Conversation

Jonathan Corbet

If you think you got spam from me — it wasn't me, honest!

It would appear that the folks at belleclair.co.jp are running an open email relay (or have been compromised entirely). Some bright individual has been using it to send out massive volumes of spam and, for reasons known only to them, chose to put my return address on it. That has resulted in just short of 40,000 bounce messages landing in my inbox.

As a way to start your day, that just isn't as fun as it sounds.

A single notmuch command made the bounces go away; a couple of lines in header_checks has, so far, prevented the arrival of about 1,000 more. But spam with my email address on it, it seems, continues to flood the net.

Time to get serious about that DMARC setup in the hope that it might help, I guess. Email is so much fun.
3
3
19

@corbet I would definitely recommend DMARC with `p=reject` (at least until backscatter wave passes), with appropriate SPF record and DKIM signing if you can easily enable it. Allowing everyone to spoof your domain should not even be an option in 2023. 😲

1
0
0
@mnalis SPF and DKIM are there and have been for some time. We just haven't done the DMARC part to tell sites that we mean it; I'm afraid to just turn it on, so I need to go through the reporting process and such, and just haven't found the time to figure out how to do that. Needless to say, my motivation level has increased...
0
0
0

@corbet email ain't what it used to be (quite literally, given the discussion of SPF, DKIM, and DMARC)

0
0
0