[mailop] Phishing hosted by Cloudflare-ipfs.com / Abuse Handled by Sparkpostmail.com?

2024-05-13 Thread Benoit Panizzon via mailop
Hi all Our customers increasingly get phishing emails targeting our email platform accessible under the domain: Cloudflare-ipfs.com (interplanetary file system, I guess that is their name for CNS). I reported some of those to the cloudflare abuse desk. To my surprise, after usually 1 or two

Re: [mailop] how does mailhash.josephlist.net work?

2024-04-04 Thread Benoit Panizzon via mailop
> Yes, there are joe jobs. No, there are not very many. Yes, everyone can send emails containing targeted URI to known spamtraps, which then will extract and feed those URI to URI Blacklists. So I guess this works on in similar way, just for email addresses found in emails. Joe-Jobs are an

[mailop] how does mailhash.josephlist.net work?

2024-04-02 Thread Benoit Panizzon via mailop
Hi List I came across emails rejected by mailhash.josephlist.net reason: 550 5.7.1 block listed email address s...@example.com by mailhash.josephlist.net (c559b92e0e284312b26c88d4bb707d14) What I found out is that the email content is searched for email addresses and if some hash of that email

[mailop] Anyone from sendinblue on this list?

2024-03-05 Thread Benoit Panizzon via mailop
Hi If anyone from sendinblue is reading here. We have repeated issue of tracking URI used by sendinblue get used in emails sent to our spamtraps/honeypot mimiking an open relay, causing the sender ip (not from the network of sendinblue) and 'spamvertized' trackingdomain to get blacklisted, thus

Re: [mailop] Office365: only accepts messages from people in its organization or on its allowed senders list

2024-02-20 Thread Benoit Panizzon via mailop
Hi > As the list is restricted, that’s pretty poor business practice - “We expect > you to reply to this message, but you can’t, and here’s why!” Yes, this is exactly what we get... From: noreply@... CC: ms-peering-updates@... Subject: BGP Peering AS8075, Request to increase prefix filter

[mailop] Office365: only accepts messages from people in its organization or on its allowed senders list

2024-02-20 Thread Benoit Panizzon via mailop
Hi List Maybe somebody could enlighten me, what is going on We very often face the issue of Office365 business customers sending an email to us and asking for reply, but when we reply we get: === schnip === Your message to [RECIPIENT] couldn't be delivered. The group [USERPART OF EMAIL]

Re: [mailop] Microsoft 365 IP addresses listed on Spamcop

2024-02-15 Thread Benoit Panizzon via mailop
Hi Christoph > I am attempting to send mail from a M365 tenancy, however, we are seeing > issues with it being filtered due to the address appearing on bl.spamcop.net. > "Decision Engine classified the mail item was rejected because of IP Block > (from outbound normal IP pools) -> 550 mail from

[mailop] Ping Microsoft / MSN

2024-01-22 Thread Benoit Panizzon via mailop
https://blacklist.imp.ch/entry.php?id=1.0.8.0.0.0.0.0.0.0.0.0.0.0.0.0.2.1.e.2.3.0.4.f.1.1.1.0.1.0.a.2 no further comment needed... Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden __

Re: [mailop] How to report abuse to cloudflare? Only via Web-Form?!? Phishing sites not against cloudflare policy!?!

2023-11-16 Thread Benoit Panizzon via mailop
Hi Laura > Cloudflare does not concern itself with abuse. It does not host any websites, > it only proxies back to the web host. They are not responsible for the > content and they are unable to disconnect customers. I am aware they do not host the content. But they hide the IP address of

Re: [mailop] How to report abuse to cloudflare? Only via Web-Form?!? Phishing sites not against cloudflare policy!?!

2023-11-16 Thread Benoit Panizzon via mailop
Hi > If you want any real action from Cloudflare, you have to jump through the > hoop of filling in the web based abuse form. It sucks but only you can > decide whether it's worth your time and effort. Yes, but what I don't get is, why on their first reply, they confirm opening a case but then

[mailop] How to report abuse to cloudflare? Only via Web-Form?!? Phishing sites not against cloudflare policy!?!

2023-11-15 Thread Benoit Panizzon via mailop
Hi out there A website, most probably hacked WordPress, behind cloudflare, is hosting a phishing site targetting our webmail user. I reported this to the owner of the hacked website. I know he read my messages and choose to ignore the issue. So next step, report to cloudflare. First reply from

[mailop] Phishing Emails sent via mail-sgaapc01on20624.outbound.protection.outlook.com ([IPv6:2a01:111:f400:feab::624]:24545)

2023-09-26 Thread Benoit Panizzon via mailop
Hi List With little hope, that anyone @ microsoft is reading this list. I have attempted to contact Microsoft on many different ways to try to address those issues. Clearly a phishing email claiming being from DPD hitting one of our spamtraps square in the face causing immediate blacklisting of

[mailop] Amazon SES using SAME sender Domain for multiple customer?

