techsupport techsupport Domain facing massive e-mail spoofing attacks: Can something be done?
Jump
  • clement clement 8 months ago 0%

    Hi, thank you for the answer, and sorry for the late reply :( ...

    I analysed the logs thoroughly, and I can confirm my SMTP server hasn't sent any email aside the legitimate ones.
    And u/voracitude 's answer confirmed my thoughts, being that the emails were sent from somewhere else.

    I don't think it's that much unusual to use a "small" domain for spoofing: SMEs are "easy targets" usually, and if the recipient's anti-spam isn't configured properly then the attackers could benefit from a domain which may be small but has a good reputation.

    0
  • techsupport techsupport Domain facing massive e-mail spoofing attacks: Can something be done?
    Jump
  • clement clement 8 months ago 0%

    @intelisense
    Hello, thank you for your answer and sorry for the late reply.

    I took some time analyzing my SMTP server logs, and it contains 100% legit outgoing traffic. And no successful SSH connection for weeks on the server so it can't have been erased.
    u/voracity confirms my thoughts as well. I think the issue is outside and unrelated to my server. And the e-mail address in question seems to have leaked from several places according to haveibeenpwned (the password is safe though).

    RE: lemmy.world/comment/7170785

    0
  • techsupport techsupport Domain facing massive e-mail spoofing attacks: Can something be done?
    Jump
  • clement clement 8 months ago 100%

    @voracitude Thank you very much! This confirms my worries, not much can be done...

    4
  • techsupport techsupport Domain facing massive e-mail spoofing attacks: Can something be done?
    Jump
  • clement clement 8 months ago 100%

    @wintermute_oregon
    I tested on Mxtoolbox, it shows my server isn't an open relay.

    1
  • techsupport techsupport Domain facing massive e-mail spoofing attacks: Can something be done?
    Jump
  • clement clement 8 months ago 100%

    @intelisense
    Those are properly configured, I get a 10/10 on mail-tester dot com, as well as everything validated on mxtoolbox.

    1
  • techsupport
    techsupport clement 8 months ago 100%
    Domain facing massive e-mail spoofing attacks: Can something be done?

    Domain facing massive e-mail spoofing attacks: Can something be done? Hello, I am running my own mailserver using Mailcow and I noticed, since mid-January, a huge rise of e-mail address spoofing attacks, in three ways: (1) a lot of spam ends up in the inbox despite having rspamd. (2) a few undelivered e-mail errors (3) some e-mails with rubbish content sent to public administrations, with my e-mail address mentioned in the "via" field, but different sender address (possibly from a third hacked mailserver), end up in my inbox as well. My mailserver doesn't seem to have been hacked BTW, as e-mails were sent today and the last connection to the SMTP service was 2 days ago according to Mailcow admin UI. Here are my questions: (1) Does the address spoofing make that rubbish mail end up in the recipients' inbox? (2) Is it shown as being sent by me or by the third hacked mailserver? (3) Is there a way to block the incoming spam using that technique in rspamd? (4) Can this spoofing attack impact my domain name's reputation (blacklist, ...?) (5) Last but not least, do you think I could get in legal trouble given the fact attackers seem to spoof my e-mail to target public administrations of my country (France, in case that matters)? If so, what could prove neither me nor my mailserver are faulty? I am respecting all the good practices for e-mail security (SPF, DKIM, DMARC, and even signing my emails with an S/MIME cert). Oh and my server isn't an open relay ^\_^ Thank you! [@email](https://sh.itjust.works/u/email) [@techsupport](https://lemmy.world/c/techsupport)

    10
    13
    technology Technology Facebook degrading Firefox user experience now?
    Jump
  • clement clement 8 months ago 0%

    @TheBaldness
    What type of error is it? Time-out, blocked, ... ?

    0
  • technology Technology Facebook degrading Firefox user experience now?
    Jump
  • clement clement 8 months ago 100%

    @TheBaldness
    When opening the developer tools and going to the Network tab, are there errors? (refresh the page to be sure everything appears in the tab)

    7
  • testfediverse
    Test fediverse clement 8 months ago 100%
    Un post de test vers un article depuis Iceshrimp

    Un post de test vers un article depuis Iceshrimp Voilà un test de post vers Lemmy depuis Iceshrimp Lien vers un article pour voir : [next.ink/122730/amd-annonce-ses-apu-ryzen-8000g-am5-avec-usb4-et-quatre-cpu-ryzen-5000-en-am4/](https://next.ink/122730/amd-annonce-ses-apu-ryzen-8000g-am5-avec-usb4-et-quatre-cpu-ryzen-5000-en-am4/) [@testfediverse](https://jlai.lu/c/testfediverse)

