We are currently receiving lots of password phishing mails with envelope
sender and From: header
<a href="mailto: ... at charterinternet dot com"> ... at charterinternet dot com</a> and Reply-To:
<a href="mailto: ... at live dot com"> ... at live dot com</a>.
The connecting mail servers
que41.charter.net[209.225.8.24]
que51.charter.net[209.225.8.25]
do apparently *not* stop re-connecting after receiving REJECT (554)
errors, but keep coming back with the same sender-recipient pairs.
Regards,
wolfgang