2023-09-25 Thread Benoit Panizzon via mailop
Hi List... There is a company which is sending a lot of misdirected/unwanted email via Amazon SES and has failed to react to my attempts to contact them by email and phone in the last 14 days or so to try to solve the issue. Usually I then go ahead and block the envelope-sender domain. In this

[mailop] Anyone a contact @ virusfree.cz

2023-08-15 Thread Benoit Panizzon via mailop
Hi Gang virusfree.cz is listing one of our mail servers. I opened a support case with them almost two weeks ago to ask for a delisting and reason/evidence for the listing. They are praised for their good support: https://www.virusfree.cz/en/customers-and-support Unfortunately I don't get any

[mailop] Delivery Reports, requested by Microsoft 'Outlook' customer, reported as Spam by same Microsoft 'Outlook' customer?

2023-08-10 Thread Benoit Panizzon via mailop
Hi Team I would be very happy, if anymone at microsoft could get in touch with me, we probably get more than 90% false positives from the microsoft spam report robot. Newest crazy addition! exam...@outlook.com is sending an email indicating request for a delivery report. Our server AFTER

[mailop] Solved Re: Office365 STARTTLS not working anymore?

2023-07-18 Thread Benoit Panizzon via mailop
Ok, my bad... Missed the -crlf option because SMTP requires CRLF line endings. STARTTLS works. So actual conclusion: outlook.office365.com SMTP: Plain SSL on Port 465 not accessible. STARTLS on 587 (and 25) works! IMAP: STARTLS advertised but BROKEN on port 143 since 2 days. Plain

Re: [mailop] Office365 STARTTLS not working anymore?

2023-07-18 Thread Benoit Panizzon via mailop
Hi.. Weird... if somebody could point me to what I'm doing wrong... Our Postfix: Jul 18 08:04:53 asterix postfix/smtp[81902]: Untrusted TLS connection established to hotmail-com.olc.protection.outlook.com[104.47.51.33]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits) Is

[mailop] IMAP solved (port 993 ssl) but how to SMTPS? (Re: Office365 STARTTLS not working anymore?)

2023-07-18 Thread Benoit Panizzon via mailop
Hi again IMAP Login thankfully works on imaps port 993 with plain SSL. But now I get the same issue with SMTP. Port 465 which traditionally is used for smtps via plain SSL is closed. Port 587 advertises STARTTLS: Trying 2603:1026:c0b:16::2... Connected to outlook.office365.com. Escape

Re: [mailop] Office365 STARTTLS not working anymore?

2023-07-18 Thread Benoit Panizzon via mailop
Hi Oliver > As far as I know Microsoft never officially supported or advertised STARTTLS > for its mail submission services. Given that RFC8314 "Use of Transport Layer > Security for Email Submission and Access" basically deprecates STARTTLS in > favor of implicit TLS for submission services,

[mailop] Office365 STARTTLS not working anymore?

2023-07-18 Thread Benoit Panizzon via mailop
Hi Team Since two days I'm unable to connect to an Office365 IMAP Mailbox with OAUTH2 My client connects to Port 143 and performs STARTTLS but is not getting anything in reply. Is there a known outage? Hast Microsoft discontinued STARTTLS? Mit freundlichen Grüssen -Benoît Panizzon- -- I m p

[mailop] SPF: Does include: a host without TXT entry invalidate the whole SPF entry?

2023-06-06 Thread Benoit Panizzon via mailop
Hi List One more technical question after some discussion with one of our customers. Sender has SPF entry: "v=spf1 ip4:10.1.2.0/25 include:_spf.example.com -all" _spf.example.com either has no txt entry or just does not exist. So from my point of view, the SPF entry is still valid as it has

[mailop] Microsoft Office365 not rejecting emails when instructed so by SPF recored?

2023-05-23 Thread Benoit Panizzon via mailop
Hi List I'm surprised... six-group.com is the biggest payment platform in Switzerland. Of course they use SPF to protect their domain from being abused by phishers. It looks like GV0CHE01FT013.mail.protection.outlook.com is happily accepting phishing emails which, according to SPF should get

[mailop] ab...@microsoft.com => Mailbox full

2023-04-20 Thread Benoit Panizzon via mailop
For heaven's sake Microsoft! I'm trying to report the same spaming Office 365 Customer again which uses a shared ip address with some other Swiss companies that use Office 365 and experience collateral damage... That is NOT the reply I expect. === snipp === Delivery has failed to these

[mailop] How to address Microsoft if spaming Office365 customers cause collateral damage for other Office365 customers sharing the same IP?

