September 10, 2007
@ 10:26 AM

I received some nice spam from Bell.ca this morning.

It was sent from an authorized host, as per the SPF records:

"v=spf1 mx ip4:198.235.69.10 ip4:198.235.69.45 ip4:198.235.69.46 ip4:206.47.0.168 ip4:206.47.0.173 ip4:206.47.0.177 ip4:207.236.237.0/25 ip4:67.70.214.43 ip4:216.18.99.22 ip4:69.156.197.234 ip4:66.241.131.163 +all"

Message headers:

Received: from TOROON12-1242491208.sdsl.bell.ca (74.14.233.72) by
 mail.justinho.com ([internal ip removed]) with Microsoft SMTP Server id 8.0.744.0; Mon,
 10 Sep 2007 10:23:43 -0400
From: enlarge laser <
xkpnzyx@bell.ca>
...
X-MS-Exchange-Organization-PRD: bell.ca
Received-SPF: Pass (orinoco.jupiterstation.justinho.com: domain of
 
xkpnzyx@bell.ca designates 74.14.233.72 as permitted sender)
 receiver=orinoco.jupiterstation.justinho.com; client-ip=74.14.233.72;
 helo=TOROON12-1242491208.sdsl.bell.ca;
X-MS-Exchange-Organization-PCL: 2
X-MS-Exchange-Organization-Antispam-Report: DV:3.3.5707.600;SV:3.3.5708.437;SID:SenderIDStatus
 Pass;TIME:TimeBasedFeatures
X-MS-Exchange-Organization-SCL: 4
X-MS-Exchange-Organization-SenderIdResult: PASS

Someone's machine got pwn3d and started spewing junk.  I'm guessing the overly lax SPF record is due to poor control of things... =)