3 ms·
Scammers exploited a bug in Gmail to impersonate UPS, Google closed as won’t fix
- bombcar 3y agoThat's a weird subdomain, somehow they got one allocated.
- kiwijamo 3y agoGasp, Google ignoring established standards. /s Google has a strange relationship with spam. When I operated my own mail server I discovered much more than 50% of spam was from their network. So stuff like this comes at no surprise to me. Where is their incentive to do good? They own a significant part of the email market despite their poor behaviour over the years.
- jsiepkes 3y ago> Gasp, Google ignoring established standards. /s Actually Google is adhering to the standard. The sender is using a valid 'ups.com' subdomain it seems. So this seems more like a problem on UPS'es end. If Google actually made changes because of this THEN it wouldn't be adhering to standards.
- nubinetwork 3y agoThat's okay, sorbs.net has most of Gmail's servers blocked due to spam... the ones that aren't will probably get caught by spamassassin.
- justsomehnguy 3y ago> sorbs.net Thanks, I thought what a blackout from a faulty backup diesel in the datacenter was a problem for me today. You reminded me what there are people who needs to fight with SORBS. I feel (a bit) better now.
- aaron695 3y agoLogic is the spammers have worked out how to abuse UPS mailing infrastructure. UPS screwing up is more believable than Google. > The sender found a way to dupe @gmail ’s authoritative stamp of approval This has two meanings, if dupe means fool, then no. If dupe means duplicate, aka the spammers are injecting a fake stamp of approval then that's interesting. There's little to comment on without those headers and email contents.
- burnished 3y agoThere doesnt seem to be enough information to corroborate what this person is claiming. Those records are also DNS records, without evidence to the contrary I am assuming that they are functioning as normal, so if there is a problem then it seems reasonable that it is with some one with access to that UPS subdomain. I do not get why gmail is being blamed here, but perhaps I'm simply missing a concrete detail. Failing that this reads like OP is unwittingly asking google to extend their reach.
- 2000UltraDeluxe 3y agoIt looks like one of those subdomain names used by scammers who use hijacked DNS accounts to create subdomains on legitimate domains and use them for phishing. _IF_ that is the case, then it must have been in the UPS end.
- burnished 3y agoFollowup in case anyone sees: turns out OP was correct, a french language Linkedin post that details the exploit: https://www.linkedin.com/posts/christophe-dary-85330561_spf-dmarc-bimi-activity-7070510499196489728-pPTh https://www.linkedin.com/posts/christophe-dary-85330561_spf-...