Re: [mailop] Strange mail delivery from microsoft

2023-06-18 Thread Hans-Martin Mosner via mailop
Am 18.06.23 um 18:53 schrieb Klaus Ethgen via mailop: Hi, I have tighten my firewall a bit and seen many attacks from Microsoft (40.92.0.0/16). Attacks or mail delivery attempts? They contact once from a IP and then never again. If I greylist them, the will try to deliver from a different addr

Re: [mailop] Strange mail delivery from microsoft

2023-06-18 Thread Hans-Martin Mosner via mailop
Am 19.06.23 um 06:36 schrieb Klaus Ethgen via mailop: I have some update.. Greylisting was not the problem I had/have with microsoft. Your original mail sounded a little different. However, upon re-reading it is possible that you activated greylisting in response to the previous perceived attac

Re: [mailop] SendGrid is deleting your mail

2023-06-22 Thread Hans-Martin Mosner via mailop
Am 22.06.23 um 06:52 schrieb Matt Harris via mailop: On Wed, Jun 21, 2023 at 6:11 PM Sebastian Nielsen via mailop wrote: >>The RFC forbids doing that, and I argued against it The RFC and reality is two different things. If a client don't want to retry, I think they are free to cho

[mailop] SPF +all considered harmful

2023-07-08 Thread Hans-Martin Mosner via mailop
Most likely none of you would consider adding +all to an SPF record a smart move, here's another reason why you shouldn't do it: Google cloud services are being used to spam (ongoing for a long time, Google doesn't seem to care). What I noticed today is that the spammer is using domains with S

Re: [mailop] Guide for setting up a mail server ?

2023-07-13 Thread Hans-Martin Mosner via mailop
Has anyone on this list tried forwarding (e.g. for ex-employees) via attachment? The original message would be kept intact, while the outer message clearly originates with the forwarding agent who may even add a human readable reminder to the addressee to let the sender know about the changed a

Re: [mailop] spamhaus false positive ?

2023-08-19 Thread Hans-Martin Mosner via mailop
Am 19.08.23 um 10:43 schrieb Pascal HOARAU via mailop: Hello, Since this night (French time) a lot of companies are blacklisted by spamhaus, mostly transactional IPs. Do you have the same issue and any info ? Regards, Pascal The spamhaus rejections that I see look all justified. Maybe you

[mailop] Noticeable increase of spam emanating from Colocrossing?

2023-10-02 Thread Hans-Martin Mosner via mailop
Hi, does anybody else see a noticeable increase of spam from Colocrossing hosted IPs? I don't have hard data but my gut feeling is that the number of attempts have increased by a significant amount during the few weeks. Cheers, Hans-Martin ___ mailop

Re: [mailop] belgacom.be / skynet.be - massing phishing

2023-10-13 Thread Hans-Martin Mosner via mailop
Am 13.10.23 um 18:30 schrieb Mary via mailop: Hello everyone, Anyone from belgacom.be notice massive amounts of phishing with/from skynet.be addresses? I've tried to report them without success. Posted on spamcop.net in case anyone would notice, again without success. No, they don't notice,

Re: [mailop] Success MiTM attack

2023-10-22 Thread Hans-Martin Mosner via mailop
Am 22.10.23 um 12:23 schrieb Paul Menzel via mailop: It was interesting and surprising to me, as the common perception is, that SSL certificates protect against MiTM attacks as it should provide authenticity. The weak point of SSL certificates is that clients are willing to accept new certs fo

Re: [mailop] salesforce phishing emails

2023-11-29 Thread Hans-Martin Mosner via mailop
Am 28.11.23 um 11:54 schrieb Mary via mailop: Dear salesforce, Please stop your clients from sending Facebook phishing emails. I've been asking them something like that by way of abuse reports since end of September, to no avail. They don't seem to care. Sadly, they host legitimate customer

Re: [mailop] Incoming spam from outlook.com

2023-12-15 Thread Hans-Martin Mosner via mailop
Am 15.12.23 um 14:49 schrieb L. Mark Stone via mailop: We too are seeing high volumes of such email. Historically, we have avoided deploying greylisting*, but are curious if greylisting would block these emails? Could anyone who is doing greylisting comment on whether these garbage emails are

Re: [mailop] Samsung and SIZE

2024-01-14 Thread Hans-Martin Mosner via mailop
Am 15.01.24 um 07:54 schrieb Sebastian Nielsen via mailop: That header is supposed to be attached by the originating MUA, and I don't *think* transit MTAs are permitted to rewrite it... Problem is, that when MUA or first MTA has a incorrect date set, the email comes like last in inbox... hav

Re: [mailop] Anyone else noticing an increase in spam from Office365 distribution lists?

2024-01-17 Thread Hans-Martin Mosner via mailop
Am 17.01.24 um 15:20 schrieb Paul Menzel via mailop: With this in mind, did somebody compile a block list yet? Or should I just create a whitelist? A block list does not make sense, as new domains are added continuously. It's just too simple. I've had good experience with a whitelist, but tha

Re: [mailop] Anyone else noticing an increase in spam from Office365 distribution lists?

