Isteer.net: No bounce processing, no RFC2142/5321 required role addresses, no respect for opt-out

Isteer.net, a domain name registered to IPSS-Intelligent Precision Solutions and Services Oy, a Finnish limited company, is an ESP to various Finnish advertisers. They don’t process bounces, they deliberately refuse mail to abuse and postmaster, and they don’t respect opt-out.

This is not related to Intellectual Property Software Solutions of Wirral, UK, in any way.

Spamming IP: 77.73.6.98 (Memset Hosting, UK)

One of the slightly interesting bits here is that isteer.net was registered only in December 2010. (As per the Finnish Business Information System search above, of course the company itself is about 12 years old.) Anyway, isteer.net didn’t exist, and consequently couldn’t have started providing ESP services to anybody until well after Savon Voima plc had abandoned atro.fi in the end of August 2009. IPSS were using ipss.fi for the same purpose earlier, and to a degree, were and still are using (UK) Memset Ltd’s miniserver.com.

I keep mail logs for a year, so I currently have data starting from October 24, 2010. The first occurrence of isteer.net sent mail is from the end of February 2011 (cue Postfix log snippet):

Feb 23 06:41:08 myhostname postfix/qmgr[13605]: 69D4C794D24: from=<bounce_a_b_c_d@bounce.isteer.net>, size=19453, nrcpt=1 (queue active)
Feb 23 06:41:08 myhostname postfix/local[14496]: 69D4C794D24: to=<spam@myhostname>, orig_to=<some.address@atro.fi>, relay=local, delay=0.36, delays=0.29/0.01/0/0.05, dsn=2.0.0, status=sent (delivered to command: /usr/bin/procmail)

The first occurrence of ipss.fi and miniserver.com is from February 1, 2011 (cue Postfix log snippet):

Feb  1 10:54:48 myhostname postfix/smtpd[3857]: connect from ipssoaa5.miniserver.com[77.73.6.98]
Feb  1 10:54:48 myhostname postfix/smtpd[3857]: B5D80794CE4: client=ipssoaa5.miniserver.com[77.73.6.98]
Feb  1 10:54:48 myhostname postfix/cleanup[3861]: B5D80794CE4: message-id=<1460312650.1173108.1296550436345.JavaMail.tomcat@ipssoaa5.miniserver.com>
Feb  1 10:54:48 myhostname postfix/qmgr[13605]: B5D80794CE4: from=<bounce_a_b_c_d@bounce.ipss.fi>, size=10441, nrcpt=1 (queue active)
Feb  1 10:54:48 myhostname postfix/smtpd[3857]: disconnect from ipssoaa5.miniserver.com[77.73.6.98]
Feb  1 10:54:48 myhostname postfix/local[3862]: B5D80794CE4: to=<spam@myhostname>, orig_to=<some.address@atro.fi>, relay=local, delay=0.27, delays=0.21/0.01/0/0.05, dsn=2.0.0, status=sent (delivered to command: /usr/bin/procmail)

Postmaster and abuse at {memset.com, miniserver.com, ipss.fi} were informed on February 8, 2011, that atro.fi had changed owners and needed to be removed from all lists. Abuse at ipss.fi bounced as “no such user”. All the rest were eventually delivered (have mail logs to prove). No answer, no reaction.

On June 1, 2011, isteer.net sent UBE on behalf of huuto.net, a Finnish online auction site. This led to the mail to abuse and postmaster that failed on June 2. The failure note has been forwarded to the CEO’s personal address, to postmaster, and abuse at ipss.fi. As in February, postmaster was accepted, abuse rejected. The CEO’s address accepted the mail, too.

Sometime after that, I seem to have set up a policy rule to reject their messages at HELO level. Cue Postfix log snippet:

Jul  5 09:29:16 myhostname postfix/smtpd[28222]: connect from bounce.isteer.net[77.73.6.98]
Jul  5 09:29:16 myhostname postfix/smtpd[28222]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<some.address@atro.fi> proto=ESMTP helo=<bounce.isteer.net>
Jul  5 09:29:16 myhostname postfix/smtpd[28222]: disconnect from bounce.isteer.net[77.73.6.98]

This is obviously a non-issue to them:

Aug 19 11:00:28 myhostname postfix/smtpd[22477]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<some.address@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

