Re: [mailop] Phishing hosted by Cloudflare-ipfs.com / Abuse Handled by Sparkpostmail.com?

2024-05-13 Thread Michael Irvine via mailop
This is normally an issue when it comes to SaaS solutions offering a free trial that happens to allow outbound email sending. Scammers will use it as many tend to trust the source. This is true for many senders as I still get at least 1-3 fake document shares a week on my personal Google

Re: [mailop] Phishing hosted by Cloudflare-ipfs.com / Abuse Handled by Sparkpostmail.com?

2024-05-13 Thread Faisal Misle via mailop
I know Cloudflare uses Sparkpost's infra to send replies from their abuse desk system, which is likely what you're seeing. Received: from mta-87-157.sparkpostmail.com ([192.174.87.157]) by safari.mxrouting.net with esmtps (TLS1.2) tls TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256

[mailop] Phishing hosted by Cloudflare-ipfs.com / Abuse Handled by Sparkpostmail.com?

2024-05-13 Thread Benoit Panizzon via mailop
Hi all Our customers increasingly get phishing emails targeting our email platform accessible under the domain: Cloudflare-ipfs.com (interplanetary file system, I guess that is their name for CNS). I reported some of those to the cloudflare abuse desk. To my surprise, after usually 1 or two

Re: [mailop] Someone at Google (GSuite) with a clue?

2024-05-13 Thread Aaron C. de Bruyn via mailop
While it was a groups permission issue, the GSuite logs for GMail do *not* show anything about a permission problem. See attached photo (if the list supports attached photos). -A On Mon, May 13, 2024 at 5:42 AM Faisal Misle via mailop wrote: > Also worth noting that it was not rejected at the

Re: [mailop] Sudden TSS04's From Yahoo/AOL Early This Morning

2024-05-13 Thread Michael E. Weisel via mailop
Thanks Mike and Faisal for the reply, I did open a ticket after I sent this message earlier and am waiting for a response. Thanks, Michael Michael E. Weisel CTO / Deliverability Lead Gold Lasso (301) 990-9857 Corporate (240) 813-0174 Direct Dial From: Mike Hillyer Date: Monday, May 13,

Re: [mailop] Sudden TSS04's From Yahoo/AOL Early This Morning

2024-05-13 Thread Mike Hillyer via mailop
The possibility of it being an issue at Yahoo! is why you should open a ticket, it allows them to investigate whether they have a false positive. Mike Mike Hillyer Co-Founder 443-472-7226 Let's Meet: https://cal.com/mike-kumomta/meet On Mon, May 13, 2024 at 8:06 AM Michael E. Weisel via

Re: [mailop] Sudden TSS04's From Yahoo/AOL Early This Morning

2024-05-13 Thread Faisal Misle via mailop
I am of the opinion you should still submit a ticket - their team will have more information as to why it was flagged and if it was a false positive. On 5/13/24 1:46 PM, Michael E. Weisel via mailop wrote: Good morning Mailop friends.  One of our clients suddenly started seeing TSS04’s

Re: [mailop] Someone at Google (GSuite) with a clue?

2024-05-13 Thread Faisal Misle via mailop
Also worth noting that it was not rejected at the SMTP stage because the email address was valid. Google does not check for permissions to post to the Group until after it has accepted and processed the message, hence the delayed NDR. The Google rep also may not have had access to group

[mailop] Sudden TSS04's From Yahoo/AOL Early This Morning

2024-05-13 Thread Michael E. Weisel via mailop
Good morning Mailop friends. One of our clients suddenly started seeing TSS04’s early this morning. I haven’t opened a ticket yet in case this was an issue at Yahoo like happened a few months back. Anyone else seeing similar issues this morning? Nothing changed with their sending so not

[mailop] Breaking DKIM and BIMI in 2024 (with 16y old CVE-2008-0166)

2024-05-13 Thread Lukas Tribus via mailop
Hey list, it looks like CVE-2008-0166 affected DKIM keys are still out there: https://16years.secvuln.info/ lukas ___ mailop mailing list mailop@mailop.org https://list.mailop.org/listinfo/mailop