b0chard Posted 4 hours ago Posted 4 hours ago Hi, I'm not sure if this is a security risk. The domain I bought was an old used domain, and I found that the recipient address in my domain which I'm getting the spam emails is breached upon checking on haveibeenpwned. I am getting those spam emails because catch-all is enabled. Although, I don't mind those emails, I actually like reading some of them. A while ago, I got this spam email which is coming from my own domain. I don't know how it be possible for someone to send an email to me from my own domain, even though I only have one email created in Plesk. Is this a kind of email spoofing, and how did they do it? should I be worried about the security of my emails? Thank youu!! Quote
b0chard Posted 2 hours ago Author Posted 2 hours ago I should have posted this in Questions subforum. srorry. Quote
MoneyBroz Posted 1 hour ago Posted 1 hour ago 2 hours ago, b0chard said: Is this a kind of email spoofing Yes it is 1 Quote
b0chard Posted 29 minutes ago Author Posted 29 minutes ago 1 hour ago, MoneyBroz said: Do you have DKIM or SPF setup for your domain? I don't have, can you add for me? Quote
b0chard Posted 18 minutes ago Author Posted 18 minutes ago below is the DKIM DNS record I saw in Plesk. for the name: _domainkey.bochard.net. IN TXT "o=-" and for the value: default._domainkey.bochard.net. IN TXT "v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA+SDLc/Hl5PNixlC3Z1QqVI5F0WQUTC0wA2GHBtcHm+cqyRxqCWP7OmmV5Z7Vn3nos10c8TB7chpdkPiTVeO53mrpK6ZC9fjhlfFajdLReXJvRhqR+MBCwUEw1IimwFUz35YIRwqJ2bHaqvtjhuH4oOZ45qq79GB9gsc5OGC/A74pvZBOzMt1zYo3BvwUNo2LTgcyMDTunY+ZU15PBFyE34tj8iniPctiznyx+MboWzR4FCG/igoSwuksUm591bW8PblllmtUzdIQi7ORn9P+JO+bCW29gJlJ77wxupzvelwUMbi/iNWrCnyVbJVNxHxGQTu4jzvMg74BfIGZ1YErmQIDAQAB;" Quote
wolstech Posted 6 minutes ago Posted 6 minutes ago They're probably being sent with a fake from header to make them look like you sent them to yourself. Pretty common with spam. Plesk's email system doesn't have a good spam filter, so you're likely going to receive most if not all spam sent to your domain. Decent spam filters will discard these fake From emails as sender spoofing. That said, DKIM, SPF, and DMARC have been set up for the domain bochard.net. We recommend sending a real email (not just the word "test" or a blank email) to https://www.mail-tester.com/ to make sure that everything is set up correctly. If you get less than a 10/10 score please post a link to the full report so we can help you fix any other issues that there may be. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.