2023-03-30 Thread Benoit Panizzon via mailop
Hi all Received: from mail-vi1eur04on0730.outbound.protection.outlook.com ([IPv6:2a01:111:f400:fe0e::730]:47502) from new...@news-science-travel.com Auth: by a Spamtrap on 2001:4060:dead:beef::1907:2 25 pretending to be an open relay for jodyyw...@blacklist.woody.ch; Mon, 27 Mar 2023

Re: [mailop] Cyren

2023-02-13 Thread Benoit Panizzon via mailop
> This is a good hypothesis but so far I have not seen any absolute > confirmation that they are "listing the world." I guess we will see... I fear this is the case. I have contacted the ISP in question whose ctasd instance was adding 6 SpamAssassin Points to every email sent by their customer.

Re: [mailop] Cyren

2023-02-13 Thread Benoit Panizzon via mailop
Hi All I have started seeing a lot of emails sent via one Swiss ISP flagged as spam by the SpamAssassin CTASD, which according to Google, is Cyren's anti spam service. Have they started flagging all emails as spam to tell their customer to stop using their service? Mit freundlichen Grüssen

Re: [mailop] Office365 sometimes sending reply to email to originator 'submission' ip instead of there the MX points?

2023-01-16 Thread Benoit Panizzon via mailop
Hi Gang Short update: Was 'human error' on our side. Submission Host was wrongly advetised as one of the 'MX'. Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden __ Zurlindenstrasse 29

Re: [mailop] Reject vs spam folders

2022-09-15 Thread Benoit Panizzon via mailop
Hi > > First of all: I am fed up with telling people to look for missing emails in > > their spamfolders. > > > > If I have to check a spamfolder for false positives every day, I can just > > have them delivered to my inbox. The spamfolder does not have an advantage > > then. > > > > Your

Re: [mailop] opendkim replacement

2022-07-04 Thread Benoit Panizzon via mailop
Hi > If you are looking for something that integrates as a milter like opendkim, > dkimpy-milter seems to do exactly that. With a bit of luck it could even > integrate with your existing opendkim configuration. I'll have a look at it. > However, I am curious about what the issue is with

Re: [mailop] opendkim replacement

2022-07-04 Thread Benoit Panizzon via mailop
Hi I would also be interested in finding a 'plug in' replacement for the, sometimes dodgy openDKIM milter. > rspamd or WildDuck rspamd is a full featured spamfilter. I only need the part that validates and signs DKIM. WildDuck is a fully featured mail plattform. I guess I have to stick with

Re: [mailop] Barracuda DKIM checker reports invalid signature

2022-06-13 Thread Benoit Panizzon via mailop
Hi Sebastien > One common issue is Canonicalization. Try setting your to relaxed/relaxed and > it solves many issues. Many of these things "downconvert" the emails into > 7BITMIME and also munge certain whitespace characters, which can b0rk the > signatures. > > So try setting to

[mailop] Barracuda DKIM checker reports 'invalid signature'

2022-06-13 Thread Benoit Panizzon via mailop
Hi Gang Maybe I could ask for some help here... We have a DKIM issue with recipients which use Anti-Spam Products from Barracuda Networks. All tests we could find, confirm that we configured Domainkey correctly for the domain imp.ch and signatures are valid. Google is happy with our signatures.

Re: [mailop] Spamhaus: Get more details about LISTING (Could a DMARC Report Address point to a spamtrap)?

2022-05-19 Thread Benoit Panizzon via mailop
Following up to this issue... The 'comments' field while requesting a delisting is obviously not being looked at by Spamhaus. Opening a case via their contacts page worked smoothly and the cause was found in a 'too aggressive rule' that has been fixed in the meantime, but still no very clear

[mailop] Spamhaus: Get more details about LISTING (Could a DMARC Report Address point to a spamtrap)?

2022-05-17 Thread Benoit Panizzon via mailop
Hopefully somebody from spamhaus is reading. The 2nd day in a row, our main mailplattform IP address is listed and outlook.com blocks all emails. Spamhaus only gives a timestamp +/- 5 minutes. There are A LOT OF EMAILS passing our plattform in 10 Minutes. Yesterday I found a suspect. One

[mailop] Business Office 365 hosted Exchange IP Addresses shared between customers? Lateral damage on spam sending customer.

2022-03-29 Thread Benoit Panizzon via mailop
Hi List One of the local electricity plants is sending invoices via hosted Office 365 emails services to it's customers, many hosted on our email platform. It's a larger Office 365 customer. Many of those emails were rejected as spam. So they opened a case with our abuse desk. I noticed their IP

[mailop] Anyone from BT UK on this list?

2022-03-10 Thread Benoit Panizzon via mailop
Hi Please contact me regarding BT 'Customer-Resolutionteam' directing to open support cases via Community Support Site, but Email Verification failing with: RCPT from outbound-dkim.eu.khoros-mail.com[34.246.32.154]: 450 4.1.8 : Sender address rejected: Domain not found; from=

Re: [mailop] So how do you actually manage to send mails to outlook/hotmail?

