Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Spam from Gmail.com
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Spam from Gmail.com

Hi everyone,

More of a curious thing than an actual problem (so I stuck it in the general category) is anyone else seeing increased spam from Gmail.com addresses that actually looks to have been relayed through Gmail? ....getting quite a lot at the minute

Thanked by 1angelius

Comments

  • No, not for me. On average I get maybe 1-2 odd spam e-mails via google in 3 month time. They all are in russian and usually beg me to donate to some "good" cause.

    Thanked by 1chip
  • stormstorm Member
    edited August 2023

    I receive a few a week. I report them here: https://support.google.com/mail/contact/abuse
    Not sure it does any good though.

    Thanked by 1gartenzaun
  • I have had that problem for a while now (maybe a year).

    Just regular text emails, sometimes with a PDF attachment, from gmail.

    Thanked by 1chip
  • Gmail.com is ok,what's worse is outlook.com,99% email from outlook.com to my domain is scam or phising.
    All emails from outlook.com go to junk unless it is whitelisted.Before i reported more than a hundred at spamcop,but seems no use,there are too many,all are really from outlook.com,all SPF passed.So best way to stop it is making a rule to let all of these go to junk!!

    Thanked by 1chip
  • Yup. Reporting does nothing, and I obviously can't block gmail like I could block random badly configured servers like I used to. Only big provider who has that issue, at least for me.

    Thanked by 1chip
  • chipchip Member

    @shruub said:
    Yup. Reporting does nothing, and I obviously can't block gmail like I could block random badly configured servers like I used to. Only big provider who has that issue, at least for me.

    I've resorted to using them to train the baysian filtering..... seems to be working for now and only the odd one slips through .... but seeing loads of them rejected in rspamd and a few months ago didn't see any

    I think its quite ironic as Gmail has more recently stopped accepting unauthenticated email from external sources.... what are they going to do to help external sources stop receiving spam from them?

  • maverickmaverick Member
    edited August 2023

    Yeah, I have noticed incresing spam volume from Gmail lately, too. >:)

    It's true, much harder to block spam from Gmail, because you can't just blacklist Gmail IP's.

    But... as soon as i noticed that spam volume from Gmail increased, I looked for any clue in the message headers and actually managed to find it.

    It's simple: if it has "undisclosed.recipients:;" in the To header, it must be spam. This single rule has rejected 100% of Gmail spam this year (dozens of attempts). B)

    YMMV, if you need to receive emails where you're not mentioned in the To header, then it is dangerous, obviously. I'm so tired of spam that I decided to risk, and it paid off, no spam from Google.

    Now, has anybody noticed increasing spam from Contabo & Colocrossing, starting this spring/summer?

    Contabo can be easily filtered with the same rule I mentioned for Gmail (RBL's are so far pretty ineffective there, as if this is some brand new spam campaign).

    Colocrossing seems to be well covered with RBL's I use, so far... Though the volume of spam that suddenly started arriving is a bit alarming, if it starts to leak through filters, probably the only remedy would be to blacklist the whole ASN.

  • @chip said:

    @shruub said:
    Yup. Reporting does nothing, and I obviously can't block gmail like I could block random badly configured servers like I used to. Only big provider who has that issue, at least for me.

    I've resorted to using them to train the baysian filtering..... seems to be working for now and only the odd one slips through .... but seeing loads of them rejected in rspamd and a few months ago didn't see any

    I think its quite ironic as Gmail has more recently stopped accepting unauthenticated email from external sources.... what are they going to do to help external sources stop receiving spam from them?

    Interesting! I might try the training as well. But, I suppose, if you are as large as gmail, there will always be some spam. Don't feel like defending Google, but it's probably the people setting their password to "Ilikecats123" or just entering them on random sites. Most of the address I receive spam from seem like "legit" users, judging by the name.

  • jarjar Patron Provider, Top Host, Veteran

    Huge uptick in invalid Gmail addresses sent from Google cloud boxes. They look like they're hoping to hit someone who improperly whitelisted all Google IP space or something.

    Thanked by 1chip
  • Gmail decided not to send me any spam emails... thank god it saved my mailbox.

    Thanked by 1chip
  • chipchip Member

    @maverick said:
    Yeah, I have noticed incresing spam volume from Gmail lately, too. >:)

    It's true, much harder to block spam from Gmail, because you can't just blacklist Gmail IP's.

    But... as soon as i noticed that spam volume from Gmail increased, I looked for any clue in the message headers and actually managed to find it.

    It's simple: if it has "undisclosed.recipients:;" in the To header, it must be spam. This single rule has rejected 100% of Gmail spam this year (dozens of attempts). B)

    YMMV, if you need to receive emails where you're not mentioned in the To header, then it is dangerous, obviously. I'm so tired of spam that I decided to risk, and it paid off, no spam from Google.

    Now, has anybody noticed increasing spam from Contabo & Colocrossing, starting this spring/summer?

    Contabo can be easily filtered with the same rule I mentioned for Gmail (RBL's are so far pretty ineffective there, as if this is some brand new spam campaign).

    Colocrossing seems to be well covered with RBL's I use, so far... Though the volume of spam that suddenly started arriving is a bit alarming, if it starts to leak through filters, probably the only remedy would be to blacklist the whole ASN.

    I hadn't noticed the undisclosed recipients header .... thats something I could block as any mailing list should be putting me in the to field or there probably not for me

    As for contabo and colocrossing I haven't seen that, yet; hopefully it stays that way... I do have one that has "chased" me for years goes after a specific domain and it appears to be a windows server ... it identifies itself as win-(random string) ... so it fails ptr/dns etc and never gets any further but he's been there across 3-4 different virtual servers all with different provided and ASN's .... but its always the same IP so simple to block and sends as [email protected]

  • keplerkepler Member
    edited August 2023

    Its mostly a BCC spam. For anyone that uses custom domain, enabled catchall and gave unique email address for each service to track leak or hacks or simply provider selling customer email address, the spam defeat it because you can't track which unique email address is being spammed to since the TO header is empty. Just create a rule to discard, reject or mark spam incoming email without the symbol @ in TO header

Sign In or Register to comment.