cancel
Showing results for 
Search instead for 
Did you mean: 

Spam emails being sent/received

FIXED
Mardler
Aspiring Pro
Posts: 752
Thanks: 57
Registered: ‎01-07-2012

Re: Spam emails from plus.com addresses

What is, John? My question or the OP above?

I have no idea why PN chose to put my new topic under this one, they're different issues! It also doesn't help but hinders the OP.

PN, please rectify.

jab1
The Full Monty
Posts: 22,706
Thanks: 7,928
Fixes: 334
Registered: ‎24-02-2012

Re: Spam emails from plus.com addresses

@Mardler If your above post is in answer to my reply, the answer is : the issue you are experiencing.

John
Mardler
Aspiring Pro
Posts: 752
Thanks: 57
Registered: ‎01-07-2012

Re: Spam emails from plus.com addresses

It was, John.

I have had no response from PN nor did I see anything relevant before I posted a new topic. Are you talking about the referral mentioned above? If so, it's not necessarily the same issue.

The two topics should have been kept separate.

jab1
The Full Monty
Posts: 22,706
Thanks: 7,928
Fixes: 334
Registered: ‎24-02-2012

Re: Spam emails from plus.com addresses

@Mardler I tend to agree that the issue you refer to is not related really to the topic it has been merged into, but that was not my decision.

John
Batphone
Rising Star
Posts: 79
Thanks: 29
Registered: ‎14-07-2017

Re: Spam emails from plus.com addresses

The "Boots store survey" issue does appear to be different to the one reported by the OP, but might the be related in some way?

 

jab1
The Full Monty
Posts: 22,706
Thanks: 7,928
Fixes: 334
Registered: ‎24-02-2012

Re: Spam emails from plus.com addresses

Could be/may be, but I have asked the mods to review the merge.

John
Townman
Superuser
Superuser
Posts: 27,998
Thanks: 12,495
Fixes: 235
Registered: ‎22-08-2007

Re: Spam emails from plus.com addresses

@Mardler 

Boots survey is but one flavour of nefarious activity hitting PN mail accounts.  I’ve got evidence from @jab1 which matches my own experience, that having nothing to do with the subject of Boots.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

RedRobotSteve
Newbie
Posts: 3
Registered: ‎09-06-2017

Re: Spam emails from plus.com addresses

I'm also getting the same boots survey messages (4 so far), all addressed to subaddress@myusername.plus.com, all apparently(?) from some random plusnet user.

Easy enough for me to spot, since I know this particular subaddress was stolen back in 2017, and it has been automatically tagged and blackholed since then.  Though it's been a good few years since this particular email address was targeted.

 

 

Townman
Superuser
Superuser
Posts: 27,998
Thanks: 12,495
Fixes: 235
Registered: ‎22-08-2007

Re: Spam emails from plus.com addresses

How is the target address “blackholded?”

Have you made it an alias of your own black hole mailbox or do you divert SPAM to the same?

If the address was blackholded in the straight forward sense, you would never have seen it.

This reminds me to go check my black hole mailbox!!

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

PhilipHeyes
Pro
Posts: 244
Thanks: 108
Fixes: 1
Registered: ‎10-11-2021

Re: From address doesn't meet the authentication requirements defined for the sender

I have started to receive fake "Boots Survey" spam emails and they are from <account>.plus.com
They are not being detected as [-SPAM-] by the Plusnet inbound spam filters.

In the last two days three different version of <account>.plus.com have been used all have valid _SPF / DNS entries,
so I shall not list them here as they could well be genuine customers being hijacked.

If this is a widespread problem, it would come as no surprise the SMTP servers are landing on the blocked lists of iCloud, Microsoft, Talk Talk and Tiscali.

The sending SMTP servers are using the host names from Plusnet's _SPF but the IPs do not match.


Received: from avasout-ptp-004.plus.net ([192.168.2.6])      ( Note the Private LAN IP )

Received: from avasout-ptp-002.plus.net ([84.93.223.46])    ( Should be IP 84.93.230.235 )

Received: from avasout-peh-004.plus.net ([84.93.223.46])    ( Should be IP 212.159.14.20)


Looking up the one public IP  84.93.223.46 that has been used twice with two different host names :

84.93.223.46.bizsurf.pth-ag2.dyn.plus.net     ( this does not have any _SPF records )

Anyone else seeing similar to this ?


jkg
Grafter
Posts: 35
Registered: ‎18-12-2007

Re: From address doesn't meet the authentication requirements defined for the sender

I received some of these fake Boots survey emails, so I forwarded them report@phishing.gov.uk, as one does.
But the forwards came back as undeliverable!
PhilipHeyes
Pro
Posts: 244
Thanks: 108
Fixes: 1
Registered: ‎10-11-2021

Re: From address doesn't meet the authentication requirements defined for the sender

I have just forwarded the last three fake Boots survey emails to report@phishing.gov.uk
and received one conformation reply email, no delivery rejections.

RedRobotSteve
Newbie
Posts: 3
Registered: ‎09-06-2017

Re: Spam emails from plus.com addresses

I mean it's locally tagged so it sticks out like a sore thumb should I happen to see it.

So as to remind me that regardless of how "compelling" the message is, if it's to one of the subdomains I know have been compromised, I'm sure not going to pay any real attention to it.

 

 

Townman
Superuser
Superuser
Posts: 27,998
Thanks: 12,495
Fixes: 235
Registered: ‎22-08-2007

Re: Spam emails from plus.com addresses

Ah. you are using client based email marking rather than...

 

image.png

Found here - https://www.plus.net/manage_my_mail

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Batphone
Rising Star
Posts: 79
Thanks: 29
Registered: ‎14-07-2017

Re: Spam emails from plus.com addresses

The one I received today is interesting as it indicates a possible targetting of PlusNet employees. There are 4 links embedded in what looks like two links in the signature. I tried to attach a file with the full headers but got a 404 Forbidden message.

(BTW, just to make clear, I do not work for PlusNet, BT or EE or any ofther partner company).

 

Dear Team,

Kindly check staff memo referring to the above subject from HR for our annual open vacation plan.


<redacted>

Please do note that all names highlighted in  Red are the ones approved for open vacation.

kindly return your response to verify date on or before 9/28/2025 5:21:51 p.m. .

Please let me know,should you have further questions.

  
Thanks & Regards,

Director of Human Resources

HR Manager
Email :- <redacted>

Web   :-<redacted>