Aug 29 18:18:03 myhostname postfix/smtpd[25169]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<some.address@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

Sep 16 16:27:09 myhostname postfix/smtpd[18989]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<some.address@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

Sep 30 09:54:00 myhostname postfix/smtpd[364]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<some.address@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

Oct 13 10:30:14 myhostname postfix/smtpd[5859]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<some.address@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

Earlier this week, I had a glitch on my main mail server and a secondary was accepting mail, without all of the usual rules in place. Hence, some mail was delivered:

Oct 21 20:45:59 otherhost postfix/smtpd[25179]: connect from bounce.isteer.net[77.73.6.98]
Oct 21 20:45:59 otherhost postfix/smtpd[25179]: D94D815FAC8: client=bounce.isteer.net[77.73.6.98]
Oct 21 20:45:59 otherhost postfix/cleanup[25183]: D94D815FAC8: message-id=<361998890.577489.1319218855230.JavaMail.tomcat@ipssoaa5.miniserver.com>
Oct 21 20:46:00 otherhost postfix/qmgr[23110]: D94D815FAC8: from=<bounce_a_b_c_d@bounce.isteer.net>, size=12223, nrcpt=1 (queue active)
Oct 21 20:46:00 otherhost postfix/smtpd[25179]: disconnect from bounce.isteer.net[77.73.6.98]
Oct 21 20:46:00 otherhost postfix/local[25184]: D94D815FAC8: to=<spam@mydomain>, orig_to=<some.address@atro.fi>, relay=local, delay=0.27, delays=0.22/0.01/0/0.04, dsn=2.0.0, status=sent (delivered to mailbox)
Oct 21 20:46:00 otherhost postfix/cleanup[25183]: 1700D15FAC9: message-id=<361998890.577489.1319218855230.JavaMail.tomcat@ipssoaa5.miniserver.com>
Oct 21 20:46:00 otherhost postfix/qmgr[23110]: 1700D15FAC9: from=<bounce_a_b_c_d@bounce.isteer.net>, size=12367, nrcpt=1 (queue active)
Oct 21 20:46:00 otherhost postfix/local[25184]: D94D815FAC8: to=<some.address@atro.fi>, relay=local, delay=0.3, delays=0.22/0.01/0/0.07, dsn=2.0.0, status=sent (forwarded as 1700D15FAC9)
Oct 21 20:46:00 otherhost postfix/qmgr[23110]: D94D815FAC8: removed

And here, finally, are the spam headers for the most recent entry:

From bounce_a_b_c_d@bounce.isteer.net  Fri Oct 21 20:46:00 2011
Return-Path: <bounce_a_b_c_d@bounce.isteer.net>
Received: from bounce.isteer.net (bounce.isteer.net [77.73.6.98])
by mail.atrotossavainen.fi (Postfix) with ESMTP id D94D815FAC8
for <some.address@atro.fi>; Fri, 21 Oct 2011 20:45:59 +0300 (EEST)
Received: from ipssoaa5.miniserver.com (localhost [127.0.0.1])
by bounce.isteer.net (Postfix) with ESMTP id 3905D53CE3E
for <some.address@atro.fi>; Fri, 21 Oct 2011 20:40:55 +0300 (EEST)
Date: Fri, 21 Oct 2011 20:40:55 +0300 (EEST)
From: "Keltainen pörssi" <kepo.palaute@sanoma.fi>
To: some.address@atro.fi
Message-ID: <361998890.577489.1319218855230.JavaMail.tomcat@ipssoaa5.miniserver.com>
Subject: Kodinkonepaketti tonnilla!
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_577488_190403560.1319218855228"
Status: RO
Content-Length: 11263
Lines: 178

Keltainen Pörssi is a “submit your ad for free” kind of paper. Sanoma.fi is Sanoma News Oy, Finland’s largest newspaper publisher.

12 Responses to Isteer.net: No bounce processing, no RFC2142/5321 required role addresses, no respect for opt-out

  1. This is disturbing. I checked our spamtrap feeds and found nothing from these spammers, but we do not have good spamtrap feeds from all parts of the world. You use Postfix. Did you configure it to bounce email to all email addresses but your own after you registered it?