2021-07-12 Thread Benoit Panizzon via mailop
Hi Marcus I had a similar issue some time ago. Google uses some 'Domain Reputation' Woodoo. I used to operate an automated spam feedback loop from my spamtrap, under a specific hostname in my domain. One only used for those reports. Unfortunately, it looks like some 'abuse contact addresses'

Re: [mailop] Technical Contact to paddle.com mail platform operator?

2021-07-06 Thread Benoit Panizzon via mailop
Hi > 2021-06-29         mta214a-ord.mtasv.net [104.245.209.214] > 2021-06-29         mta216a-ord.mtasv.net [104.245.209.216] > 2020-11-25         mta200a-ord.mtasv.net [104.245.209.200] Thank you. I can confirm, other customers (other domains on our platform) are getting email from those IP

[mailop] DigitalOcean: Marketing Emails to abuse email address after contacting their abuse department?

2021-06-22 Thread Benoit Panizzon via mailop
Hi List I guess some of you have also contacted DigitalOcean's abuse desk in the past. We did so from our abuse desk email address. I was quite surprised, to find our abuse desk email address subscribed to DigitalOcean's: * Educational Resources * Events and Meetups * User Research Surveys *

[mailop] Zendesk being abuse to distribute PDF malware

2021-05-25 Thread Benoit Panizzon via mailop
Hi List I just tumbled over a new was those attackers have found to distribute their PDF to avoid being blocked by spam filter and virus scanner (or maybe just a coincidence?) The attacker sends an email to a Zendesk support site, with the PDF attachment and a huge list of recipients CC. The

[mailop] Registered @ Microsoft JMRP - blacklisted without feedback received

2021-05-11 Thread Benoit Panizzon via mailop
Dear List One of our main smtp outbound ip addresses is blocked by microsoft. host outlook-com.olc.protection.outlook.com[104.47.10.33] said: 550 5.7.1 Unfortunately, messages from [157.161.12.84] weren't sent. Please contact your Internet service provider since part of their network is on our

[mailop] Weird 'tempfail too many recipients' bug/incompatibility EXIM => Postfix?

2021-01-19 Thread Benoit Panizzon via mailop
Hi Gang I wonder of anyone else has seen this kind of this issue between EXIM and Postfix. Sender uses Exim, Version unknown Recipient uses Postfix 3.1.0 Email is sent to a lot of recipients. Postfix is configured to only accept a certain amount of recipients. Surplus recipients get rejected

[mailop] Revisiting: outlook_hexstr...@outlook.com email addresses

2020-10-06 Thread Benoit Panizzon via mailop
Hi List I already mentioned this issue some time ago, and now I am seeing this more often again. Sometimes the From: Header and evelope-from from Outlook.com customers do NOT contain their email address but a strange hex string. This is an authentic email from one of our customers. So I wanted

Re: [mailop] Any chance that Microsoft would tell it's customer that the 'junk' folder creates complaints?

2020-09-24 Thread Benoit Panizzon via mailop
> Would that even change the customer behaviour? I doubt so. > Maybe if they make it so user has to click 5 times through warnings > before it ends to the junk folder, while trash is only 1 click away. > But, if they do that, people would also probably stop reporting junk. I am sure this would

[mailop] Any chance that Microsoft would tell it's customer that the 'junk' folder creates complaints?

2020-09-24 Thread Benoit Panizzon via mailop
Hi Gang We had one more case of one of our customers sending commercial newsletters resulting in us getting complaints from hotmail.com etc. users. We confronted our customer and requested a proof of opt-in for the Microsoft recipients. Our customer ignored this. So on the next occurrence, we

[mailop] firebasestorage.googleapis.com any legitimate uses?

2020-08-27 Thread Benoit Panizzon via mailop
Hi List In the last couple of days we face an increasing amount of phishing sites hosted @ firebasestorage.googleapis.com targeting our customers. They get taken down rather quickly when added to phishtank.com, but still they are valid for one or two days after reception, long enough for stup**

Re: [mailop] ANNOUNCEMENT: The NEW invaluement "Service Provider DNSBLs" - 1st one for Sendgrid-spams!

2020-08-25 Thread Benoit Panizzon via mailop
Hi Rob This works like a charm, blocking a lot of: bounces+8465718 atm. Thank you for your excellent plugin! Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden __ Zurlindenstrasse 29

Re: [mailop] Just how does SendGrid fail this badly?

2020-08-20 Thread Benoit Panizzon via mailop
Am Tue, 18 Aug 2020 11:01:19 -0700 schrieb Luke via mailop : > In the Return-Path. "bounces+1234567" the number following bounces+ is the > SendGrid account ID. Return-Path: Does the c581 part also belong to the account id? I might consider trying to extract this on my spamtrap and collect

Re: [mailop] New SendGrid IP(s) detected sending phishing last 24 hours..

2020-08-13 Thread Benoit Panizzon via mailop
Here's my contribution (Reversed IP) Last 6 months for a single hit, possily longer back if there are more hits. This is just the 'hits' by spamtrap or customer report database, not the actual blacklisted ip addresses. Most of them did not get blacklisted because of positive dnswl.org crosscheck.

