Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-31 Thread Slavko via mailop
Dňa 31. mája 2024 15:35:36 UTC používateľ Alessandro Vesely via mailop napísal: >Lots of queries, aren't they? I only use Smpamhaus zen and DNSWL for >whitelisting, for receiving SMTP. My own RBL blocks via iptables. Note: my MSA is separated from MX, but both use the same (caching) DNS serv

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-31 Thread Alessandro Vesely via mailop
On Fri 31/May/2024 14:59:24 +0200 Slavko via mailop wrote: Dňa 31. 5. o 11:51 Alessandro Vesely via mailop napísal(a): What RBLs do you configure? Beside my own RBLs i use DROP & AuthBL from SpamHaus, BIP from virusfree.cz, and multiple codes from dronebl.org. They are queried in paralel, t

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-31 Thread Slavko via mailop
Dňa 31. 5. o 11:51 Alessandro Vesely via mailop napísal(a): > What RBLs do you configure? Beside my own RBLs i use DROP & AuthBL from SpamHaus, BIP from virusfree.cz, and multiple codes from dronebl.org. They are queried in paralel, thus count doesn't have big inpact. But rejects based on RBL ar

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-31 Thread Alessandro Vesely via mailop
On Thu 30/May/2024 23:12:17 +0200 Slavko via mailop wrote: Dňa 30. mája 2024 19:56:01 UTC používateľ Michael Peddemors via mailop napísal: However, it isn't as simple as blocking every IP that bangs on your door. If you block large CGNAT IP's for instance, one compromised IoT device behind

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Slavko via mailop
Dňa 30. mája 2024 19:56:01 UTC používateľ Michael Peddemors via mailop napísal: >However, it isn't as simple as blocking every IP that bangs on your door. If >you block large CGNAT IP's for instance, one compromised IoT device behind >that IP can stop hundreds of legitimate users. Yes, that

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Jarland Donnell via mailop
Possibly valuable attachments: - We saw an increase in compromised email accounts sending Comcast phishing emails which actually contained HTML that pulled valid Comcast assets into the emails. To the point that we have halted all outgoing mail containing those assets. This might correlate to

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Michael Peddemors via mailop
Great that you want/willing to share.. However, it isn't as simple as blocking every IP that bangs on your door. If you block large CGNAT IP's for instance, one compromised IoT device behind that IP can stop hundreds of legitimate users. Think about the Airports' WIFI.. Coffee Shops.. or Dyn

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Slavko via mailop
Dňa 30. mája 2024 18:23:25 UTC používateľ Michael Peddemors via mailop napísal: >I am sure there are many others that are dedicated to strictly AUTHentication >abuse.. The key is to be able to do the check at all levels of authentication, >whether by using an RBL, or static lists.. I hope, th

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Michael Peddemors via mailop
On 2024-05-30 10:46, Richard Laager via mailop wrote: On May 30, 2024, at 12:35, Michael Peddemors via mailop wrote: They do know there is RBL's that list known abusive BEC Attackers? I’m new to the list (though not email admin). What RBL are you saying I should be looking at? I already u

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Richard Laager via mailop
> On May 30, 2024, at 12:35, Michael Peddemors via mailop > wrote: > > They do know there is RBL's that list known abusive BEC Attackers? I’m new to the list (though not email admin). What RBL are you saying I should be looking at? I already use SpamHaus’s various lists and SpamCop. Thanks!

Re: [mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Rob McEwen via mailop
and implementation matures. Rob McEwen, invaluement -- Original Message -- From "Michael Peddemors via mailop" To mailop@mailop.org Date 5/30/2024 1:24:07 PM Subject [mailop] [STATE OF THE UNION] Tales from the Trenches.. Both life and Business have been very active, so

[mailop] [STATE OF THE UNION] Tales from the Trenches..

2024-05-30 Thread Michael Peddemors via mailop
Both life and Business have been very active, so it's been a bit since I posted one of these.. It's about time again.. * SendGrid continues to allow the same common threats from escaping * Increase in threat actors from Thailand/Vietnam region, but probably proxies for Chinese actors * Digital