User's banner
Avatar

Clément VILLISEK [Old account]

clement@ck.villisek.fr
Joined
5 posts • 15 comments

NEW ACCOUNT: @clemv
My personal Fediverse instance will be shut down this summer, so please go to my new profile instead :)

Direct message

Hi, thank you for the answer, and sorry for the late reply :( …

I analysed the logs thoroughly, and I can confirm my SMTP server hasn’t sent any email aside the legitimate ones.
And u/voracitude 's answer confirmed my thoughts, being that the emails were sent from somewhere else.

I don’t think it’s that much unusual to use a “small” domain for spoofing: SMEs are “easy targets” usually, and if the recipient’s anti-spam isn’t configured properly then the attackers could benefit from a domain which may be small but has a good reputation.

permalink
report
parent
reply

@intelisense Oh and sorry for the second message I forgot the last part of your message. Here’s the DMARC record, I’ve been using it for months now:

_dmarc.villisek.fr.     900     IN      TXT     "v=DMARC1; p=quarantine; rua=mailto:postmaster@villisek.fr,mailto:b377e11c@mxtoolbox.dmarc-report.com; ruf=mailto:postmaster@villisek.fr,mailto:b377e11c@forensics.dmarc-report.com; rf=afrf; sp=quarantine; fo=0:1:d:s; pct=100; adkim=r; aspf=s"
permalink
report
parent
reply

@intelisense
Hello, thank you for your answer and sorry for the late reply.

I took some time analyzing my SMTP server logs, and it contains 100% legit outgoing traffic. And no successful SSH connection for weeks on the server so it can’t have been erased.
u/voracity confirms my thoughts as well. I think the issue is outside and unrelated to my server. And the e-mail address in question seems to have leaked from several places according to haveibeenpwned (the password is safe though).

RE: lemmy.world/comment/7170785

permalink
report
parent
reply

@voracitude Thank you very much! This confirms my worries, not much can be done…

permalink
report
parent
reply

@intelisense
Those are properly configured, I get a 10/10 on mail-tester dot com, as well as everything validated on mxtoolbox.

permalink
report
parent
reply

@TheBaldness
What type of error is it? Time-out, blocked, … ?

permalink
report
parent
reply

@TheBaldness
When opening the developer tools and going to the Network tab, are there errors? (refresh the page to be sure everything appears in the tab)

permalink
report
reply

@Syl
Depuis Iceshrimp. Merci, je prendrai le temps d’essayer demain.
Si ce post pose souci un admin peut le supprimer :)

permalink
report
parent
reply

@technologie Ah zut, je ne pensais pas que ça allait mal s’afficher comme ça sur Lemmy. Désolé. Qqun connait la bonne méthode pour partagée un post vers Lemmy ? Juste copier l’URL ?

permalink
report
reply