2024-01-18 Thread Hans-Martin Mosner via mailop
Am 17.01.24 um 15:35 schrieb Hans-Martin Mosner via mailop: Am 17.01.24 um 15:20 schrieb Paul Menzel via mailop: With this in mind, did somebody compile a block list yet? Or should I just create a whitelist? A block list does not make sense, as new domains are added continuously. It's

[mailop] Extortion spam from OVH-hosted *.sbs domains

2024-01-24 Thread Hans-Martin Mosner via mailop
Tonight we received a huge wave of extortion spams from OVH hosted domains trying to get bitcoin payments. The senders claim that recipients watched child porn. This is the final straw for me to add a rule to reject all mail traffic from OVH until the sender is whitelisted. OVH is completely un

Re: [mailop] Extortion spam from OVH-hosted *.sbs domains

2024-01-26 Thread Hans-Martin Mosner via mailop
Am 26.01.24 um 09:42 schrieb Simon Bressier via mailop: Hi all, FYI Hans-Martin, I reached out to ovh team yesterday night to push your message, seems your abuse report has been processed by the proper team. No idea if they answered you, but at least, they have handled the report, and probabl

Re: [mailop] Extortion spam from OVH-hosted *.sbs domains

2024-01-27 Thread Hans-Martin Mosner via mailop
Am 26.01.24 um 09:42 schrieb Simon Bressier via mailop: Hi all, FYI Hans-Martin, I reached out to ovh team yesterday night to push your message, seems your abuse report has been processed by the proper team. No idea if they answered you, but at least, they have handled the report, and probably

Re: [mailop] Ooops - sorry

2024-02-02 Thread Hans-Martin Mosner via mailop
Am 02.02.24 um 04:03 schrieb Lou Katz via mailop: Wound up way back in my archive and responded to an old, dead issue. If only the issue were as dead as it is old... SPF is a PITA that stays. :-) Hans-Martin ___ mailop mailing list mailop@mailop.or

Re: [mailop] problem setting up open-dmarc

2024-02-09 Thread Hans-Martin Mosner via mailop
Am 09.02.24 um 16:20 schrieb Gellner, Oliver via mailop: A not really serious reply: I'm interested to learn how I can get amused by looking at XML data, this would greatly improve my professional life. Until now I have been more in the state of wanting to jump out the window when I see DMARC re

[mailop] Outgoing Spam from Microsoft IPs

2024-02-13 Thread Hans-Martin Mosner via mailop
We've been seeing runs of spam mails from Microsoft IP addresses without reverse DNS (possibly cloud servers). One is sending with addresses , starting on February 8. The other (same or different spammer?) uses and started just yesterday. Have others seen these? Is there some way to identify

Re: [mailop] Outgoing Spam from Microsoft IPs

2024-02-16 Thread Hans-Martin Mosner via mailop
Am 16.02.24 um 03:37 schrieb Matt Palmer via mailop: Although I must say that without reverse DNS would seem to be the easier blocking option -- when was the last time you saw legitimate mail from an IP without rDNS? - Matt We do that, with some exceptions, as we indeed get some legitimate

Re: [mailop] One click unsubscribe in mailing list messages

2024-02-23 Thread Hans-Martin Mosner via mailop
Am 24.02.24 um 00:12 schrieb Mark Fletcher via mailop: On Fri, Feb 23, 2024 at 3:09 PM Jay Hennigan via mailop wrote: There are many systems that scan links in email and falsely unsubscribe. I'd make it two-click. When clicked, have it go to a page that says: You are about to uns

Re: [mailop] One click unsubscribe in mailing list messages

2024-02-24 Thread Hans-Martin Mosner via mailop
Am 25.02.24 um 04:10 schrieb Philip Paeps via mailop: It's actually encouraging to see the web-MUAs driving improvement in this space.  Parsing List-Unsubscribe: to present a button feels like a very obvious thing to do.  It's surprising how few traditional MUAs have ever done that. Yes. I'm

Re: [mailop] Filter out emoji from email adresses

2024-03-05 Thread Hans-Martin Mosner via mailop
Am 04.03.24 um 22:40 schrieb Sebastian Nielsen via mailop: Anyone that have a general algoritm to filter out emoji from sender addresses? It's possible that the problem isn't specific to emojis but to any unicode code point in the supplementary planes (code point values above U+). Applicat

Re: [mailop] [spamhaus] de-listing requests successful, but only for a couple of days.

2024-03-15 Thread Hans-Martin Mosner via mailop
Am 15.03.24 um 09:11 schrieb Alexandre Dangreau via mailop: Hello, In fact, if you need a /64 IPv6 range you probably use the wrong service. For VPS and Public Cloud instances (PCI) the IPv6 range is shared with all the VM, so each VM (VPS or PCI) have one single IPv4 (/32) and one single IPv6

Re: [mailop] [spamhaus] de-listing requests successful, but only for a couple of days.

2024-03-17 Thread Hans-Martin Mosner via mailop
Am 17.03.24 um 04:23 schrieb Jarland Donnell via mailop: I'm gonna be "that guy" though for a minute. If there are any IPv6 only mail servers, they are hobbyists trying to prove a point. There are a ton of IPv4 only mail servers. In short, there is no benefit to sending mail over IPv6 beyond th

Re: [mailop] [spamhaus] de-listing requests successful, but only for a couple of days.

