4BF30146007; Sat, 19 Jun 2010 01:44:35 -0700 (PDT)
To: <email>
Subject: hi
From: "elody002@yahoo.cn" <toadyone@bay12games.com>
Reply-To: <elody002@yahoo.cn>
Date: Sat, 19 Jun 2010 08:44:35 -0000
X-Mailer: SMF
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="SMF-87f18405698de29a03460206963dadfc"
Content-Transfer-Encoding: 7bit
Message-Id: <20100619084435.4BF30146007@mail.bay12forums.com>