This media is not supported in your browser
VIEW IN TELEGRAM
Even if hardly E-Mail-related: Here's a little rant from Roger Waters about our privacy. Enjoy! 😊
Microsoft has sunk a massive Office 365 email hijacking campaign https://www.techradar.com/news/microsoft-sinks-massive-office-365-email-hijacking-campaign
TechRadar
Microsoft has sunk a massive Office 365 email hijacking campaign
BEC campaign used cloud-based infrastructure to scale.
Feliz Viernes!
The new deliverability.tv episode is here! Featuring Yanna-Torry, the founder of letsauthenticatetheworld.com, a great project that InboxSys are proud to sponsor.
Check it out!
https://www.youtube.com/watch?v=LPkCoT9p2L8
The new deliverability.tv episode is here! Featuring Yanna-Torry, the founder of letsauthenticatetheworld.com, a great project that InboxSys are proud to sponsor.
Check it out!
https://www.youtube.com/watch?v=LPkCoT9p2L8
YouTube
Deliverability.TV - Episode 036: "Let's authenticate the world" with Yanna-Torry Aspraki
In this episode, we speak about our guest Yanna-Torry Aspraki and her project "letsauthenticatetheworld.com". Yanna-Torry's parents emigrated from Greece to Canada, where Yanna-Torry was born, grew-up and introduced in the Deliverability community. Since…
Now Microsoft started sending DMARC reports, Gmail suddenly quit. We have heard multiple reports from senders about missing Gmail DMARC reports since 03.10.2021.
That is quite significant, since Gmail is the largest DMARC report sender worldwide.
Did anyone get DMARC reports from Gmail in the past three days?
That is quite significant, since Gmail is the largest DMARC report sender worldwide.
Did anyone get DMARC reports from Gmail in the past three days?
As you can read here, a few mail providers have been subject to DDOS attacks in the past week.
Runbox made a statement we don't mind repeating:
Anyone who is experiencing DDoS attacks is encouraged to never capitulate... ...We also encourage our respective customers to continue supporting independent email services such as the three of us now under attack.
Runbox made a statement we don't mind repeating:
Anyone who is experiencing DDoS attacks is encouraged to never capitulate... ...We also encourage our respective customers to continue supporting independent email services such as the three of us now under attack.
We had already noticed. Today it was confirmed:
Postmaster Tools IP Reputation data has not been available since 12/17/21. Google is aware of the issue and is working to resolve it
That's the second time this year...
Postmaster Tools IP Reputation data has not been available since 12/17/21. Google is aware of the issue and is working to resolve it
That's the second time this year...
Apparently, also SNDS data is missing since a few days. This is generally not uncommon. It happens regularly.
Microsoft Exchange finally has its Millennium-bug. Only two Decades late: https://twitter.com/JRoosen/status/1477120097747677184.
E-Mail Deliverability
We had already noticed. Today it was confirmed: Postmaster Tools IP Reputation data has not been available since 12/17/21. Google is aware of the issue and is working to resolve it That's the second time this year...
According to reliable rumors, Google Postmaster is showing data again. It is not known yet if and when the missing data will become available.
Important news for HORDE admins: https://thehackernews.com/2022/02/9-year-old-unpatched-email-hacking-bug.html
1&1 (hosting gmx.net, web.de and more) has made policy changes today. The new policy can be found here, here or here. You'll find 2 major changes:
1) Strict DKIM alignment is very strongly recommended. Bulk senders not aligning DKIM to the From:-header domain can expect to be blocked.
2) DMARC (with a reject-policy, of course) is now recommended.
We expect other ISPs to follow this example soon, if they haven't already.
1) Strict DKIM alignment is very strongly recommended. Bulk senders not aligning DKIM to the From:-header domain can expect to be blocked.
2) DMARC (with a reject-policy, of course) is now recommended.
We expect other ISPs to follow this example soon, if they haven't already.
"Email Authentication für Empfänger" is German for "Email Authentication for recipients". This is a document by the ECO Competence Group Email, describing Email authentication from a recipient's point of view. It's amongst the most comprehensive guides to E-Mail authentication I've seen so far.
I'm not sure if an English translation of the document is planned, but I have heard of efforts to write a second piece named "Email authentication for senders".
I'm not sure if an English translation of the document is planned, but I have heard of efforts to write a second piece named "Email authentication for senders".
eco
Email Authentication - eco
Toggle navigation E-Mail Home News Ziele Downloads Kontakt Email Authentication für Empfänger Email Authentication für Empfänger Sebastiaan de Vos sebastiaan@inboxsys.com Patrick Ben Koetter p@sys4.de version 0.6, 30.05.2022 Inhaltsverzeichnis 1. Risikobetrachtung…
Perhaps you have noticed Gmail becoming stricter about RFC violations. Maybe you've read about it on a mailing list. Somehow it's unbelievable we still have to talk about this in 2022, 30 years after RFC821 described a clear mechanism to do exactly that: block E-Mail. Not only Google is more strict on RFC violations, but also other ISPs are playing with the subject. For example, Mail.de has created a postfix milter that detects RFC violations: https://github.com/mail-de/mailheadercheck. This milter also has a dry-run mode, so you can test it without any risk. I've installed it two days ago and when I check my postfix log, I can see I would have blocked 7 E-Mails if it wouldn't be in dry-run mode:
$ grep mailheadercheck /var/log/mail.log | grep 'result=reject' | awk -F 'error_response_text=' '{print $2}' | awk -F '"' '{print $2}' | sort | uniq -c | sort -n
2 Missing Date:-Header
5 Zero or too many addresses in From:-Header
Try it out and don't hesitate to use the comment-function!GitHub
GitHub - mail-de/mailheadercheck: This milter checks some headers (From, Subject, Date) for RFC validity.
This milter checks some headers (From, Subject, Date) for RFC validity. - mail-de/mailheadercheck
E-Mail Deliverability
"Email Authentication für Empfänger" is German for "Email Authentication for recipients". This is a document by the ECO Competence Group Email, describing Email authentication from a recipient's point of view. It's amongst the most comprehensive guides to…
English translation can be found here.