Re: paypal fraud

2024-11-07 Thread Benny Pedersen
Benny Pedersen skrev den 2024-11-07 22:13: Neither Microsoft or Paypal will do anything unless you advise them of this - doubt PayPal even knows. if the above perl module is fixed for this issue i belive thay will know more https://dmarcian.com/dmarc-inspector/?domain=paypal.com relaxed ad

Re: paypal fraud

2024-11-07 Thread Benny Pedersen
Jared Hall via users skrev den 2024-11-07 21:15: 1) Paypal's SPF is a little borked.  Here's there first included SPF: v=spf1 ip4:173.0.84.224/27 ip4:66.211.170.85/30 ip4:66.211.170.88/29 ip4:173.224.165.0/26 ip4:173.0.94.244/30 ip4:173.224.161.128/25 ip4:173.0.84.0/29 -all its still not s

Re: paypal fraud

2024-11-07 Thread Benny Pedersen
MX skrev den 2024-11-07 05:44: Isn’t this just a forwarded email from Office 365 using SRS? It SRS does not solve rfc in dkim, h= tag misssing minimal required headers https://github.com/fastmail/mail-dkim/issues/35

Re: paypal fraud

2024-11-07 Thread Jared Hall via users
On 11/7/2024 2:20 PM, Benny Pedersen wrote: Bill Cole skrev den 2024-11-07 14:47: I'm quite sure we don't want the SA project committed to running any sort of blocklist which requires active close attention. We can't do that competently. how to solve dkim reuse headers then ?, i bet paypal

bug reported to github now was paypal....

2024-11-07 Thread Benny Pedersen
https://github.com/fastmail/mail-dkim/issues/35

Re: paypal fraud

2024-11-07 Thread Benny Pedersen
Bill Cole skrev den 2024-11-07 14:47: I'm quite sure we don't want the SA project committed to running any sort of blocklist which requires active close attention. We can't do that competently. how to solve dkim reuse headers then ?, i bet paypal do all thay can to remove that public key in d

Re: paypal fraud

2024-11-07 Thread Bill Cole
On 2024-11-06 at 22:25:34 UTC-0500 (Thu, 07 Nov 2024 04:25:34 +0100) Benny Pedersen is rumored to have said: Alex skrev den 2024-11-07 03:02: welcomelist_auth *@paypal.com [2] blocklist_from *@paypal.com [2] the dkim is imho 100% invalid, there missing important headers dkim signed, eg mes

Re: paypal fraud

2024-11-07 Thread Benny Pedersen
Matus UHLAR - fantomas skrev den 2024-11-07 19:51: missing DKIM_VALID_EF, so not dmarc aligned strict DMARC does not require this. correct for dmarc non strict yes, correct, it does if dkim domain is dmarc strict Even mail from this mailing list does not have DKIM_VALID_EF. Because this

Re: paypal fraud

2024-11-07 Thread Matus UHLAR - fantomas
Alex skrev den 2024-11-07 14:55: Can I use spamassassin -D on an email I've already received to confirm DKIM signature? On 07.11.24 17:56, Benny Pedersen wrote: sure "spamassassin -D -t email 2>&1 | less" :) but its sadly dkim valid with non compliant h= tags, i consider this should be repor

Re: paypal fraud

2024-11-07 Thread Benny Pedersen
Michael Peddemors skrev den 2024-11-07 18:03: For the record, just because it actually comes from the Paypal infrastructure, doesn't mean it is good. Last couple of weeks they have been struggling with scammers using actual Paypal accounts. Fake orders, and using scammers telephone numbers to

Re: paypal fraud

2024-11-07 Thread Benny Pedersen
Alex skrev den 2024-11-07 14:55: Can I use spamassassin -D on an email I've already received to confirm DKIM signature? sure "spamassassin -D -t email 2>&1 | less" :) but its sadly dkim valid with non compliant h= tags, i consider this should be reported as a bug missing DKIM_VALID_EF, so

Re: paypal fraud

2024-11-07 Thread Alex
> > > can I have a copy of the email ? > I am working on improving some KAM Paypal rules. > Sent, thanks. >