    • (It’s not surprising you don’t see anything from anybody who, if I understand correctly, operates only in Finland. I can’t guarantee these two are the only ops for which isteer.net provide services – I would be surprised if that was the case – but the only occurrences I’ve had so far have been to addresses of people (that is, not business or role ones) that could quite conceivably have signed up with huuto.net (our local ebay) or Keltainen Pörssi (“submit your ad for free” paper and online service).)

      To answer your question re bouncing: effectively yes, but I didn’t explicitly have to do that – as I didn’t configure catchall, I was by default rejecting mail addressed to anything that I hadn’t configured.

      As described in the domain’s front page, after I registered the domain and set up a mail server on December 29, 2009, I started seeing mail delivery attempts to the addresses of the previous owners. I allowed them to go 550 5.1.1 No such user for a while. I don’t think I’ve spotted anything from this sender during that time, as when I spotted such entries in the mail logs I used to send mails to the legit-looking ones among the senders who made these attempts to say they’re doing this and I’d appreciate it if they removed the domain from their lists as it has changed owners.

  2. I’m no expert on opt-out; I never opt-out of anything I didn’t request. But it seems reasonable that, upon notification that a domain has changed hands, managers of bulk email lists (be they a major ESP or a local church) would remove any email addresses at that domain from their lists. After all, those email addresses no longer exist, so whatever the mailing list is mailing won’t be seen by anybody who is interested.

    From what you said elsewhere, Atro, Finnish law requires opt-out, but also requires that the companies respect opt-out — is this correct? if so, then the bulk mailers that you mention are failing to respect opt-out unless you jump through their automated hoops for every email address that they’re hitting on your server. That *stinks*.

    I can’t predict what Spamhaus’ or another blacklist’s attitude would be toward this, but if I were not deliberately collecting spam, I’d drop their IPs in my firewall and be done with them. :/

    • In principle, I never opt out of anything I didn’t request either. My whole point is in your first paragraph above.

      But both repurposing atro.fi and providing an email address for the business in the Business Information System are sort of an experiment. In the case of the former, it is expected that there will be bulk/commercial email to addresses whose current owner did not request it, but it is impossible to say whether the previous tenants did. In the latter case, it is expected that there will be legal UCE to the business address, and this is useful in order to find out whether any particular sender respects opt out (and simply to enumerate the senders in order to remember who not to do any business with).

      Finnish law regarding electronic direct marketing is based on opt-in for individuals, opt-out for businesses. See the English translation of the Act on the Protection of Privacy in Electronic Communications Sections 26 and 27. Section 28 deals with how marketing must be clearly recognizable as such and how a means of opting out must be provided.

      In my opinion, the “in toto” obligations here (w.r.t. the ownership change of atro.fi) stem more from the Personal Data Act, Section 9, Paragraph 2, which requires that no erroneous, incomplete or outdated personal data be processed.

  3. We are currently fixing the issue and adding those bounce and postmaster addresses. Technically speaking customers should not get more than three bounced emails but since we are providing services to our customers we are not fully controlling email traffic. Sometimes our customers are using old address list. Each mail has opt-out possibility. We are also in progress to implement DKIM.

    • Pirkka, thanks for participating. As you can see in other posts and discussions on this blog, we encourage ESP participation. We want to hear back from you folks.

      What I don’t get is:

      1) you’ve been in business for over 10 years yet “abuse” and “postmaster” come as surprises to you?

      2) you don’t listen to removal requests sent to you? (cf postmaster mail February 8; mail to your CEO Terho on June 1)

      3) you don’t take notice of bounces? (As you can see, you got six, and would have been getting more had I not had a glitch. It also seems likely that if you’ve been handling bulk emailing for Keltainen Pörssi and Huuto.net for any length of time, you would have tried to mail these folks, whose addresses must have entered those lists prior to August 31, 2009, on a previous occasion as well, and any time after September 1, 2009, you would have received some sort of a bounce for them.)

      You say that each mail has opt-out possibility, but what I’m telling you is not just that address X wants to opt out of customer Y’s mailing list, but that every address at a domain that has changed hands must be omitted from the mailing lists of any and all of your customers and that I’d appreciate it if you made the presence of addresses at that domain a quality control item with regard to lists your customers bring in (much like I’d assume you would take a closer look at customers trying to bulk to RFC required role addresses). I would be surprised if you disagreed with me that requiring me to do this piecemeal was unreasonable – particularly as you and your customers have a duty as per Personal Data Act, Section 9 Paragraph 2, not to process erroneous or outdated personal data.

