[Email] - Block email pretending from disroot.org #442

Closed
opened 2023-02-25 08:20:34 +01:00 by meaz · 3 comments
Owner

On support, we have had quite a few users complaining about phishing emails pretending coming from disroot.org

Could we block, in the "from", email that are marked as being sent from Disroot.org but with an email coming from something else?

See the screencapture, that will make more sense...

On support, we have had quite a few users complaining about phishing emails pretending coming from disroot.org Could we block, in the "from", email that are marked as being sent from Disroot.org but with an email coming from something else? See the screencapture, that will make more sense...
meaz added the
Mail
spam-protection
labels 2023-02-25 08:20:34 +01:00
meaz added this to the 23.03 - March milestone 2023-02-25 08:44:04 +01:00

Do you use SPF, DMARC & DKIM entries for disroot.org DNS zone?

Do you use [SPF](https://en.wikipedia.org/wiki/Sender_Policy_Framework), [DMARC](https://en.wikipedia.org/wiki/DMARC) & [DKIM](https://en.wikipedia.org/wiki/Dkim) entries for disroot.org DNS zone?
Owner

@6e2f61 yes we do. Our dmarc policy is to reject even. But this email wasn't spoofing as the from address was some random email address. The issue was the name that was trying to look like disroot and it can be anything of course. So the only way to fight it is adding it to amavis/spamassasin to reject upon content.

@6e2f61 yes we do. Our dmarc policy is to reject even. But this email wasn't spoofing as the from address was some random email address. The issue was the name that was trying to look like disroot and it can be anything of course. So the only way to fight it is adding it to amavis/spamassasin to reject upon content.
Author
Owner

After discussion, we will do it differently so I'm closing this.

After discussion, we will do it differently so I'm closing this.
meaz closed this issue 2023-03-04 07:38:24 +01:00
muppeth added this to the 23.03 - March project 2023-03-08 12:14:50 +01:00
Sign in to join this conversation.
No Milestone
No project
No Assignees
3 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: Disroot/Disroot-Project#442
No description provided.