cancel
Showing results for 
Search instead for 
Did you mean: 

Spam emails being sent/received

FIXED
purkle
Grafter
Posts: 46
Thanks: 16
Registered: ‎20-12-2015

Re: Spam emails from plus.com addresses

It looks like whoever is behind the Boots emails has either moved or or is now also spoofing Optonline emails - see screenshot 

purkle
Grafter
Posts: 46
Thanks: 16
Registered: ‎20-12-2015

Re: Spam emails from plus.com addresses

Thanks for the MXTOOLBOX hint @Townman 🙂

Im listed on Spamhaus according to the images attached 🙂

It took me a while but I eventually found a way to update the case!

 

PhilipHeyes
Pro
Posts: 252
Thanks: 109
Fixes: 1
Registered: ‎10-11-2021

Re: Spam emails from plus.com addresses

Plusnet's out bound email servers are seen in two _SPF lists, there were 13 servers at the last count.

These are the only ones I am concerned about being black listed causing sent emails to be rejected repeatedly by various mail operators :

https://www.nslookup.io/domains/plusnet.plus.com/dns-records/ 


mx.avasin.plus.net looks like an in bound email server. 

Our Public IP I don't expect to be defined as an known email sender.

Townman
Superuser
Superuser
Posts: 28,103
Thanks: 12,544
Fixes: 236
Registered: ‎22-08-2007

Re: Spam emails from plus.com addresses

What’s the point you are trying to make with the above link?  There’s no such sub-domain.  Plusnet.plus.com does not exist.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

PhilipHeyes
Pro
Posts: 252
Thanks: 109
Fixes: 1
Registered: ‎10-11-2021

Re: Spam emails from plus.com addresses

View the link and then scroll down to see the two _SPF entries for the list of PN outbound servers.

James_B
Community Gaffer
Community Gaffer
Posts: 386
Thanks: 820
Fixes: 10
Registered: ‎10-09-2024

Re: Spam emails being sent/received

Thanks to all that have taken the time to report this issue in the community. We’ve been sharing examples with our security team who have found no indications of any leaks from within our network. The logs indicate that the spam is originating from individual customer IPs which suggests that individual account could have been compromised. We’ve been reaching out to these customers with advice and continue to have a high level alert in place to detect further activity. If you have been affected by this issue, we’d recommend scanning your device for malware and updating your password. If the issue persists, please get in touch for further support

Townman
Superuser
Superuser
Posts: 28,103
Thanks: 12,544
Fixes: 236
Registered: ‎22-08-2007

Re: Spam emails from plus.com addresses

@PhilipHeyes 
And? What’s the value add?

There’s two SPF lists of outbound MTAs for Plusnet / Free-online / Force9 and three for the rest.  So what is the point you are seeking to convey / discuss / inform?

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

jab1
The Full Monty
Posts: 22,728
Thanks: 7,938
Fixes: 334
Registered: ‎24-02-2012

Re: Spam emails being sent/received


@James_B wrote:

Thanks to all that have taken the time to report this issue in the community. We’ve been sharing examples with our security team who have found no indications of any leaks from within our network. The logs indicate that the spam is originating from individual customer IPs which suggests that individual account could have been compromised. We’ve been reaching out to these customers with advice and continue to have a high level alert in place to detect further activity. If you have been affected by this issue, we’d recommend scanning your device for malware and updating your password. If the issue persists, please get in touch for further support


I haven't (AFAIK) been used to send the spam, but I have certainly received some, to a mailbox that to the best of my knowledge hasn't been compromised, so where did they get it from?

John
Champnet
Hero
Posts: 3,155
Thanks: 1,236
Fixes: 18
Registered: ‎25-07-2007

Re: Spam emails being sent/received

@jab1   An ex-employee with a grudge ?

Townman
Superuser
Superuser
Posts: 28,103
Thanks: 12,544
Fixes: 236
Registered: ‎22-08-2007

Re: Spam emails being sent/received

@James_B 

@jab1 's point is well made, I have seen at least two Plusnet email addresses associated with the SPAM episode which do not appear in a known data breach (Have I Been Pwned: Check if your email address has been exposed in a data breach).  So the question remains, from where might these email addresses have been harvested?

How does a business KNOW that there has not been a data breach on their systems?  It is not though a hacker leaves a note saying "You've had your data taken", like a Labour chancellor leaves a note behind saying "We have spent all the money!".

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

purkle
Grafter
Posts: 46
Thanks: 16
Registered: ‎20-12-2015

Re: Spam emails being sent/received

James can you confirm that if NO outbound emails of this nature have been seen in either our Webmail or email client that ther has been NO security breach on our own PCs and that this is a simple case of spoofing?
The warnings to check our own systems seem to contradict what we are seeing.

All I want is for my Plusnet email to be removed from any blacklist and that has not been formally addressed here - you can’t refer to individual cases but could at least provide some information/clarification on how our concerns are to be resolved 🙏.
As yet there is no sign of any resolution to my own problems 😒.
I KNOW there are other cases but the silence and lack of clear information is deafening 😔
Thanks!
purkle
Grafter
Posts: 46
Thanks: 16
Registered: ‎20-12-2015

Re: Spam emails being sent/received

I finally managed to get a little bit more help from Plusnet and spoke to a manager who used to look after some of the email problems.
We’re still not sure if the advocate that is looking after my case is back at work or not, and so the guy I spoke to this morning has reached out to his manager to ask someone to contact me today.
What I did find out which no one has told me previously is that it will be up to me to contact spamhaus to get my email address removed from the blacklist.
I’ve asked if Plusnet can provide me with some sort of supporting official note that I can give to spamhaus to smooth the process.
What a mess!!!
purkle
Grafter
Posts: 46
Thanks: 16
Registered: ‎20-12-2015

Re: Spam emails being sent/received

As soon as anyone manages to get their email removed from being blacklisted , please tell us how ! 😀
Townman
Superuser
Superuser
Posts: 28,103
Thanks: 12,544
Fixes: 236
Registered: ‎22-08-2007

Re: Spam emails being sent/received

@plusnettony / @James_B 

Can representations please be made to the team managing these issues, to request that a bulk application be raised to the black list bodies to ask for all *.plus.com sub-domains to be removed from their lists.  The expectation that each individual might do this themselves is not reasonable.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

purkle
Grafter
Posts: 46
Thanks: 16
Registered: ‎20-12-2015

Re: Spam emails being sent/received

The suggestion that we would have to resolve this ourselves was not the final formal response by just that agents belief.
I’ve just spoken to the guy dealing with my case (he called me) and he knows nothing more.
He is concerned that his level don’t know more about what is happening. He is asking the specific questions
Do we need to resolve this ourselves
Can Plusnet resolve it for us

He has promised to call me again today or tomorrow.

In the meantime I’ve reached out to Spamhsus.