      • What I really, really don’t get is that this is still going on as of Dec 8, nearly two months after the conversation above.

        Dec 8 12:58:30 myhost postfix/smtpd[11322]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<x@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

        Nov 24 13:42:53 myhost postfix/smtpd[18042]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<x@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

        Nov 18 14:51:45 myhost postfix/smtpd[15013]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<x@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

        Nov 15 16:27:36 myhost postfix/smtpd[18675]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<x@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

        Nov 10 12:52:22 myhost postfix/smtpd[4703]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<x@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

        Nov 4 12:29:03 myhost postfix/smtpd[7993]: NOQUEUE: reject: RCPT from bounce.isteer.net[77.73.6.98]: 554 5.7.1 <bounce.isteer.net>: Helo command rejected: See http://www.rfc-ignorant.org/; from=<bounce_a_b_c_d@bounce.isteer.net> to=<x@atro.fi> proto=ESMTP helo=<bounce.isteer.net>

  4. Dum de dum. I spoke with Pirkka on private email on Friday, Dec 9, 2011. I also said I’d be removing the REJECT from my MTA configuration to see if I was getting any more… And sure enough, I am.

    From bounce_a_b_c_d@bounce.isteer.net Mon Dec 12 13:46:28 2011
    Return-Path: <bounce_a_b_c_d@bounce.isteer.net>
    Received: from bounce.isteer.net (bounce.isteer.net [77.73.6.98])
    by mail.atrotossavainen.fi (Postfix) with ESMTP id 8F17C7CC198
    for <x@atro.fi>; Mon, 12 Dec 2011 13:46:28 +0200 (EET)
    Received: from ipssoaa5.miniserver.com (localhost [127.0.0.1])
    by bounce.isteer.net (Postfix) with ESMTP id 0E94253CDB6
    for <x@atro.fi>; Mon, 12 Dec 2011 13:45:38 +0200 (EET)
    Date: Mon, 12 Dec 2011 13:45:38 +0200 (EET)
    From: “Keltainen pörssi”
    To: x@atro.fi
    Message-ID: <894002084.190369.1323690338056.JavaMail.tomcat@ipssoaa5.miniserver.com>
    Subject: Vastaa ja voita 55
    MIME-Version: 1.0
    Content-Type: multipart/alternative;
    boundary=”—-=_Part_190368_1659698881.1323690338053″
    Content-Length: 8678
    Lines: 175

  5. Duh.

    From bounce_a_b_c_d@bounce.isteer.net Fri Dec 16 12:44:43 2011
    Return-Path: <bounce_a_b_c_d@bounce.isteer.net>
    Received: from bounce.isteer.net (bounce.isteer.net [77.73.6.98])
    by mail.atrotossavainen.fi (Postfix) with ESMTP id EB3377CC198
    for <x@atro.fi>; Fri, 16 Dec 2011 12:44:42 +0200 (EET)
    Received: from bounce.isteer.net (localhost [127.0.0.1])
    by bounce.isteer.net (Postfix) with ESMTP id 8FD4F53DA7C
    for <@atro.fi>; Fri, 16 Dec 2011 12:44:39 +0200 (EET)
    Date: Fri, 16 Dec 2011 12:44:39 +0200 (EET)
    From: “Keltainen pörssi” <kepo.palaute@sanoma.fi>
    To: x@atro.fi
    Message-ID: <1025168987.199215.1324032279585.JavaMail.tomcat@bounce.isteer.net>
    Subject: =?ISO-8859-1?Q?Vastaa_ja_voita_55″_Samsung_LED-TV_sek=E4_m?=
    =?ISO-8859-1?Q?uita_huikeita_palkintoja_jouluksi_kotiin!?=
    MIME-Version: 1.0
    Content-Type: multipart/alternative;
    boundary=”—-=_Part_199214_942388116.1324032279583″

  6. As of Dec 21, they’re still at it. I should get around to making a new post.

  7. Pingback: Isteer.net » MainSleaze

  8. Pingback: Keltainen Pörssi and isteer.net keep pushing it » MainSleaze

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Go back to top