Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-12 Thread Bill Cole
On 2023-10-12 at 10:24:11 UTC-0400 (Thu, 12 Oct 2023 10:24:11 -0400) Ricky Boone is rumored to have said: Thank you. It was my mistake initially, as I was under the impression that submitting unsolicited samples wasn't preferred, and was just intending to raise awareness for others in case the

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-12 Thread Ricky Boone
Thank you. It was my mistake initially, as I was under the impression that submitting unsolicited samples wasn't preferred, and was just intending to raise awareness for others in case they see anything similar. Attached is evidence with redactions. Again, my apologies if the original email came

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-12 Thread Bill Cole
On 2023-10-11 at 22:02:22 UTC-0400 (Wed, 11 Oct 2023 22:02:22 -0400) Ricky Boone is rumored to have said: My apologies. The samples that I have contain email addresses that I am not at liberty to share without redacting. If it's okay that there are certain strings that are removed, I should b

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-11 Thread Ricky Boone
My apologies. The samples that I have contain email addresses that I am not at liberty to share without redacting. If it's okay that there are certain strings that are removed, I should be able to make them available. Is there a preferred method for getting this to you? On Wed, Oct 11, 2023 at

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-11 Thread Bill Cole
On 2023-10-11 at 16:45:15 UTC-0400 (Wed, 11 Oct 2023 16:45:15 -0400) Ricky Boone is rumored to have said: Just a heads up, it appears that usssa[.]com has had their SendGrid email sending account popped, and a bad actor has been sending phishing emails from it. The domain is defined in 60_welc

Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-11 Thread Ricky Boone
Just a heads up, it appears that usssa[.]com has had their SendGrid email sending account popped, and a bad actor has been sending phishing emails from it. The domain is defined in 60_welcomelist_auth.cf with def_welcomelist_auth/def_whitelist_auth entries with *@*.usssa.com.