Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The curious case of microsoft.com #159

Closed
ale5000-git opened this issue May 28, 2019 · 4 comments
Closed

The curious case of microsoft.com #159

ale5000-git opened this issue May 28, 2019 · 4 comments
Assignees
Milestone

Comments

@ale5000-git
Copy link

ale5000-git commented May 28, 2019

After some researches:

  • account-security-noreply@account.microsoft.com (signed by accountprotection.microsoft.com) => Include DKIM signature that inexplicably almost always fail but sometimes succeed
  • maccount@microsoft.com (signed by microsoft.com) => Pass DKIM validation
  • support@mail.support.microsoft.com (signed by mail.support.microsoft.com) => Pass DKIM validation
  • postmaster@euroconsumers.onmicrosoft.com (signed by euroconsumers.onmicrosoft.com)
  • CMMRC.WNST.WW.00.IT.ARV.BRS.CS.1FL.SPT.SG.PI@css.one.microsoft.com => It miss DKIM signature, although it look spammy it is real and I get it when I have requested a business invoice from Microsoft.

*@css.one.microsoft.com that is from account support maybe should be set to NEUTRAL.
For the others it need more researches.

I have sent you some samples.

@ale5000-git
Copy link
Author

ale5000-git commented May 29, 2019

@lieser: I have sent you another mail that didn't come from Microsoft but it has Microsoft logo that shouldn't have.

It is signed by [custom-subdomains].onmicrosoft.com (these subdomains could probably be bought).

@lieser lieser added this to the 2.1.0 milestone Aug 11, 2019
@lieser
Copy link
Owner

lieser commented Aug 11, 2019

Thanks a lot for catching and reporting that onmicrosoft.com is used to sign e-mails not from Microsoft. Removed the favicon for the domain in pre release 2.1.0pre3.

I also did the following changes to the default rules:

  • *@mail.support.microsoft.com can now also be signed by mail.support.microsoft.com
  • *@css.one.microsoft.com no longer has to be signed (added a NEUTRAL rule for it)

@ale5000-git
Copy link
Author

ale5000-git commented Aug 21, 2019

  • microsoftrewards@email.microsoftrewards.com (signed by email.microsoftrewards.com) => need Microsoft icon

@lieser
Copy link
Owner

lieser commented Aug 29, 2019

added icon for microsoftrewards.com in 2.1.0

@lieser lieser closed this as completed Aug 29, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants