Re: [mailop] syncaor/centurylink/hughes contact?

2021-08-24 Thread Udeme Ukutt via mailop
W00t! YW On Tue, Aug 24, 2021 at 10:01 PM Russell Clemings wrote: > Yes, thanks. I got other replies as well and will follow up if needed. > > On Tue, Aug 24, 2021 at 6:55 PM Udeme Ukutt wrote: > >> Russell, I replied you off list. >> >> - Udeme >> >> On Tue, Aug 24, 2021 at 8:14 PM Russell Cle

Re: [mailop] syncaor/centurylink/hughes contact?

2021-08-24 Thread Scott Undercofler via mailop
Nevermind, found it in splunk. 174.138.31.223 is the issue, as its included in your emails that are getting marked phish because of massive phish traffic from that ip. I submitted it for mitigation. Yes, thanks. I got other replies as well and will follow up if needed. On Tue, Aug 24,

Re: [mailop] syncaor/centurylink/hughes contact?

2021-08-24 Thread Russell Clemings via mailop
Yes, thanks. I got other replies as well and will follow up if needed. On Tue, Aug 24, 2021 at 6:55 PM Udeme Ukutt wrote: > Russell, I replied you off list. > > - Udeme > > On Tue, Aug 24, 2021 at 8:14 PM Russell Clemings via mailop < > mailop@mailop.org> wrote: > >> Does anyone on this list hav

Re: [mailop] [NOTICE] GMail allowing raw Bcc headers in emails to exit their infrastructure..

2021-08-24 Thread Philip Paeps via mailop
On 2021-08-25 08:07:02 (+0800), Michael Peddemors via mailop wrote: On 2021-08-24 4:44 p.m., Brandon Long wrote: See the second possible implementations specified in https://datatracker.ietf.org/doc/html/rfc5322#section-3.6.3 Learn

[mailop] syncaor/centurylink/hughes contact?

2021-08-24 Thread Russell Clemings via mailop
Does anyone on this list have a contact for Synacor, or at least one of the ISPs that appear to use them (centurylink.net, hughes.net, wowway.com, tds.net, q.com, possibly others)? We're seeing false-positive bounces ("554 5.7.1 [VI-1] Message blocked due to spam content in the message") from each

[mailop] Outlook 5.7.1 block list sendersupport ignore ticket responses

2021-08-24 Thread Matt Corallo via mailop
We had a mistake in a config which resulted in some user From:s on other domains and should have been relayed through user-configured SMTP relays instead going out directly. Config persisted for all of a few minutes, which is no problem for other providers, but did result in Outlook completely bl

Re: [mailop] Microsoft RDNS issues

2021-08-24 Thread Al Iverson via mailop
Confirmed, seeing it here as well. https://xnnd.com/dns.cgi?t=a&d=mail-eopbgr660111.outbound.protection.outlook.com.&m=yes (hit reload a couple times, you'll get different results, intermittent servfails. Trying it this way is interesting: https://xnnd.com/dns.cgi?t=a&d=mail-eopbgr660111.outbound.

[mailop] [REQUEST] Anyone know anything about recent compromise, StreamHub equipment?

2021-08-24 Thread Michael Peddemors via mailop
Noticed a larger than normal amount of authentication attacks, launched from systems that appear to be 'StreamHub' systems.. The AUTH attacks are reminiscent of other compromised GPON equipment attacks, but this looks new(er) or at least the volume jumped greatly. Standard password spraying a

Re: [mailop] Microsoft RDNS issues

2021-08-24 Thread Nitin Agarwal via mailop
We're seeing this as well. Here are some details/lookups on a sample Office 365 ip: https://www.misk.com/tools/#dns/40.107.66.111 Reverse dns is fine, forward lookup fails intermittently due to a nameserver referral loop: https://www.misk.com/tools/#dns/mail-eopbgr660111.outbound.protection.outl

Re: [mailop] DMARC: Anyone using pct=n with n !=0 and n !=100?

2021-08-24 Thread A. Schulze via mailop
Am 23.08.2021 um 19:26 schrieb John R Levine: yes, I mean the daily aggregated reports, we review them at all once a month I'm confused.  Since the pct doesn't affect the reports, what's the point? Once you get the number of failures low enough, just set pct=100 and be done with it. sorry,