2024-03-17 Thread Hans-Martin Mosner via mailop
Am 17.03.24 um 14:05 schrieb Jaroslaw Rafa via mailop: Dnia 17.03.2024 o godz. 08:30:39 Hans-Martin Mosner via mailop pisze: does IPv6 (not exclusively though), and I've been trying to usher in the future by setting up at least dual stack on my home DSL connection (that at least works now

Re: [mailop] Phishing hosted by Cloudflare-ipfs.com / Abuse Handled by Sparkpostmail.com?

2024-05-14 Thread Hans-Martin Mosner via mailop
IPFS is a p2p file storage, so cloudflare doesn't control what content is put there, they don't even know who put it there, so it's a natural extension of their "we're not responsible, it's our customer's responsibility, but we won't tell you who that customer is" policy. I chose to reject all

Re: [mailop] salesforce phishing emails

2024-06-12 Thread Hans-Martin Mosner via mailop
Am 28.11.23 um 11:54 schrieb Mary via mailop: Dear salesforce, Please stop your clients from sending Facebook phishing emails. Sorry for digging up this old thread... I seem to have found a contact at salesforce which reads, responds and apparently reacts to reports: security -at- salesforce.

Re: [mailop] salesforce phishing emails

2024-06-12 Thread Hans-Martin Mosner via mailop
Am 12.06.24 um 18:04 schrieb Anne P. Mitchell, Esq. via mailop: I've also always found abuse@ to be responsive there, and it's peopled by a real person, who gives real responses (at least that was the case as recently as 12/21/23. That's interesting, I've been sending lots of abuse reports to

Re: [mailop] Massive mail flooding from gmail

2024-07-05 Thread Hans-Martin Mosner via mailop
Am 05.07.24 um 09:24 schrieb Gerald Vogt via mailop: Hi, since June 28th we are flooded with thousands of emails from various gmail accounts going to one of our list addresses. We have already reported some of them at https://support.google.com/mail/contact/abuse but it didn't really helped.

Re: [mailop] [E] Re: AT&T Block

2024-07-07 Thread Hans-Martin Mosner via mailop
Am 07.07.24 um 14:54 schrieb Alessandro Vesely via mailop: (a bit of understandable ranting) Is that anyhow related to democracy? No. But mail interoperation isn't govered by democracy. Idealized history: Initially (when there were a few dozen mailhosts), there was mutual understanding that e

Re: [mailop] Domains discrimination

2024-07-11 Thread Hans-Martin Mosner via mailop
Am 11.07.24 um 21:20 schrieb John Levine via mailop: It appears that Ralph Seichter via mailop said: Personally, I don't factor the price of domains into the block/pass decisions, You should. There is a very strong correlation between cheap and bad. And there are very rational reasons for t

[mailop] Gmail spammer regex - may be useful if you're affected

2024-08-16 Thread Hans-Martin Mosner via mailop
Hi folks, for a while now I've been seeing spam mail from gmail addresses matching this firstname/lastname regex: /[a-z]{3}(anthony|brian|charles|christopher|daniel|david|donald|edward|george|james|jason|jeff|john|joseph|kenneth|kevin|mark|michael|paul|richard|robert|ronald|steven|thomas|willi

[mailop] Ideas for possible content for FAQ: "Best Practices for running a mail server"

2020-02-16 Thread Hans-Martin Mosner via mailop
Some ideas from running small to medium mail servers for a long time. Many of you will probably have more extensive experience and advice, but this is just a minimal list off the top of my head to get something for a start: 1. Don't hide behind anonymity. Mail server domain whois should have an

Re: [mailop] Ideas for possible content for FAQ: "Best Practices for running a mail server"

2020-02-17 Thread Hans-Martin Mosner via mailop
Am 16.02.2020 22:15, schrieb Jaroslaw Rafa via mailop: Dnia 16.02.2020 o godz. 15:21:34 Hans-Martin Mosner via mailop pisze: 1. Don't hide behind anonymity. Mail server domain whois should have an identifiable registrant organization, there [...] 8. (opinionated) Don' use SPF, i

Re: [mailop] Ideas for possible content for FAQ: "Best Practices for running a mail server"

2020-02-17 Thread Hans-Martin Mosner via mailop
Am 17.02.20 um 19:21 schrieb Alessandro Vesely via mailop: > On Sun 16/Feb/2020 15:21:34 +0100 Hans-Martin Mosner via mailop wrote: >> (opinionated) Don' use SPF, it's broken by design. > > I don't think that a FAQ starting with such opinionated entries is going &

Re: [mailop] Opinions? Email Abuse over TOR Network? (spamtraps)

2020-02-20 Thread Hans-Martin Mosner via mailop
Am 20.02.2020 11:02, schrieb Benoit Panizzon via mailop: But I guess, just silently blacklisting Tor exist nodes and not sending a ARF report to the ISP could be an option to solve that issue. This is probably a reasonable way of dealing with the problem. TOR exit nodes are somewhat like dyna

