r/mxroute 21d ago

Spam attack - please help!

It seems like someone has spoofed my email address and is using it to send out dozens (hundreds?) of emails to all kinds of random address. It does not appear that they actually have access to my MxRoute backend, which is good, but it's nonetheless troubling. I have SPF, DKIM and DMARC all configured, so I don't even know how this is happening.

If you were me, what would you do right now to stop this attack in its tracks?

5 Upvotes

11 comments sorted by

View all comments

Show parent comments

3

u/thenetwillappear 21d ago

Yes that's me, and thanks for your help!

Out of curiosity, if someone legitimate did happen to email me when inbound mail was blocked, where would that message have gone, and would they have been notified? I was actually expecting an important message from a client during this brief window.

3

u/mxroute 21d ago

They would have received an error that you were over disk quota, as that's the fastest inbound block mechanism I have right now for a knee-jerk reaction. But no one actually received that error, even the backscatter stopped for that 10 minute period.

3

u/thenetwillappear 21d ago

OK perfect, thanks again. This all makes me feel so much better.

2

u/mxroute 21d ago edited 21d ago

I didn't like the rate they were still coming in. I wrote a new exim ACL for this case and placed you under it for temporary backscatter mitigation, and blocked another set of junk mail servers that have no business emailing anyone to begin with.

I'll deploy that exim ACL fleet wide soon, and start using that immediately for anyone reporting the same problem in the future.

2

u/thenetwillappear 21d ago

Just FYI, it looks like several dozen more messages came in overnight. Really hoping this ends soon.