Spoof email is using my domain name email address but target almost only my contact list with credible content body

Since yesterday, one of my work email addresses is used to send spoof emails with phishing attachments. SPF and DKIM was configured on my domain name but not DMARC, but since yesterday in the evening, everything is configured and I receive… Continue reading Spoof email is using my domain name email address but target almost only my contact list with credible content body

Is it acceptable/common for an SMTP server to not verify the From-Address of authenticated users?

I have an account within an organisation that provides e-mail-services within their infrastructure. These can be connected to via IMAP/SMTP and Exchange and always require password authentication. Today I learned that when I change the Fro… Continue reading Is it acceptable/common for an SMTP server to not verify the From-Address of authenticated users?

I clicked what looked like an Amazon email, but it (maybe) was from an Amazon affiliate. Ended up at Amazon.com anyway. Can I safely investigate?

In a case of clicking too fast, I clicked on a picture that looked like it was from Amazon. However this was not the case. I did end up at Amazon, but I’m aware that other things could’ve taken place before I landed on the Amazon page. I … Continue reading I clicked what looked like an Amazon email, but it (maybe) was from an Amazon affiliate. Ended up at Amazon.com anyway. Can I safely investigate?

Should I take action if I receive a phishing email that passes all email sender checks?

I received an email that passed all the email sender checks (spf, dkim, dmarc), and the sent-from domain is a legitimate domain from a legitimate company. However, the email content itself was suspiciously phish-y. I even started to write … Continue reading Should I take action if I receive a phishing email that passes all email sender checks?