Re: [mailop] Sendgrid strikes again; zendesk, actually

2020-02-25 Thread Hans-Martin Mosner via mailop
Am 25.02.20 um 19:12 schrieb Alessandro Vesely via mailop: > On Tue 25/Feb/2020 16:30:29 +0100 Luke via mailop wrote: >> Some more detail on this would be helpful. > On Mon, 24 Feb 2020 11:35:08 +0100 I received the first abusive message, with > subject: "I have videos of you masturbating" > sent b

Re: [mailop] Ideas for possible content for FAQ: "Best Practices for running a mail server"

2020-02-27 Thread Hans-Martin Mosner via mailop
Am 26.02.2020 22:35, schrieb Michael Peddemors via mailop: ... * Unsubscribe pages/urls * Domain Pages I'm somewhat unsure about this one. Although nowadays the WWW *is* the internet for many people, running a mail server and running a web presence are two different things, and it should be a

Re: [mailop] Any idea who wrote 'Spam Lawsuits: What's the Worst that Can Happen?' ?

2020-02-27 Thread Hans-Martin Mosner via mailop
Am 26.02.2020 22:59, schrieb Tom Kulzer via mailop: http://static.mailchimp.com/www/guides/spam-lawsuits/package/spam-lawsuits.pdf Well, it looks like their server is overwhelmed by the millions of mailop readers trying to fetch that document all at once: An error occurred while processing

[mailop] Spam from no-re...@sharepointonline.com via outbound.protection.outlook.com

2020-03-15 Thread Hans-Martin Mosner via mailop
Hello, for a number of days, "no-re...@sharepointonline.com" is sending mails to non-existent addresses (many of which are quite certainly imported from some circulating address list, as we have seen them being targeted for years). Mar 15 11:58:49 mail postfix/smtpd[19571]: NOQUEUE: hold: RCPT

Re: [mailop] Spam from no-re...@sharepointonline.com via outbound.protection.outlook.com

2020-03-22 Thread Hans-Martin Mosner via mailop
Am 22.03.20 um 08:37 schrieb Suresh Ramasubramanian via mailop: > > This is abuse of free trial accounts of office 365, and the document sharing > that sharepoint allows.   Create a > document with porn spam text and share it, with a porn spam spiel, with a big > list of spam recipients. > >   >

[mailop] Orange.es - anybody home?

2020-05-21 Thread Hans-Martin Mosner via mailop
Hello, I've tried to report some spam to orange.es, this report is stuck in our outgoing queue: (host inc.wanadoo.es[62.36.20.20] refused to talk to me: 451 Temporary local problem - please try later) ab...@orange.es Manual telnet session from my home I

Re: [mailop] SPF strict / DMARC interaction / "big" provider behavior...

2020-06-17 Thread Hans-Martin Mosner via mailop
Am 17.06.20 um 21:15 schrieb vom513 via mailop: > I know the ultimate answer is “do what makes sense for me” - but I’d love > some feedback from folks here on what they consider best practice etc. Also > please help me with my understanding of SPF / DMARC interactions (especially > with regard

Re: [mailop] Ongoing Spam-OP from 'Alphainfo INC' / Garuda Mailer / GBS Industries

2020-06-22 Thread Hans-Martin Mosner via mailop
Am 22.06.20 um 17:01 schrieb Benoît Panizzon via mailop: > > Anyone else seeding those emails since about 2 Months or having any > contact to Alphainfo INC / Alphainfo Lab / gbsind.com / GBS Group ? > Alpha Infolab (AS133320) has been in my "block-unconditionally" list for ages. They host persiste

Re: [mailop] Microsoft Block list (S3150)

2020-06-29 Thread Hans-Martin Mosner via mailop
Am 29.06.2020 13:16, schrieb Laura Atkins via mailop: On the advice of their lawyers Microsoft doesn’t share that information with senders. laura Sounds a bit like Kafka's "Der Prozess". Don't tell the defendant what he's being accused of... Cheers, Hans-Martin ___

Re: [mailop] Microsoft Block list (S3150)

2020-06-29 Thread Hans-Martin Mosner via mailop
Am 29.06.20 um 16:42 schrieb Michael Rathbun via mailop: > On Mon, 29 Jun 2020 15:46:05 +0200, Hans-Martin Mosner via mailop > wrote: > >> Am 29.06.2020 13:16, schrieb Laura Atkins via mailop: >>> On the advice of their lawyers Microsoft doesn’t share that >

Re: [mailop] [EXTERNAL] Re: Microsoft Block list (S3150)

2020-06-29 Thread Hans-Martin Mosner via mailop
Am 29.06.20 um 21:30 schrieb Michael Wise via mailop: > >   > > A **VERY** strong economic argument. > >   > I know. I'm mainly venting my frustration, knowing too well that my activity won't flip a single bit in Redmond. Hoping that some organization would do the right thing because it's the rig

Re: [mailop] harassment/death threat detection/filtering/prosecution

2020-07-15 Thread Hans-Martin Mosner via mailop
This is a tricky problem. I would guess that some traditional spam-rejection mechanisms might be applicable, but there are grey areas: Rejection of mails from anonymous origins may help, but on one hand there are some (sent via hacked ordinary mailboxes) which can't technically be distinguished

Re: [mailop] OVH Bulk Mailer? Anyone know this one?