    1
    0
    technologie Technologie - 🤖 [@technologie](https://jlai.lu/c/technologie)
    Jump
  • clement clement 8 months ago 100%

    @Syl
    Depuis Iceshrimp. Merci, je prendrai le temps d'essayer demain.
    Si ce post pose souci un admin peut le supprimer :)

    1
  • technologie Technologie - 🤖 [@technologie](https://jlai.lu/c/technologie)
    Jump
  • clement clement 8 months ago 66%

    @technologie Ah zut, je ne pensais pas que ça allait mal s'afficher comme ça sur Lemmy. Désolé. Qqun connait la bonne méthode pour partagée un post vers Lemmy ? Juste copier l'URL ?

    1
  • technologie
    Technologie - 🤖 clement 8 months ago 60%
    [@technologie](https://jlai.lu/c/technologie)

    [@technologie](https://jlai.lu/c/technologie) RE: [masto.ai/users/linforme/statuses/111726683992027048](https://masto.ai/users/linforme/statuses/111726683992027048)

    1
    5
    "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearGA
    Game Development clement 12 months ago 90%
    Are there testable demos for alternative game engines?

    Are there testable demos for alternative game engines? Hello everyone. I am getting interest in alternative game engines like Open3D Engine, Godot, Flax, Stride, Bevy, etc... But I'm surprised how hard it is to find any "playable" demos of these. The only things I was able to find were screenshots and videos, but no proper executable that shows off their performance... Do you know any demo for any alternative engine (by alternative, I mean, not Unreal or Unity) ? Thank you :-) (this is my first post on an ActivityPub community, sorry if I didn't post it the right way) [@gamedev@lemmy.ml](https://lemmy.ml/c/gamedev) [@gamedev@lemmy.blahaj.zone](https://lemmy.blahaj.zone/c/gamedev) [@gamedev@programming.dev](https://programming.dev/c/gamedev)

    8
    3
    "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearGA
    Game Development clement 12 months ago 90%
    Are there testable demos for alternative game engines?

    Are there testable demos for alternative game engines? Hello everyone. I am getting interest in alternative game engines like Open3D Engine, Godot, Flax, Stride, Bevy, etc... But I'm surprised how hard it is to find any "playable" demos of these. The only things I was able to find were screenshots and videos, but no proper executable that shows off their performance... Do you know any demo for any alternative engine (by alternative, I mean, not Unreal or Unity) ? Thank you :-) (this is my first post on an ActivityPub community, sorry if I didn't post it the right way) [@gamedev@lemmy.ml](https://lemmy.ml/c/gamedev) [@gamedev@lemmy.blahaj.zone](https://lemmy.blahaj.zone/c/gamedev) [@gamedev@programming.dev](https://programming.dev/c/gamedev)

    8
    1
    technology Technology Need recommendations for a reliable mobile phone (UK)
    Jump
  • clement clement 1 year ago 100%

    @emma@beehaw.org If you are looking for a phone with an huge battery, CAT phones ("CAT" from "Caterpillar" - yeah, they make phones) can be interesting for you. You can choose one of them depending on how much you're ready to spend on it.

    Otherwise, Fairphone 3 and 4 are good options as you can replace their battery when it dies, and they provide spare ones for as long as thhe device is supported (they support them usually much longer than most phones from other manufacturers, so far). I own a Fairphone 4 and it's very good. But maybe too expensive if it isn't your main internet/entertainment device.

    3
  • technology Technology So Elon's a "visionary" who wants to turn X into a single website where you can do everything — kinda like Yahoo!
    Jump
  • clement clement 1 year ago 100%

    @mnrockclimber@lemmy.sdf.org Oh, you're right! I didn't know about that. My bad 😄

    1
  • technology Technology So Elon's a "visionary" who wants to turn X into a single website where you can do everything — kinda like Yahoo!
    Jump
  • clement clement 1 year ago 100%

    @ajsadauskas@aus.social @technology@beehaw.org for photos, Flickr also fits: it is owned by Yahoo since 2005

    20
  • fediverse Fediverse What would an r/place-like Fediverse event look like?
    Jump
  • clement clement 1 year ago 100%

    @Magiwarriorx@lemmy.world i think it'd be very intensive in terms of disk and network usage. Not only for the r/place-like host, but also for other Fediverse server admins.

    4
  • france France Retour d'utilisation d'un smartphone vieux de 10 ans
    Jump
  • clement clement 1 year ago 100%

    " la majorité des gens n’aurait pas besoin d’acheter un smartphone neuf, si seulement les mises à jour étaient faciles à avoir après 3 ans…"

    Tout est dit en une phrase, je pense....

    2