I though y'all might find this amusing.

The class action administrators of the lawsuit against Experian for the breach of 15 million T-Mobile customers' data revealed in 2015 just sent out emails to the millions of class members notifying them about how to collect their benefits under the lawsuit settlement.

The domain the emails came from has a p=reject pct=100 DMARC policy, and the emails failed DMARC checks, since neither SPF nor DKIM was aligned: the From: line of the emails said "@classact.com", while both the DKIM signature and envelope sender domain said "bluehornet.com".

This means that most of the victims sent these emails will never see them.

It gets better. When I attempted to email the lawyers from the lawsuit to notify them about the problem and ask them to fix it, my email was bounced for two of the recipients, because the email list for the lawyers is hosted on outlook.com and it modified my message and broke the DKIM signature before forwarding it on to those two recipients.

SMDH.

You can read more details on my blog <https://blog.kamens.us/2019/08/02/experian-t-mobile-class-action-lawyers-send-victims-important-emails-guaranteed-to-be-rejected-by-most-recipients/> if you're curious.

  jik


_______________________________________________
dmarc-discuss mailing list
dmarc-discuss@dmarc.org
http://www.dmarc.org/mailman/listinfo/dmarc-discuss

NOTE: Participating in this list means you agree to the DMARC Note Well terms 
(http://www.dmarc.org/note_well.html)

Reply via email to