2020-08-05 Thread Hans-Martin Mosner via mailop
Unless you or your users happen to be customers of those few mostly french companies who use OVH for customer communication, blocking them is a pretty sensible thing to do. They still host spammers, they still ignore abuse reports, so nothing has changed in the last year. Cheers, Hans-Martin

Re: [mailop] OVH Bulk Mailer? Anyone know this one?

2020-08-07 Thread Hans-Martin Mosner via mailop
Am 07.08.20 um 22:54 schrieb Alain Gaudreau via mailop: > @Chris > > My vision of it is larger and includes a blacklist with the ability to > exclude and grey list certain hosts within the large blocks controlled by ovh > and the lot. I'm working on a system which may in the long run include su

Re: [mailop] OVH Bulk Mailer? Anyone know this one?

2020-08-08 Thread Hans-Martin Mosner via mailop
Am 07.08.20 um 19:14 schrieb Alain Gaudreau via mailop: > > I disagree Hans-Martin. > I sympathize with you. Constantly fighting mail blocks is certainly as tiring as constantly fighting mail abuse. > >   > > We have been using ovh for years and years and enforce strict abuse policies > on our cl

Re: [mailop] Delisting request from sendgrid customer about ip used in recent phishing campaign.

2020-08-11 Thread Hans-Martin Mosner via mailop
Am 11.08.20 um 16:53 schrieb Benoit Panizzon via mailop: > Hi List > > o1678912x138.outbound-mail.sendgrid.net [167.89.12.138] and IP under > control of sendgrid was repeatedly involved in phishing and other spam > since June. > > It ended up being blacklisted @ SWINOG. > > Now a sendgrid customers

Re: [mailop] Delisting request from sendgrid customer about ip used in recent phishing campaign.

2020-08-13 Thread Hans-Martin Mosner via mailop
Am 11.08.20 um 18:22 schrieb Len Shneyder via mailop: > Hello Benoit and Hokan, > > Thanks for pointing this out and I'm sorry you're still seeing what sounds > like a high volume of phish. I've asked our > fraud ops team to investigate this. In the future if you could send > suspicious emails to

Re: [mailop] Delisting request from sendgrid customer about ip used in recent phishing campaign.

2020-08-13 Thread Hans-Martin Mosner via mailop
Am 13.08.20 um 19:28 schrieb Al Iverson via mailop: > On Thu, Aug 13, 2020 at 11:34 AM Hans-Martin Mosner via mailop > wrote: >> Mails to abuse@ should be handled quickly without being CC'd to a VP. It's >> the abuse desks job to stop abuse ASAP. If they are un

Re: [mailop] Just how does SendGrid fail this badly?

2020-08-18 Thread Hans-Martin Mosner via mailop
It's in the envelope sender, which your mail system probably doesn't preserve when it stores mail. Traditional mbox format has it in the 'From ' line. Cheers, Hans-Martin Am 18. August 2020 20:03:46 schrieb Carl Byington via mailop : -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue,

Re: [mailop] Mailman confirmation email denial of service

2020-08-19 Thread Hans-Martin Mosner via mailop
Am 19.08.20 um 11:51 schrieb Andy Smith via mailop: > Hi, > > Not sure if this is the best place to mention this, but… > > Since yesterday I've been seeing a large number of attempted > subscriptions to all the public lists on one of my Mailman servers. > There's so far been 160 attempted subscript

Re: [mailop] Mailman confirmation email denial of service

2020-08-20 Thread Hans-Martin Mosner via mailop
After having thwarted additional attacks (thanks for the hint about SUBSCRIBE_FORM_SECRET!) I looked at our mailman logs to see if everything is quiet now, and to find patterns. Apparently the initial check was from a serbian IP address: Aug 18 10:01:55 2020 (8184) : pending mmc49...@eoopy.com 

Re: [mailop] Just how does SendGrid fail this badly?

2020-08-20 Thread Hans-Martin Mosner via mailop
Am 20.08.20 um 09:10 schrieb Benoit Panizzon via mailop: > > Return-Path: > > Does the c581 part also belong to the account id? No, it's a short hash to verify that bounces were indeed caused by mails actually sent from sendgrid. For example, and are doodle notifications sent to two different

Re: [mailop] Deutsche Telekom rejects connections because of missing "provider identification"

2020-08-27 Thread Hans-Martin Mosner via mailop
Am 26.08.20 um 19:36 schrieb flo via mailop: > Hi there > > Have any of you had any bad experiences with Deutsche Telekom lately? > They put one of my servers on their blacklist after an IP change with > the reason that I have to provide an imprint on that machine. > Have I missed something? Is thi

Re: [mailop] Deutsche Telekom rejects connections because of missing "provider identification"

2020-08-28 Thread Hans-Martin Mosner via mailop
Am 28.08.20 um 10:10 schrieb Bjoern Franke via mailop: > > and this also no guarantee for no spam. Recently I got some spam for > "dates18.com" sent via Casual Networks B.V (on > the CSA whitelist) in which even the "Imprint"-URLs lead to "Congratulations, > you confirmed your mailaddress". The

[mailop] Spam using bit.ly link shorteners, this time via Outlook

2020-09-15 Thread Hans-Martin Mosner via mailop
Hi, most have probably seen the spams containing just a bit.ly short link and names of recipient and purported sender (likely from hacked address books). They mostly came via hacked mail accounts, but now the spammer seems to have a bot creating accounts at outlook.com for this purpose. Does an

Re: [mailop] [External] Spam using bit.ly link shorteners, this time via Outlook

2020-09-16 Thread Hans-Martin Mosner via mailop
7;re getting is targeted to german users... Cheers, Hans-Martin Am 16. September 2020 10:25:00 schrieb "Kevin A. McGrail" : I have seen then and have rules for SpamAssassin that combat them. Are you using SpamAssassin? Regards, KAM On September 16, 2020 2:00:09 AM EDT, Hans-Martin Mosne

[mailop] cloudapp.azure.com?

