EmailDiscussions.com  

Go Back   EmailDiscussions.com > Email Service Provider-specific Forums > FastMail Forum
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
Stay in touch wirelessly

FastMail Forum All posts relating to FastMail.FM should go here: suggestions, comments, requests for help, complaints, technical issues etc.

Reply
 
Thread Tools
Old 28 Apr 2016, 06:54 AM   #1
dodorkahedron
Junior Member
 
Join Date: Jun 2013
Posts: 25
Spike in amount of backscatter spam in inbox

I have received several false "delivery status notifications" (with fake forged addresses from domains I manage through FM) in the past hour that show as recognized backscatter in the header but still arrive in my inbox.

My spam level is set at Standard (always block messages from known insecure email hosts/relays; move message to Spam when score is 5+; discard when score is 10+; add score as {spam xx.x} when 5+)

Is anyone else experiencing an inbox influx of backscatter spam? Or, regular spam in the inbox, for that matter. Seems to be on the rise again over the past few weeks. (I didn't realize 419 scammers were still so active!)
dodorkahedron is offline   Reply With Quote

Old 28 Apr 2016, 07:09 AM   #2
walesrob
Essential Contributor
 
Join Date: Dec 2006
Location: UK
Posts: 392
Quote:
Originally Posted by dodorkahedron View Post
I have received several false "delivery status notifications" (with fake forged addresses from domains I manage through FM) in the past hour that show as recognized backscatter in the header but still arrive in my inbox.

My spam level is set at Standard (always block messages from known insecure email hosts/relays; move message to Spam when score is 5+; discard when score is 10+; add score as {spam xx.x} when 5+)

Is anyone else experiencing an inbox influx of backscatter spam? Or, regular spam in the inbox, for that matter. Seems to be on the rise again over the past few weeks. (I didn't realize 419 scammers were still so active!)
Yep, me too, although all but one were correctly filed into spam. Must have had about 10 DSN's in one hour, then they suddenly stopped again.
walesrob is offline   Reply With Quote
Old 28 Apr 2016, 07:21 AM   #3
Mugwhamp
Cornerstone of the Community
 
Join Date: Jul 2004
Location: Manila
Posts: 509
Quote:
Originally Posted by walesrob View Post
Yep, me too, although all but one were correctly filed into spam. Must have had about 10 DSN's in one hour, then they suddenly stopped again.
Same here, but my finely tuned spam folder is not catching them in most cases. They are using spoofed subdomains of FastMail domains that I use.
Mugwhamp is offline   Reply With Quote
Old 28 Apr 2016, 07:56 AM   #4
neilj
Cornerstone of the Community
 
Join Date: Apr 2004
Location: Melbourne
Posts: 971

Representative of:
Fastmail.fm
Make sure you have backscatter protection turned on in Settings -> Spam Protection (click the Show Advanced link).
neilj is online now   Reply With Quote
Old 28 Apr 2016, 08:16 AM   #5
dodorkahedron
Junior Member
 
Join Date: Jun 2013
Posts: 25
Thanks, Neil. I thought I'd had it set to send backscatter to the Spam folder; apparently I didn't. Thanks to everyone else for your replies as well!
dodorkahedron is offline   Reply With Quote
Old 28 Apr 2016, 09:19 AM   #6
Mugwhamp
Cornerstone of the Community
 
Join Date: Jul 2004
Location: Manila
Posts: 509
Quote:
Originally Posted by neilj View Post
Make sure you have backscatter protection turned on in Settings -> Spam Protection (click the Show Advanced link).
I know for a fact that I had it enabled before the Settings screen update, but when I checked just now, it was not enabled. FYI. BTW, is it better to set to discard or put it in my Spam folder? I don't want it to upset the fine tuning of my spam filter.
Mugwhamp is offline   Reply With Quote
Old 28 Apr 2016, 01:45 PM   #7
WormholeLawyer
Member
 
Join Date: Feb 2014
Posts: 56
I am having the same thing. Why is this impacting all of us on Fastmail? I've never had this issue before.

Also, do we need to do anything with our SPF or DKIM to stop this?
WormholeLawyer is offline   Reply With Quote
Old 28 Apr 2016, 03:17 PM   #8
anotherJeremy
Essential Contributor
 
Join Date: Aug 2004
Location: Japan
Posts: 226
I'm getting a lot of backscatter too. Could have sworn I had backscatter protection set up, but looking at my settings I saw that it was turned off. I hope turning it back on fixes the issue.
anotherJeremy is offline   Reply With Quote
Old 28 Apr 2016, 04:09 PM   #9
misc
Essential Contributor
 
Join Date: Jul 2013
Location: Germany
Posts: 251
I've not realized yet that there are advanced settings.