[mailop] Delisting request from sendgrid customer about ip used in recent phishing campaign.

2020-08-11 Thread Benoit Panizzon via mailop
Hi List o1678912x138.outbound-mail.sendgrid.net [167.89.12.138] and IP under control of sendgrid was repeatedly involved in phishing and other spam since June. It ended up being blacklisted @ SWINOG. Now a sendgrid customers complains to us, that his emails are being rejected because of this

Re: [mailop] Outlook 2016: Excessive IMAP connections

2020-08-11 Thread Benoit Panizzon via mailop
Hi Tim No, ICMP is not being blocked. At least not on the IMAP server side. Yes, IPv6 in use, but the affected customer mostly don't use IPv6 and don't use mobile networks. But since we increased to 50 connections per user+ip the complaints are almost gone. As I understand, Outlook 2016 opens

[mailop] Outlook 2016: Excessive IMAP connections

2020-08-07 Thread Benoit Panizzon via mailop
Hi Gang We use DoveCot as IMAP Server and have limited the number of connections per IMAP account to 20 which looks to have been sufficient in the past couple of years. Since about two weeks we get an increased number of users complaining about IMAP connections problem and name (0x8...) error

Re: [mailop] Digital Ocean Broken Bot attack, just in case it's you and not me..

2020-07-09 Thread Benoit Panizzon via mailop
> >Range, 192.241.227.0/24 > > One connect each on Thu, Sat, Sun, and Mon. Did EHLO after banner, then > closed the connection. 116 connections between 27. June and 1. July to my spamtrap / honeypot, mostly sending "EHLO zg-0626-127" and then disconnecting. Mit freundlichen Grüssen

Re: [mailop] Is Gmails DMARC check broken?

2020-06-03 Thread Benoit Panizzon via mailop
Hi Laura > Why is Google applying a strict reject when the policy is p=none? I think I mentioned that I reverted back to p=none quickly after I saw such rejects. TTL is 300 :-) -- -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden

Re: [mailop] Is Gmails DMARC check broken?

2020-06-03 Thread Benoit Panizzon via mailop
Hi Tim > and I guess the domain in the HELO too? the HELO contains the FQDN of the sending machine which is not the same as the domain of the envelope sender or From: Header. The HELO needing to match anything for DMARC or SPF would be quite new to me. -- -Benoît Panizzon- -- I m p r o W a r

[mailop] Is Gmails DMARC check broken?

2020-06-02 Thread Benoit Panizzon via mailop
Hi Gang I'm on the way of more widely deploying DMARC and also testing DKIM once again. Also on our ISP email service domains. So at the moment I'm only using DMARC with SPF. According to my reading on how DMARC works, if no DKIM record is published, a passing SPF record is sufficient for

[mailop] Google: 'Low reputation of the sending domain'

2020-06-02 Thread Benoit Panizzon via mailop
Hi Gang My personal mailserver is not able to send any emails to gmail accounts since several months. I was hoping this would solve itself eventually. It did not. There are no breaches or spam or anything sent from that server. I would know as I am part of the AS6772 Abuse Desk. :-) Just the

Re: [mailop] Opinions? Email Abuse over TOR Network? (spamtraps)

2020-02-20 Thread Benoit Panizzon via mailop
Hi Just a clarification on the issue, as we just got a 2nd similar complaint from another Tor Exit node operator (obviously same attacker being routed through another exit, guessing from the involved email addresses). The Spamtrap / HoneyPot in question not only listens to port 25 but also

[mailop] Recipe vs fake From: header?

2020-02-18 Thread Benoit Panizzon via mailop
Hi List Lately, our customers are getting an increased amount of phishing emails, or emails containing malware with legit looking From: headers from either banks, or even from our own customer support. SPF would block the From email addresses if also used as envelope sender. But the, from the

[mailop] Opinions? Email Abuse over TOR Network? (spamtraps)

2020-02-17 Thread Benoit Panizzon via mailop
Dear List We operate Spamtraps which feed the SWINOG Anti-Spam Blacklist. A feedback loop is sent to the abuse-c of the IP Address from which email or attackts to spamtraps was detected. Occasionally, spam or more often, log-in attempts and dictionary attacks on the submission ports of the

[mailop] Trendmicro Emails: "An email sent to you has been placed in quarantine by Hosted Email Security (HES)."

2020-01-16 Thread Benoit Panizzon via mailop
Hi Gang I wonder if others have also started seing such emails: Source: Received: from routemea20.hes.trendmicro.eu (routemea20.hes.trendmicro.eu [3.125.147.66]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by

Re: [mailop] China Telecom

2019-12-23 Thread Benoit Panizzon via mailop
Hi > Happy holidays all, Same to you! > Curious, does anyone happen to have a contact or know of a proper escalation > route at China Telecom? Seeing some wonkiness that I can't explain. Also very interrested in this! Habe been trying to get hold of a tech @ China Telecom since monts, if

[mailop] Benin, 197.234.221.180, AS37424, "For Jeny SAS Internet customers" Mylove@1

2019-11-28 Thread Benoit Panizzon via mailop
Hi Gang Over the last months, I have observed many email mailbox abuses from the "Jeny SAS" IP Range in Benin which used passwords probably obtained by phishing attacks. The interesting thing here is: If we block SMTP for the affected mailbox, this usually solves the issue. Our customer then

[mailop] How to get delisted @ senderscore.org?

