Jump to content

Recommended Posts

Posted

Hi, I'm not sure if this is a security risk. The domain I bought was an old used domain, and I found that the recipient address in my domain which I'm getting the spam emails is breached upon checking on haveibeenpwned. I am getting those spam emails because catch-all is enabled. Although, I don't mind those emails, I actually like reading some of them.

A while ago, I got this spam email which is coming from my own domain. I don't know how it be possible for someone to send an email to me from my own domain, even though I only have one email created in Plesk.

Screenshot_2025-07-27_17-28-42.png.405ab7cc65686d7950e3a4aff45cc7ec.png

 

Is this a kind of email spoofing, and how did they do it? should I be worried about the security of my emails?

Thank youu!!

Posted

below is the DKIM DNS record I saw in Plesk.

for the name:

_domainkey.bochard.net. IN TXT "o=-"

and for the value:

default._domainkey.bochard.net. IN TXT "v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA+SDLc/Hl5PNixlC3Z1QqVI5F0WQUTC0wA2GHBtcHm+cqyRxqCWP7OmmV5Z7Vn3nos10c8TB7chpdkPiTVeO53mrpK6ZC9fjhlfFajdLReXJvRhqR+MBCwUEw1IimwFUz35YIRwqJ2bHaqvtjhuH4oOZ45qq79GB9gsc5OGC/A74pvZBOzMt1zYo3BvwUNo2LTgcyMDTunY+ZU15PBFyE34tj8iniPctiznyx+MboWzR4FCG/igoSwuksUm591bW8PblllmtUzdIQi7ORn9P+JO+bCW29gJlJ77wxupzvelwUMbi/iNWrCnyVbJVNxHxGQTu4jzvMg74BfIGZ1YErmQIDAQAB;"

 

Posted

They're probably being sent with a fake from header to make them look like you sent them to yourself. Pretty common with spam. Plesk's email system doesn't have a good spam filter, so you're likely going to receive most if not all spam sent to your domain. Decent spam filters will discard these fake From emails as sender spoofing.

That said, DKIM, SPF, and DMARC have been set up for the domain bochard.net. We recommend sending a real email (not just the word "test" or a blank email) to https://www.mail-tester.com/ to make sure that everything is set up correctly. If you get less than a 10/10 score please post a link to the full report so we can help you fix any other issues that there may be.

  • Like 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...