So, what to put in that 'Trusted Hosts' field exactly? E.g., I'm forwarding mail from my icloud.com address to fastmail. In the raw message view, I can find 'Received' headers containing icloud.com, me.com and apple.com as well. So put all those three domains as trusted host?

Same is with gmail, you can find gmail.com as well as google.com headers. Any suggestions?

Thanks,
Michael
misc is offline   Reply With Quote
Old 28 Apr 2016, 07:08 PM   #10
walesrob
Essential Contributor
 
Join Date: Dec 2006
Location: UK
Posts: 392
Wow, I had a snowstorm of these this morning. I've set up DMARC on the domains affected and the reports are coming in thick and fast. I've also temporarily changed the SPF record to -all as I only use FM for email.
walesrob is offline   Reply With Quote
Old 29 Apr 2016, 01:06 AM   #11
CyberDyne
Master of the @
 
Join Date: Sep 2004
Posts: 1,583
Huge amount of these in the last 48 hours but worryingly, while they were all initially sent from a faked alias of a number of my addresses, some were from aliases I've never even sent email from. I do hope there's not been some sort of breach during which said aliases were harvested.
CyberDyne is offline   Reply With Quote
Old 29 Apr 2016, 01:46 AM   #12
dodorkahedron
Junior Member
 
Join Date: Jun 2013
Posts: 25
I've received 29 more of these since I posted yesterday, 19 of which arrived this morning. Most are routed to Spam since re-enabling backscatter protection, but not all.

The forged return address format follows a specific pattern in each one:
Firstname Lastname and a 3 or 4 digit number. They reference an "invoice" and usually have an attachment. I'm worried that my domains, which I use solely for personal email, will end up being blacklisted.

Btw, I have two new domains which have not yet been used to send/receive mail and those have not seen any backscatter activity. It's the domains I use for public posting on listservs and forums that have been involved (so hopefully it's just bad actors webscraping addresses and not a breach within FM itself.)
dodorkahedron is offline   Reply With Quote
Old 29 Apr 2016, 02:51 AM   #13
BritTim
The "e" in e-mail
 
Join Date: May 2003
Location: mostly in Thailand
Posts: 3,090
It is sending servers, not domains, that get blacklisted, so that concern (at least) should be groundless.
BritTim is offline   Reply With Quote
Old 29 Apr 2016, 03:15 AM   #14
janusz
The "e" in e-mail
 
Join Date: Feb 2006
Location: EU
Posts: 4,942
Quote:
Originally Posted by BritTim View Post
It is sending servers, not domains, that get blacklisted.
Really?
From the Spamhaus site:
Quote:
The Spamhaus DBL is a realtime database of domains (typically web site domains) found in spam messages [...] The DBL is queriable in realtime by mail systems thoughout the Internet, allowing mail server administrators to identify, tag or block incoming email containing domains which Spamhaus deems to be involved in the sending, hosting or origination of Unsolicited Bulk Emai
(my emphasis)
janusz is offline   Reply With Quote
Old 29 Apr 2016, 06:37 AM   #15
BritTim
The "e" in e-mail
 
Join Date: May 2003
Location: mostly in Thailand
Posts: 3,090
See https://www.spamhaus.org/faq/section/Spamhaus%20DBL#282.
Quote:
If my domain is forged in spam, will it be listed?
The DBL is built predominantly using automated spamtraps and email flow monitoring. It has many checks to prevent legitimate domains being listed. Even a large spam run that forges a legitimate domain will not cause a domain listing.

Nor is it possible for someone (say your competitor) to get your domain blacklisted by simply forging your domain and sending us a spam report. Spamhaus does not accept or process spam reports from the public.

Our system also ignores legitimate domains seen in backscatter bounce messages.
It is possible for your domain to be listed if your website has been hacked and a spam run includes links to malware infested pages on your site. Simple forged email addresses in your domain will not cause you to be listed in a DBL (though, of course, there are other issues).
BritTim is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT +9. The time now is 01:02 PM.

 

Copyright EmailDiscussions.com 1998-2022. All Rights Reserved. Privacy Policy