2019-11-14 Thread Benoit Panizzon via mailop
Hi List One IP address of our email plattform, got a '20' score @ senderscore.org because of emails to 'unknown recipients' This causes one of the major swiss banks to put emails sent from our customers which were sent via this IP into a quanantine folder. So neither the sender nor the

Re: [mailop] Avoiding bounces - custom spamfilter behind real-spamfilter that reject mails

2019-10-25 Thread Benoit Panizzon via mailop
> The customer, in that case, need to change from REJECT to DISCARD or > QUARANTINE. Yes, that would be an option. But from my experience, this leads to the problem of 'disappearing' emails in case of false positives. Usually no email admin looks into the quarantine, unless somebody complains

Re: [mailop] Avoiding bounces - custom spamfilter behind real-spamfilter that reject mails

2019-10-24 Thread Benoit Panizzon via mailop
> On 24/10/2019 14:12, Benoit Panizzon via mailop wrote: > > I also considered hacking together a small 'relay' MTA which would > > receive the email but not reply OK to the final DATA command (RFC > > states you can take up to 60 seconds to reply to the DATA command) >

Re: [mailop] Avoiding bounces - custom spamfilter behind real-spamfilter that reject mails

2019-10-24 Thread Benoit Panizzon via mailop
Hi Stefan > So the reject generates bounces at our spamfilters. Howto handle this? Yes, I do know this issue, as we offer a similar service. And I must admit, I have no real solution if you use some out of the stock MTA like postfix or sendmail which work on store and forward basis. I also

[mailop] Anyone a direct contact to the Mailchimp abuse desk?

2019-10-22 Thread Benoit Panizzon via mailop
Hi All I'm looking for a direct contact to the Mailchimp Abuse Desk, regarding a case of a repeated spamer I opened in March this year. Mailchimp told me they need some time to verify my evidences and reconstruct how their customer acted. I update that mailchimp case with the question if they

Re: [mailop] Erroneous Hotmail spam/junk JMR email due to recipient error, where's the operator feedback loop?

2019-10-08 Thread Benoit Panizzon via mailop
Hi Chris I have exactly the same issue. I have found a hotmail user who made rule to 'save' all emails from a whole list of 'known friends' sender to the 'junk' folder. Causing an immediate Spam Complaint from Microsoft every time one of our customers sends that hotmail user an email. The

Re: [mailop] Weird blocking by outlook.com (S3150)

2019-08-23 Thread Benoit Panizzon via mailop
Hi Laura > In my experience, when the bounce message says "Please contact your Internet > service provider since part of their network is on our block list (S3150).” > That means that Microsoft is seeing problems across a wide range of IPs in a > space and they don’t have a clear picture of

[mailop] Weird blocking by outlook.com (S3150)

2019-08-22 Thread Benoit Panizzon via mailop
Hi List One of our mail platform IP has once more been hit by an outlook.com blocking: host outlook-com.olc.protection.outlook.com[104.47.4.33] said: 550 5.7.1 Unfortunately, messages from [157.161.12.116] weren't sent. Please contact your Internet service provider since part of their network is

[mailop] Solved: Re: Amazon AWS SES (Simple Email Services) what could cause a domain to be blocked?

2019-08-22 Thread Benoit Panizzon via mailop
Hi Team Just a follow up on that case, as from the feedback I got it looks others are also affected by this problem. I finally managed to get the attention of an Amazon SES Tech who agreed to look into the issue and got an explanation of what most probably happened. Amazon SES does NOT block

Re: [mailop] Hotmail: Moving Email to 'spam' folder generates ISP complaint?

2019-08-16 Thread Benoit Panizzon via mailop
Hi Mathieu > I don't see that as a problem, I mean I completly understand the logic behind > that. If someone wants to organize their inbox they can create subfolders > easily, using the spam folder to "rearrange" your emails is just plain > stupid, especially as mails in the spam folder are

[mailop] Hotmail: Moving Email to 'spam' folder generates ISP complaint?

2019-08-16 Thread Benoit Panizzon via mailop
Hi List A couple of days ago we found out, that Mircosoft offers an Feedback Loop to received complaints about spam incidents. Perfect, one more source we can use to detect and block phished customers's account or trojanized devices. So we enabled this. That works good so far, but we also

Re: [mailop] Amazon AWS SES (Simple Email Services) what could cause a domain to be blocked?