2020-10-09 Thread Hans-Martin Mosner via mailop
Hello, do others see spam waves from cloudapp.azure.com, too? In the logs, it looks like this (anonymized) Oct  9 11:43:54 mail postfix/smtpd[19958]: NOQUEUE: reject: RCPT from ijhytgfgg-germanywestcentral12.germanywestcentral.cloudapp.azure.com[51.116.228.69]: 554 5.7.1 <>: Sender address reje

Re: [mailop] Maximum message size

2020-10-24 Thread Hans-Martin Mosner via mailop
Am 24.10.20 um 19:19 schrieb John Levine via mailop: > > FTP was swell forty years ago but it's obsolete now. Nothing, > including the user names or passwords, is encrypted, and it needs to > set up a second TCP connection for each data transfer which confuses > NATs and firewalls. > > There are be

Re: [mailop] Google bounce after accept

2020-10-30 Thread Hans-Martin Mosner via mailop
Am 30.10.20 um 08:57 schrieb Atro Tossavainen via mailop: > Why does Google bounce after accepting a message? At Google's scale, > the potential to become the world's biggest spammer simply through > backscatter is enormous. > Sadly, doing the correct thing isn't always technically possible. The m

Re: [mailop] SSL Cert and Reputation Question

2020-11-13 Thread Hans-Martin Mosner via mailop
Am 13.11.2020 15:31, schrieb Tonya Gordon via mailop: Good morning! Does anyone have any insight into the following question we received from a customer? “If we're using a wildcard SSL cert across multiple sending/bounce/tracking domain configurations, will ISPs then associate those configs tog

Re: [mailop] Contacts from Arcor on the list? Abuse of a platform on Azure occurring..

2020-11-26 Thread Hans-Martin Mosner via mailop
Am 25.11.20 um 19:28 schrieb Michael Peddemors via mailop: > Seems like Arcor.de is using a 3rd party for something, and it's email > functions are being abused.. > > Judging by the SPF record, it looks like they are intentionally using this > 3rd party service.. > >  host -t TXT arcor.de > arcor

[mailop] Effeciveness (or not) of SPF

2020-12-06 Thread Hans-Martin Mosner via mailop
Hi folks, due to its negative effects on mail forwarding I've resisted touching SPF for a long time (I know mail users should not simply forward their mail, and the effects can be mitigated with SRS, but some users simply can't be bothered to configure multiple accounts and access them properly

Re: [mailop] Effeciveness (or not) of SPF

2020-12-07 Thread Hans-Martin Mosner via mailop
Am 07.12.20 um 23:51 schrieb Thomas Walter via mailop: > > I fully agree, but gmail is a bad example, because they actually support > importing remote mailboxes with pop3 which does not require forwarding. > We never tried that, but it is an option: Well if giving The Goog all kinds of information

Re: [mailop] [FEEDBACK] Azure Spammer Activity

2020-12-08 Thread Hans-Martin Mosner via mailop
Yesterday and the day before we received such a massive wave from them that I had to temporarily block several Microsoft IPv4 ranges... Today we got a response to our abuse reports requesting that we report these to j...@office365.microsoft.com - I would've thought that within one corporation, f

Re: [mailop] open RBL and RHSBL lists these days?

2020-12-14 Thread Hans-Martin Mosner via mailop
Am 14.12.20 um 23:28 schrieb Mary via mailop: > So what is trix.bounces.google after all? google offers a spam service these > days? > They probably wouldn't call it that, but it essentially is. It's the Google Forms feedback request mechanism, where users can send requests to fill out forms to

Re: [mailop] cloudapp.azure.com?

2020-12-17 Thread Hans-Martin Mosner via mailop
Am 09.10.20 um 12:27 schrieb Hans-Martin Mosner via mailop: > Hello, > > do others see spam waves from cloudapp.azure.com, too? So, after 9 weeks, despite several abuse reports to the appropriate places, this still continues (and not a single response indicating they understand that th

Re: [mailop] Gosh, I love sendgrid

2020-12-23 Thread Hans-Martin Mosner via mailop
Am 22.12.20 um 02:56 schrieb Eric Tykwinski via mailop: > Seriously, this is probably political…  Not saying I agree, but unless it’s > spam, i.e. unwanted by your recipients, > then you just have a bunch of wack jobs as clients and keep it at that. As John has stated in his original mail, it was

Re: [mailop] problems sending mails to gmx/web.de

2020-12-28 Thread Hans-Martin Mosner via mailop
Am 28.12.20 um 11:19 schrieb Ruben Herold via mailop: > > hi, > > I have a system that runs since christmas day's in the: > > https://postmaster.gmx.net/en/error-messages?ip=185.48.106.12&c=irlim > https://postmaster.web.de/error-messages?ip=185.48.106.12&c=irlims Both links indicate rate limits.

