5 ms·
Heh, I received a spam email through my gmail which bypassed the spam filters and decided to investigate. It had DKIM signing as the sender was an Exchange 365
by comprambler 4y ago
Heh, I received a spam email through my gmail which bypassed the spam filters and decided to investigate. It had DKIM signing as the sender was an Exchange 365 mailbox. The spam message originated from an Amazon SES which hooked through a compromised Exhange 365 mailbox. I contacted Microsoft Security Response with the Exchange mailbox in question to get this bullshit response.
The activity reported is associated with a customer account within the Microsoft Azure service. Microsoft Azure provides a cloud computing platform in which customers can deploy their own software applications. Customers, not Microsoft, control what applications are deployed on their account.
So why are even we using DKIM at all if bad actors can abuse an open cloud TOS.
- counttheforks 4y agoSo we can blacklist the key that facilitates this abuse.
- deleted 4y ago[deleted]
- comprambler 4y agoThe likely design fault here is the key is the same for every O365/exchange online client (if they are using MS as their outbound transport). It should be unique so every client could have their own reputation.
- cfeduke 4y agoI had a similar experience where email messages that should trivially be detected as spam were getting through to a Gmail inbox, originating from Exchange 365 with proper DKIM authorization. It's incredibly frustrating - I was getting between 10-12 an hour. I had to write a Google Apps script to automatically move these trivially detectable spam messages from my inbox into spam. I expect any sort of abuse report to Microsoft wouldn't result in any action on their part, just as reporting these messages as spam for about a month did nothing on the Gmail side.
- Marsymars 4y ago> I expect any sort of abuse report to Microsoft wouldn't result in any action on their part, just as reporting these messages as spam for about a month did nothing on the Gmail side. False positives are similarly annoying. I spent years reporting emails from Kijiji (while they were an eBay subsidiary) to gmail as "not spam". Set up a rule to redirect them from the spam folder to inbox, but they still get tagged as spam when I open them.
- codalan 4y agoI think DKIM was a good idea at the time of its inception. It caught a lot of the low hanging fruit, which was spammers who spoofed domains. But yeah, now anyone can buy a domain for dirt cheap, setup DKIM, and start spamming away. At least with DKIM, you have a basis for blocking a domain outright. That is, until they buy up another domain and repeat their spamming activities again. Email has really fallen apart in the past decade. When it's not spam, it's retailers and other companies sending me unsolicited, unwanted marketing emails, entirely without my consent. They are the bulk of the garbage in my inbox today. It's amazing to think that companies still think this is a valid way to advertise products and services. At best, people get annoyed and dump you in the Junk folder. At worst, they view it as a form of begging by a desperate company looking for money, and those people definitely won't be interested in buying anything from you ever again. If there was a way to measure it, I would be that companies are losing more money from annoying spam marketing campaigns than from the .00001% that do convert. Mailchimp, Constant Contact and their ilk are truly a scourge upon our inboxes. You know they're truly terrible companies because if they ever provided a global opt-out of all their email lists from all their clients, they'd go out of business. One of these days I will just create another self-hosted email service of my own with a fresh domain and only whitelist it with recipients that I actually care to hear from.
- MrTortoise 4y agoallow list
- soulofmischief 4y agoYou need to stop and ask yourself if this kind of comment adds any value to the discussion. It's not even offering a good reason for OP to make a change to their language; it's pure nagging.
- bushbaba 4y agoOne way to prevent is to make the cost of churning domains expensive. E.g. requiring registration with a $250 one time fee