2019-08-13 Thread Benoit Panizzon via mailop
Hi Marc > https://mxtoolbox.com/SuperTool.aspx?action=mx%3aleunet.ch=toolpage > > Suggest you fix that and come back to them. DMARC? It's not an error, it's not a requirement. The AWS customer who notified the problem uses this email domain:

[mailop] Amazon AWS SES (Simple Email Services) what could cause a domain to be blocked?

2019-08-12 Thread Benoit Panizzon via mailop
Hi List Amazon AWS SES Support drives me and their customer mad. So I wonder if any other email operator had a similar issue and might know what causes Amazon AWS SES Services to block email delivery to a specific domain and how this can be solved. We are an ISP and operate email services for

[mailop] How to contact 'Silverpop' Abuse Desk?

2019-07-23 Thread Benoit Panizzon via mailop
Dear List Silverpop is an email marketing platform accredited by CSA, therefore whitelisted with some email platform operators. They add such a header in emails via their plattform: X-CSA-Complaints: whitelist-complai...@eco.de Well one silverpop customer keeps sending spam to one of our

[mailop] How to identify source of email sent via Google?

2019-07-18 Thread Benoit Panizzon via mailop
Hi List Operating the SWINOG Blacklist and Spamtraps, I notice quite some spam originating from Google IPv6 Ranges (yes, trying to catching up whitelisting them, which is not easy with their constant morphing). Usually the Received: Line parser skips a line indicating a whitelisted souce IP.

Re: [mailop] Any URI whitelists out there?

2019-07-11 Thread Benoit Panizzon via mailop
> Have you taken a look at white.uribl.com: Perfect, exactly what I was looking for. Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden __ Zurlindenstrasse 29 Tel +41 61 826 93

[mailop] Any URI whitelists out there?

2019-07-11 Thread Benoit Panizzon via mailop
Hi Mailops! We operate the SWNIOG Blacklists and Spamtraps. We fairly often find URI which make it onto the blacklist, which should clearly be whitelisted. Like 'apple.com' just this week. We do maintain a whitelist, but I start wondering, if there are DNS based URI whitelists which we could

[mailop] SPF: What happens if includes specify different 'all' settings?

2019-06-27 Thread Benoit Panizzon via mailop
Hi List Just wondering as I have come across this situation multiple times. A domain includes an SPF entries which have different 'all' settings. Which one is valid? I would have guessed, that an 'include' should never contain the 'all' statement to make it possible for the domain owner to

Re: [mailop] Any contact to Google to debug 'aspmx' troubles?

2019-05-28 Thread Benoit Panizzon via mailop
Hi Grant > Why are messages, presumably from a human, outbound from RT/4 setting > the Precedence: header to bulk? I suppose to silence auto-responders to prevent them to play email ping-pong. I know the good old 'vacation' tool does not reply on presence of the bulk header. And also RT/4

[mailop] Any contact to Google to debug 'aspmx' troubles?

2019-05-27 Thread Benoit Panizzon via mailop
Hi all I'm looking for a contact to Google (or anyone with insight on what could cause the problem) to solve a specific issue we have with a company using their ASP services. Observed Problem: I send them an email from the email client 'claws-mail'. This is received perfectly. But we use RT/4

Re: [mailop] Anyone on this List with Access to Amazon SES Maillogs?

2019-05-17 Thread Benoit Panizzon via mailop
> >nc: connect to rrmx.imp.ch. port 25 (tcp) failed: Network is unreachable > >nc: connect to rrmx.imp.ch. port 25 (tcp) failed: Network is unreachable > >nc: connect to rrmx.imp.ch. port 25 (tcp) failed: Network is unreachable > > > >So maybe AWS SES is trying to connect to the IPv6 address and

[mailop] Did CloudFlare change tolerant attitude against spamer?

2019-05-16 Thread Benoit Panizzon via mailop
Hi List I have noticed that we didn't get any spamtrap hits advertising cloudflare.com in the last couple months. Before, spamers did love their anonymizing proxy service and their policy which stated as long as it's not DMCA or CP related we won't take down a customer's site. Is still states

[mailop] Anyone on this List with Access to Amazon SES Maillogs?

2019-05-16 Thread Benoit Panizzon via mailop
Please contact me off-list Short story: A customer of Amazon SES is attempting to send emails to one of our customers. Our customer is not getting them, we don't see ANY trace of those emails in our logs, they just seem to disappear in transit. Re-Tested yesterday, exact times known. Long

[mailop] Mylove@1

2019-05-16 Thread Benoit Panizzon via mailop
Hi List I wonder if others have also stumbled over the password "Mylove@1". We use RoundCube as Webmail. We have 'stupid' customers, who give away their email password by answering to phishing emails or just simply are victims of trojans stealing their credentials. Subsequently those accounts

[mailop] Anyone with contact to: Digibyte Media B.V. Netherlands?