Re: [mailop] [E] Re: IP based reporting for Yahoo feedback loop gone?

2020-12-31 Thread Hans-Martin Mosner via mailop
Am 31.12.20 um 22:07 schrieb Hal Murray via mailop: > Scott Mutter said: >> If spam is sent from one of our servers - the IP address of one of our >> servers - it's me you ultimately want to contact, not the owner of the IP >> address. If you contact the owner of the IP address - they don't have r

Re: [mailop] Does anyone have any contact for cloudmark.com?

2021-01-05 Thread Hans-Martin Mosner via mailop
Am 05.01.21 um 23:28 schrieb Brian Reichert via mailop: > I had mail recently bounce, with this seemingly informative message: > > Remote host said: 550 5.7.1 H:CSI [66.228.38.138] Connection > originating from an IP address with a poor reputation. Please see > http://csi.cloudmark.com/reset-

Re: [mailop] [EXTERNAL] Blocked from hotmail/live/outlook but ticket response says not blocked

2021-01-07 Thread Hans-Martin Mosner via mailop
Am 07.01.21 um 01:49 schrieb Seth Mattinen via mailop: > > Well, now I just got an email that says "Not qualified for mitigation Coming from Microsoft, this is particularly hypocritical as two of their own services (Sharepoint and Azure) are massive sources of spam, in addition to all the breach

Re: [mailop] [FEEDBACK] Azure Spammer Activity

2021-01-14 Thread Hans-Martin Mosner via mailop
Am 09.12.20 um 08:43 schrieb Hans-Martin Mosner via mailop: > Today we got a response to our abuse reports requesting that we report these > to j...@office365.microsoft.com - I > would've thought that within one corporation, forwarding of abuse tickets > should work somehow. W

Re: [mailop] [FEEDBACK] Azure Spammer Activity

2021-01-14 Thread Hans-Martin Mosner via mailop
Am 14.01.21 um 19:06 schrieb Jaroslaw Rafa via mailop: > Who will draw the line between what is and what isn't allowed to > publish/send/say on the Net? Who will guarantee taht when you send some > political content with which your ISP doesn't agree, you won't be labeled as > "spammer" and "bad guy

Re: [mailop] [FEEDBACK] Azure Spammer Activity

2021-01-14 Thread Hans-Martin Mosner via mailop
Am 14.01.21 um 23:50 schrieb Andreas Schamanek via mailop: > > On Thu, 14 Jan 2021, at 20:22, Michael Wise via mailop wrote: > >> On Tue, 8 Dec 2020, at 23:43, Hans-Martin Mosner wrote: >>> Today we got a response to our abuse reports requesting that we report >>> these to j...@office365.microsoft

Re: [mailop] Is it something to worry about?

2021-01-20 Thread Hans-Martin Mosner via mailop
Am 20.01.21 um 10:40 schrieb Jaroslaw Rafa via mailop: > Hello, > just got an information from MxToolbox that my IP (actually not my IP in > particular, but the ASN it belongs to) has been blacklisted at UCEPROTECT > level 3. Checking of my IP (217.182.79.147) at > http://www.uceprotect.net/en/rblc

[mailop] Sendgrid again...

2021-01-22 Thread Hans-Martin Mosner via mailop
Well I'm not complaining about the spam from them - it's a steady flow, nothing new. But it looks like they have filters on their abuse box now to reduce the amount of abuse reports: The original message was received at Fri, 22 Jan 2021 05:45:50 -0800 from m0099904.ppops.net [127.0.0.1] ---

Re: [mailop] Sendgrid again...

2021-01-22 Thread Hans-Martin Mosner via mailop
Am 22.01.21 um 15:22 schrieb Andrew C Aitchison via mailop: > > Are you sure that it was Sendgrid that blocked the message ? > Looks to me as if ab...@sendgrid.com is hosted at gmail and > it was *gmail* that objected to the content ... > > Or am I misunderstanding something ? No, of course you'r

Re: [mailop] [E] Re: Sendgrid again...

2021-01-22 Thread Hans-Martin Mosner via mailop
Am 22.01.21 um 17:16 schrieb Marcel Becker via mailop: > > > Bulk mail, email marketing, consumer email, enterprise email. Those are all > different businesses. Just because a > company does one thing doesn't mean it should be doing (or be good at) the > other.  True, but... If a company is act

Re: [mailop] Microsoft and Verizon not acceping mail

2021-02-02 Thread Hans-Martin Mosner via mailop
Apparently it's not a general problem for everyone, so it's likely the problem is somehow at your installation. If you want actual help in diagnosing the problem you should provide a bit more information, such as the error messages seen, and possibly traceroute output if you can't connect to th

Re: [mailop] Some Days I think that Gmail isn't even trying to stop outbound spam..

