Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-05-05 Thread Alessandro Vesely via mailop
On Thu 05/May/2022 12:55:53 +0200 Bernardo Reino via mailop wrote: On Thu, 5 May 2022, Alessandro Vesely via mailop wrote: On Fri 29/Apr/2022 18:24:04 +0200 Bernardo Reino wrote:  On Fri, 29 Apr 2022, Tobias Fiebig via mailop wrote: This might be a bit of a theoretical attack thing, but lookin

Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-05-05 Thread Bernardo Reino via mailop
On Thu, 5 May 2022, Alessandro Vesely via mailop wrote: On Fri 29/Apr/2022 18:24:04 +0200 Bernardo Reino wrote: On Fri, 29 Apr 2022, Tobias Fiebig via mailop wrote: This might be a bit of a theoretical attack thing, but looking over the bounces for my nightly outbound DMARC reports I actu

Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-05-05 Thread Alessandro Vesely via mailop
On Fri 29/Apr/2022 18:24:04 +0200 Bernardo Reino wrote: On Fri, 29 Apr 2022, Tobias Fiebig via mailop wrote: This might be a bit of a theoretical attack thing, but looking over the bounces for my nightly outbound DMARC reports I actually started to wonder about this; (Mostly because I am gettin

Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-04-30 Thread Tobias Fiebig via mailop
bject: Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation That's an interesting attack. I initially thought you were going to describe placing a victim as your destination target which is something which is prevented by requiring the receiver to authorize t

Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-04-30 Thread Ángel via mailop
That's an interesting attack. I initially thought you were going to describe placing a victim as your destination target which is something which is prevented by requiring the receiver to authorize them: https://www.rfc-editor.org/rfc/rfc7489.html#section-7.1 But this is getting a spamtrap to acc

Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-04-29 Thread Bernardo Reino via mailop
On Fri, 29 Apr 2022, Tobias Fiebig via mailop wrote: Heho, This might be a bit of a theoretical attack thing, but looking over the bounces for my nightly outbound DMARC reports I actually started to wonder about this; (Mostly because I am getting scared by regularly sending DMARC reports to non

[mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-04-28 Thread Tobias Fiebig via mailop
Heho, This might be a bit of a theoretical attack thing, but looking over the bounces for my nightly outbound DMARC reports I actually started to wonder about this; (Mostly because I am getting scared by regularly sending DMARC reports to non -existing accounts on a major ESP ;-)). Maybe I am ove