2019-05-13 Thread Benoit Panizzon via mailop
Hi List Since a couple of weeks our customers (and some of our support email addresses) get spam emails advertising erotica services hosted by DigiByte Media B.V. in the Netherlands. Blocking is not easy, as the sender IP, content of emails and redirection service URI used keeps changing. Their

[mailop] DigitalOcean calling for social media s* storm? (Re: Why is it so hard to have takedown's performed..)

2019-04-29 Thread Benoit Panizzon via mailop
Hi List I wonder if DigitalOcean is running for some social media related wake-up call. I Twittered to @digitalocean about the lack of responsiveness from their abuse desk. They promptly replied via Twitter: "We apologise for the trouble. Our security & operation team is already looking into

[mailop] All mx?.hotmail.com down?

2019-04-23 Thread Benoit Panizzon
Hi List A customer told us he is getting timeouts trying to send emails to a recipient under @accountprotection.microsoft.com. It looks like he is trying to reply some sort of challenge response system which I guess is not meant to be used by email. mail.msa.msidentity.com mail is handled by 5

[mailop] Outage @outlook.com creating invalid sender addresses?

2019-04-12 Thread Benoit Panizzon
Hi List Today, our support team started getting quite some emails from legitimate customers, but with envelope sender and From: header looking like: From: "Firstname Name" That Hex String is different for each sender. Recieved: header show, they got sent via outlook.com plattform, but the

[mailop] AS Number RBL (Re: Digital Ocean Sextortion Spammers..)

2019-04-11 Thread Benoit Panizzon
Hi List Our Mail Infrastructure just got hit by a new sextortion wave originating from vairous IP @ AS14061 I wondered, aren't there any RBL providers blacklisting whole AS ip ranges or returning the AS number when queried with the reversed IP, so blocking / penalizing could be easily

Re: [mailop] Digital Ocean Sextortion Spammers..

2019-04-08 Thread Benoit Panizzon
> This has gone on now for more than a month, and they aren't even trying > to hide.. Interesting digitalocean is also hosting at least two UBS.com phishing sites and it took quite a while to persuade their abuse-desk to verify by looking at the code of the site, or to use an VPN to access

Re: [mailop] Quick question on SPF...

2019-01-24 Thread Benoit Panizzon
Hi Eric > Is this a legit method? Looks like it's a typical round-robin so will fail > more often then work.. As far as I remember, 'a' does just specify ip address without specifying the protocol version. So if a hostname is ipv4/ipv6 dual stack, 'a' includes all ipv4 and ipv6 addresses that

Re: [mailop] What should an MTA do when receiving 452 4.5.3 (aka too many recipients)

2018-12-13 Thread Benoit Panizzon
Hi Michael > Kind of breaks the chain of responsibility though, so make sure you have > good logging of the event. Logging alone is not good enough. Emails disappearing without a trace (for the recipient and sender) are always bad. Spam Mails usually are delivered to single recipients. So the

Re: [mailop] What should an MTA do when receiving 452 4.5.3 (aka too many recipients)

2018-12-13 Thread Benoit Panizzon
Hi Thank you for the feedback. So I wonder if others might have found a clever solution to that problem. Goal 1: Do NOT send a delayed bounce. (aka backscatter) Goal 2: Never have an email 'disappear' in the system. Goal 3: Respect Recipient's anti-spam settings. Consider an email sent to two

[mailop] What should an MTA do when receiving 452 4.5.3 (aka too many recipients)

2018-12-13 Thread Benoit Panizzon
Hi List Email is sent to multiple recipients. When for whatever reason, recipients have incompatible settings (one wants spam to be rejected during SMTP Handshake, another one wants spam to be tagged and delivered to his inbox as example).. ...during the 'RCTP TO' phase, we don't yet know what

[mailop] mailchannels.ch / mailchannels.net ESP contact?

2018-11-29 Thread Benoit Panizzon
Hi List Does anyone know about mailchannels.ch? Looks a bit like an ESP but they send out emails with a sender domain hosted on our email plattform and protected by SPF. Unfortunately this makes us receive all the bounces. https://www.mailchannels.ch/ leads to a site with many certificates, none

[mailop] Mailexperts / spamrl.com support/delisting process deadlock.

2018-11-27 Thread Benoit Panizzon
Hi List Does anybody have a good recipe on how to solve the support deadlock created by mailexperts / spamrl.com? One of our customers is blacklisted by spamrl.com. Only by spamrl. Our abusedesk has no recorded spam complaints about the IP in question. Spamrl.com requires our customer to

Re: [mailop] Microsoft SNDS "Sorry, whois.ripe.net will not let us do any more lookups today. Please come back and try again tomorrow"

2018-11-12 Thread Benoit Panizzon
Hi List Finally git positive Feedback from the SNDS Support Team. It looks like, after some escalations, they solved the issue of too many requests to RIPE. (they only had to contact ripe and ask politely for the quota to be risen I suppose). I was now able to 'Request Access' to more than just

  1   2   >