2021-02-04 Thread Hans-Martin Mosner via mailop
Am 04.02.21 um 17:43 schrieb Luke via mailop: > Preventing outbound spam on a large system is a far greater challenge than > stopping inbound spam. The technical > challenges are similar, but the logistical challenges of preventing outbound > spam without pissing off customers is > /far/ greater

Re: [mailop] Some Days I think that Gmail isn't even trying to stop outbound spam..

2021-02-06 Thread Hans-Martin Mosner via mailop
Please folks, don't take my comments as aggressive, even though they may sometimes come across as cynical. My top priority is to somehow help curb the flood of spam, not to accuse people of not doing enough or not doing the right thing. Am 05.02.21 um 04:23 schrieb Brandon Long via mailop: > If

Re: [mailop] When RBLs go bad

2021-02-14 Thread Hans-Martin Mosner via mailop
Am 14.02.21 um 11:45 schrieb Gary Gapinski via mailop: > On 2/14/21 1:42 AM, André Peters via mailop wrote: >> Have you guys already read this?  >> https://blog.sucuri.net/2021/02/uceprotect-when-rbls-go-bad.html > > I had not read it, but just did. > >> I have seen the discussion and found it fits

Re: [mailop] Gmail inboxing help

2021-02-18 Thread Hans-Martin Mosner via mailop
Am 18.02.21 um 15:22 schrieb Lauren Donovan via mailop: > Hi Everyone, > > I am wondering if someone here might have some insight into an issue I am > experiencing with Gmail customers. Here are > the details: > > 1.) When the customers click to opt-in on our form page, they are sent a > confirma

Re: [mailop] Spam Rejection Issues with 'forwarding services' @ namecheaphosting.com

2021-02-19 Thread Hans-Martin Mosner via mailop
Am 19.02.21 um 10:36 schrieb Benoît Panizzon via mailop: > Hi List > > One of our customers way desperately trying to reach company hosting > it's email services namecheaphosting.com > > eforward1.registrar-servers.com[162.255.118.51] was constantly > rejecting our customers emails as spam. We want

Re: [mailop] Good Hosting Suggestions? (old subject @ namecheaphosting.com)

2021-02-19 Thread Hans-Martin Mosner via mailop
Am 19.02.21 um 17:45 schrieb Michael Peddemors via mailop: > Any other hosting companies that you would "recommend" for email hosting? The sad (no, actually good) truth is that there are so many good hosters that recommending one or a few would always be highly subjective and wouldn't do justice

Re: [mailop] Good Hosting Suggestions?

2021-02-21 Thread Hans-Martin Mosner via mailop
Am 21.02.21 um 02:47 schrieb Allen Kitchen (zoominternet) via mailop: > Eh - not for presently-understood threats. > > But it still seems like a possible vector for as-yet-unknown exploits; ASCII > text a little less so. But ymmv. > > ..Allen Of course you should not open binary attachments such

Re: [mailop] Hotmail and block on OVH: possible solutions alternatives?

2021-02-25 Thread Hans-Martin Mosner via mailop
Am 25.02.21 um 18:53 schrieb Scott Mutter via mailop: > > In hosting, datacenter renting, situations where we're discussing OVH and > Vultr and other providers, the OWNER of the > IP address doesn't necessarily have the same interest as the USER of the IP > address in terms of mail deliverability

[mailop] Technical details on MS Exchange vulnerabilities?

2021-03-10 Thread Hans-Martin Mosner via mailop
Hello, does anyone have a pointer to technical details about the recently surfaced Exchange vulnerabilities? I would specifically be interested whether the exploit(s) depends on the server being exposed to the internet directly and would thus not be too critical if there's a Postfix internet ma

Re: [mailop] Delivery issues with gmx recipients

2021-03-12 Thread Hans-Martin Mosner via mailop
Am 12.03.21 um 10:24 schrieb Arne Allisat via mailop: > Hello, > > Please report your ip’s and an example error message to our postmaster team > https://postmaster.gmx.net/en/contact We're having problems as well (554-Reject due to policy restrictions). I've

Re: [mailop] Delivery issues with gmx recipients

2021-03-12 Thread Hans-Martin Mosner via mailop
Am 12.03.21 um 11:53 schrieb Arne Allisat via mailop: > Sorry. Me again. > > Two things: Some people experience temp rejects with an c=irlims message.I > thought that is your case as well, but it > isn’t. > > In your case it is an c=hi and you are pointed to the „Sending mail to GMX“ > page > (ht

Re: [mailop] Delivery issues with gmx recipients

2021-03-12 Thread Hans-Martin Mosner via mailop
Am 12.03.21 um 14:16 schrieb Michael Peddemors via mailop: > On 2021-03-12 4:58 a.m., Hans-Martin Mosner via mailop wrote: >> Am 12.03.21 um 11:53 schrieb Arne Allisat via mailop: > >> >>   * Ensure that the following email headers included in your message are >>  

[mailop] Reliability of DMARC reports?

2021-03-13 Thread Hans-Martin Mosner via mailop
Hello, due to the recent GMX mail rejection incident (for which I still don't have a satisfactory explanation from GMX) I've enabled DMARC on our mail server in the hopes of getting better deliverability. But some of our outgoing mails were rejected, and the aggregate DMARC reports we were gett

  1   2   3   >