eZ Platform Discussions

Emails sent are marked as potential phishing


#1

Every e-mail I’ve received from this forum is marked in my client with:

This sender failed our fraud detection checks and may not be who they appear to be. Learn about spoofing at http://aka.ms/LearnAboutSpoofing

I think additional configuration to the mailer might be needed.


#2

Hello @mnocon, thanks for the heads up, I will look into this as soon as possible.


#3

I added include:spf.discoursehosting.com to our SPF record for ez.no, that should help.


#4

Thanks @Alex.Schuster !

@mnocon can you let us know if it happens again? Thanks.


#5

Thanks @Alex.Schuster!


#6

@robinmuilwijk I’ve triggered another mail from the forum and it is not marked that way. Looks like the problem is solved :slight_smile:


#7

That is good to hear, thanks for the feedback.


#8

Unfortunately, the spoof threat is back again - today’s “eZ Community Summary” got flagged, at least for me.


#9

@Alex.Schuster can you check on @DominikaK her comment?

what Sylvain and I changed the other day is that system e-mail are sent from ezcommunity@ez.no and no longer my private e-mail address. This should not have any effect as far as I know, as you have set the SPF record on the ez.no domain.


#10

Sorry, I did not see the notification, it was files away into a folder I did not monitor.

But you are right, @robinmuilwijk - the SPF record is correct, the sending address does not matter, as long as it is something@ez.no.

@DominikaK, can you forward me such a notification e-mail, with intact headers?


#11

It seems the problem has subsided in the meantime, and recent notification are not flagged, but I will send you the last one I received.


#12

@Alex.Schuster another mail I’ve received got marked this way today - I’ve forwarded it to you.


#13

Thanks. I got the same warning in the notification mail for your reply, but I still habe no idea why this is. So I opened a ticket at Microsoft, let’s see if they can clarify this.


#14

They couldn’t. I sent them two notification mails, one with the warning, one without. They analyzed for two weeks, but they were unable to find any relevant differences, and think this might have been a temporary failure in their SPAM detecting system.

Did this happen again recently?


#15

No, it didn’t - in case it happens I’ll let you know.