4 ms·
If your mail server or appliance still relies on DNSBLs, it's high time to upgrade to a solution that doesn't. These days, a list of 'compromised Azure tenant
by PreInternet01 2y ago
If your mail server or appliance still relies on DNSBLs, it's high time to upgrade to a solution that doesn't.
These days, a list of 'compromised Azure tenant IDs' (or domains abusing the Gmail API, or dodgy Salesforce senders: Microsoft is by no means the only issue here) is way more useful than anything source-IP-related...
- CWuestefeld 2y ago> a list of 'compromised Azure tenant IDs' [...] is way more useful than anything source-IP-related... Where do I get such a thing? A large portion of my incoming spam seems to be coming from "xxxxx.onmicrososoft.com", which sounds like it might be what you're talking about.
- PreInternet01 2y agoWell, mostly from your incoming spam. The header you're looking for is `X-MS-Exchange-CrossTenant-Id`. If it ends in `aaaa`, don't touch it, as that's the freemail-outlook.com, but otherwise, feel free to (test-)reject it. To get started: 41a71966-4fa6-4839-a87d-034d66bdda33 d931cb4a-3984-4328-9fb6-96d7d7fd51b0 e85f2c00-2730-4ca5-b8d8-609b15bd4746 (all seen-in-the-wild compromised instances in the past 14 days)
- ttul 2y agoHey there, you should start a blocklist!
- PreInternet01 2y agoYeah, no, I'm good -- having seen what happened to the ones that came before me, I'm quite happy to limit myself to policing (nah, gardening) my own little corner of the Internet...
- X-Istence 2y agoAbout 70% of my spam originates from *.onmicrosoft.com. Unfortunately I can't easily block the whole thing because there is also legitimate email traffic from Office365/Azure. I have tried sending Microsoft reports, but have not heard back, and the spam continues.
- PreInternet01 2y agoYes, Microsoft is very slow in blocking their customers from sending spam, yet very quick in blocking external senders for that reason (same for Google, Salesforce, Amazon, etc. BTW). Funny how that works... But, if you can, record the `X-MS-Exchange-CrossTenant-Id` header value for the spam you receive. If it ends in 'aaaa', that means it comes from the public outlook.com/hotmail.com service, and you'll need to do text content/from-address filtering to get rid of spam. But otherwise, deny-listing the GUID you get, will do wonders to eliminate future spam from that source...
- X-Istence 2y agoFor anyone interested, here's the list for the last month or so: https://gist.github.com/digitalresistor/03ea1b8798c519a71f06a7905d276216 https://gist.github.com/digitalresistor/03ea1b8798c519a71f06... Edit: moved list to Gist.
- PreInternet01 2y agoYou... seem to get a lot of spam! Just out of interest, across how many unique local recipient addresses is this, and how did you determine these messages were illegitimate?
- X-Istence 2y agoSingle user... me. My email address is used on all my git commits/mailing lists across the web. I check my junk folder every other day to make sure that legitimate mail does not go through because I've set my rspamd config pretty tight. So all of these are classified correctly as spam by human eyes.