Skip to main content

spoofed sender, randsom email

Comments

5 comments

  • backhousemedia
    Ya, it's really annoying. A bunch of our clients have received this same "ransom" email over the past few days and they're blowing up our support. Any way to fix this globally? It's from/to their own email addresses.
    0
  • cPanelLauren
    Hi @backhousemedia and @keat63 You may want to try some of the suggestions noted in the following threads: Thanks!
    0
  • keat63
    In my case, it didn't actually come from self to self, it did in fact come from an email address with a Turkish TLD. But as the sender address was spoofed, to my end user, it looked like it came from his own mailbox. Reading at least all way through the first thread, it seems there is no solid solution. Searching mail scanner, I've seen a few instances of this, and one thing I notice, is that the actual ransom, is not text, but is in fact a jpg image. Maybe in the short term I could create a simple rule to combat this.
    0
  • cPanelLauren
    In my case, it didn't actually come from self to self, it did, in fact, come from an email address with a Turkish TLD.

    That's exactly what spoofing is! It can look different but essentially it's when someone modifies the headers to make it appear that your domain or you (or another party entirely) is sending the offending mail. SpamAssassin should be able to flag this behavior as spam though I did note that you indicated you're using mail scanner. I believe mailscanner should have settings for this as well.
    0
  • walt
    Hello, I was catching up with some old emails, and came across a ransom one from March. It appears to be very similar to this case (same from and to address, and same time period):
    0

Please sign in to leave a comment.