[mailop] Transparency is key... Here is a perfect example.. M3AAWG is coming.. time to take a stance?

2023-05-30 Thread Michael Peddemors via mailop

18.156.43.163   (M)   1   guardpost-n08.euc1.mailgun.co
18.157.58.83(M)   1   guardpost-n07.euc1.mailgun.co
18.157.75.126   (M)   1   guardpost-n01.euc1.mailgun.co
18.158.176.19   (M)   1   guardpost-n02.euc1.mailgun.co
18.197.223.145  (M)   1   guardpost-n05.euc1.mailgun.co

Registrar: NameCheap, Inc.
Registrar IANA ID: 1068
Registrar Abuse Contact Email: ab...@namecheap.com
Registrar Abuse Contact Phone: +1.6613102107
Domain Status: clientTransferProhibited 
https://icann.org/epp#clientTransferProhibited

Registry Registrant ID: REDACTED FOR PRIVACY

whois on the IP?

18.156.0.0/14 AMAZO-ZFRA
Organization:   A100 ROW GmbH (RG-123)

Company Description: 
Key Principal: A. Masone   See more contacts
Industry: Computer Systems Design and Related Services ,  Computing 
Infrastructure Providers, Data Processing, Web Hosting, and Related 
Services ,  Professional, Scientific, and Technical Services ,  Computer 
facilities management ,  Data processing and preparation


whois mailgun.net

Registrar: NAMECHEAP INC
Registrar IANA ID: 1068
Registrar Abuse Contact Email: ab...@namecheap.com
Registrar Abuse Contact Phone: +1.9854014545
Reseller: NAMECHEAP INC
Domain Status: clientTransferProhibited 
https://icann.org/epp#clientTransferProhibited

Registry Registrant ID:
Registrant Name: Redacted for Privacy
Registrant Organization: Privacy service provided by Withheld for 
Privacy ehf


http://mailgun.net/  Error 503
http://mailgun.co(Not responding)

Kind of impossible to see if these companies are even related..

How does the public find abuse contacts?

Doesn't M3AAWG have a lot to say on this subject?

At least mailgun.us has transparent whois..
  (oops, careful, they might have forgotten to hide that one)

Of course, the abuse contact for that one points to mailgun.org, WHICH 
is again 'REDACTED' for privacy.. (as is mailgun.com)


Seems that more and more of the world is intentionally hiding behind 
terms like PRIVACY and GDPR, in order to serve their business interests...



If you have to hide behind anonymity, you aren't doing things right as 
ESP, you should professionally stand behind your name.


So, if someone registers mailgun.zip, what do we have to do to ensure 
that it belongs to the right people?


And you would think a company the size of mailgun could run their own 
DNS servers ;)


Name Server: ns-445.awsdns-55.com
Name Server: ns-907.awsdns-49.net
Name Server: ns-1728.awsdns-24.co.uk
Name Server: ns-1471.awsdns-55.org


Just saying people... the more you try to 'hide' who is behind your 
operations, the more it will affect your reputation, AND your pocket book..


Sure, Amazon was one big ones that started this, and got away with it, 
and now we have people hiding on Azure, Google, and many other cloud 
providers... hackers already love hiding behind CloudFlare, and every 
little spam friendly hoster is now rebranding as a 'cloud service' to 
take advantage of the same trends..


But if you REALLY want people to take you seriously, these type of 
business practices have to stop..










--
"Catch the Magic of Linux..."

Michael Peddemors, President/CEO LinuxMagic Inc.
Visit us at http://www.linuxmagic.com @linuxmagic
A Wizard IT Company - For More Info http://www.wizard.ca
"LinuxMagic" a Registered TradeMark of Wizard Tower TechnoServices Ltd.

604-682-0300 Beautiful British Columbia, Canada

This email and any electronic data contained are confidential and intended
solely for the use of the individual or entity to which they are addressed.
Please note that any views or opinions presented in this email are solely
those of the author and are not intended to represent those of the company.
___
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop


Re: [mailop] Transparency is key... Here is a perfect example.. M3AAWG is coming.. time to take a stance?

2023-06-01 Thread Alessandro Vesely via mailop

On Wed 31/May/2023 00:13:38 +0200 Michael Peddemors via mailop wrote:

18.156.43.163   (M)   1   guardpost-n08.euc1.mailgun.co
18.157.58.83    (M)   1   guardpost-n07.euc1.mailgun.co
18.157.75.126   (M)   1   guardpost-n01.euc1.mailgun.co
18.158.176.19   (M)   1   guardpost-n02.euc1.mailgun.co
18.197.223.145  (M)   1   guardpost-n05.euc1.mailgun.co

Registrar: NameCheap, Inc.
Registrar IANA ID: 1068
Registrar Abuse Contact Email: ab...@namecheap.com
Registrar Abuse Contact Phone: +1.6613102107
Domain Status: clientTransferProhibited 
https://icann.org/epp#clientTransferProhibited

Registry Registrant ID: REDACTED FOR PRIVACY

whois on the IP?

18.156.0.0/14 AMAZO-ZFRA
Organization:   A100 ROW GmbH (RG-123)



The difference between names and numbers is amazing:

At https://rdap.arin.net/registry/ip/18.156.0.0
among other things you find:

registrant:
A100 ROW GmbH
Marcel-Breuer-Strasse 10\nMunchen\n\n80807\nGermany

abuse:
Amazon EC2 Abuse
ab...@amazonaws.com
+1-206-555-
Abuse of Amazon Web Services
The activity you have detected originates from a dynamic hosting environment.
For fastest response, please submit abuse reports via the AWS webform:
https://repost.aws/knowledge-center/report-aws-abuse
If your company system is configured to automatically send abuse reports, 
please send them to ab...@amazonaws.com including:

* src IP
* dest IP (your IP)
* dest port
* Accurate date/timestamp and timezone of activity
* Intensity/frequency (short log extracts)
* Your contact details (phone and email)

technical:
Amazon EC2 Network Operations
amzn-noc-cont...@amazon.com

noc:
Amazon AWS Network Operations
amzn-noc-cont...@amazon.com
+1-206-555-

administrative:
IP Management
ipmanagem...@amazon.com
+1-703-464-1336


Best
Ale
--













___
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop