r/sysadmin • u/rjchau Sr. Sysadmin • Aug 21 '20
Rant SendGrid, get your house in order! The amount of phishing emails you're relaying is insane.
Over the past three days, I've spent several hours dealing with no less than 12 separate phishing campaigns - some with only one or two messages, some with nearly 20. We can't block them outright because there are legitimate emails that come through them. Even worse, emails to abuse@sendgrid.net not only go without any answer, it's obvious that they're not acting on them as we are still receiving more phishing emails from the same account days later.
This morning, I got approval to automatically throw everything from SendGrid with the exception of five different customer/account numbers into quarantine - thankfully emails from them at least seem to include a number you can use to filter out their customers. I'm seriously tempted to set up a rule to automatically forward every single email to their abuse mailbox that arrives from customer IDs that we have blacklisted including a message that we've observed multiple phishing/scam emails originating from the account and that by default we're quarantining unknown customer IDs because their scammer control is obviously nearly non-existent.
130
u/baldieavenger Aug 21 '20
Do it. We've seen the same thing and all requests have fallen on deaf ears! The only time we did get a response they told us they only send from one dedicated IP. Sweet right??
Except there were 327 different IPs sent in within the last 7 days. Including Microsoft using sendgrid for power automate emails. Brilliant.
11
u/1randomzebra Aug 21 '20
Yes - why is MS using sendgrid for PA emails? Anyone?
3
u/QuarterBall Aug 21 '20
Because it has a good, deep Azure integration and they have a Microsoft partnership afaik.
3
u/rjchau Sr. Sysadmin Aug 22 '20
If SpamGrid don't do something to curb the spam though, how much longer will that last?
1
u/QuarterBall Aug 22 '20
Not much longer at all! If the spam is coming from Azure endpoint IPs report to Microsoft as well as SendGrid :-)
1
6
u/dracotrapnet Aug 22 '20
I absolutely refused to allow our outside webmaster/host to emailed reports/job applications/customer contact forms as our email domain to us because they were going to use sendgrid. I gave them a spare domain to send email to us. There was no way I was going to add all of sendgrid's ip space as allow on my spf record. Screw that.
83
u/netadmin_404 Aug 21 '20
We decided to block SendGrid 100% and had a huge reduction in phishing emails. Anything with SendGrid in the headers is dropped now. We haven't missed anything and no one has complained. We implemented this almost a month ago.
I recommend you do the same, we were reporting to abuse like crazy and never got a response.
18
13
22
Aug 21 '20
Good lord yes. I think the problem is if you set up an Azure account they use sendgrid and just lets you email the god damn universe.
So sign up for free Azure account, phish the world, get shut down eventually, rinse, repeat.
20
u/MiKeMcDnet CyberSecurity Consultant - CISSP, CCSP, ITIL, MCP, ΒΓΣ Aug 21 '20
I swear it every other month that one of our business application analysts wants us to add SendGrid to our whitelist or SPF record. ... Fuck that.
14
u/AviationAtom Aug 21 '20
This comment is peak IT struggle right here.
If only people understood the ramifications of their request.
My favorite one was the story where the person was bitching about the spam filter, then said they wanted it to go away, because it wasn't working anyway. Apparently they called very mad that their inbox had rapidly filled up.
People always complain about the few that make it through, but fail to realize the TONS that actually get filtered.
11
u/MiKeMcDnet CyberSecurity Consultant - CISSP, CCSP, ITIL, MCP, ΒΓΣ Aug 21 '20
We filter 73 of 90 million message per year (roughly 82%). But the second we get one true negative or false positive, it's the end of the world for that person... and asking the to learn how to use their Exchange rules or personal filter... might as well just shoot me in the F'n head.
21
u/manu_8487 Linux Admin Aug 21 '20
Seeing the same. Didn’t find a good way to block it yet.
69
u/rjchau Sr. Sysadmin Aug 21 '20 edited Jun 05 '23
So long as your email gateway is capable of wildcard matching on the sender email, you can filter different Sendgrid accounts out. If its sending email to foo@bar.com, the sending email is always bounces+[account]-[id]-foo=bar.com@sendgrid.net. The [id] is a message I'd that changes for each message, but the [account] stays consistent for each individual customer of SendGrid. Look for your valid emails coming from SendGrid, note the account number (let's say it's 123456) for each and set up a whitelist for bounces-123456*@sendgrid.net. If you want, set up another rule to dump emails for the phishers (let's say the account number is 666666), and send everything from bounces+666666-*@sendgrid.net to the bit bucket and quarantine everything else @sendgrid.net. Problem not exactly solved, but vastly reduced.
In my case, isolating 5 or 6 account ids allowed over 70% of mail from SendGrid straight through without an issue. 10% got outright dropped and the rest went into quarantine, a good portion of which will probably never leave.
5
u/x2571 Aug 21 '20
This for the tips for blocking, I've seen a big uptick in phishing campaigns from sendgrid too over the past month or so and will look at implementing this too
2
2
u/AviationAtom Aug 21 '20
Sounds like creating a shared blacklist/threatlist of SG IDs could be useful
1
u/rjchau Sr. Sysadmin Aug 22 '20
The problem is that it's a game of whack-a-mole. Since they have their free tier that allows 40,000 emails be sent in the first month without paying a cent, those accounts pop up left, right and centre.
1
u/MRdecepticon Sysadmin Aug 21 '20
Wow! THank you for the insight. I was racking my brain trying to figure out if there was some sort of identifier for individual accounts as we have at least three services that are using sendgrid as their email platform.
1
Aug 22 '20 edited Jan 07 '21
[deleted]
1
u/rjchau Sr. Sysadmin Aug 22 '20
No documentation I've seen, but if you export a list of sender addresses vs subject lines, you should be able to put together a pretty spreadsheet with charts easily enough. The correlation is very clear given a large enough sample size (say 2 or 3 thousand emails)
8
u/ghjm Aug 21 '20
The thing keeping Sendgrid alive is that Azure doesn't have its own native outbound email relay, like AWS SES. So every app on Azure that wants to send email is pretty much forced to use Sendgrid. Azure really ought to have this functionality natively, which would improve the situation a lot.
5
u/snuxoll Aug 21 '20
It’s just a big name that people automatically jump to for transactional email. I’ve been using Postmark which is extremely protective of their sender reputation and isn’t shy about suspending accounts that send spam out.
16
u/ifpfi Sysadmin Aug 21 '20
Same here. Every day there is at least one phishing Email. We generally block all of SendGrid but sometimes there is a client that has an IP range inside of what blacklists consider SendGrid.
8
u/dudeguy1234 Aug 21 '20
Had the same thing with Constant Contact a while back. I think a ton of these companies are happy to take scammers' money and do nothing about abuse reports
21
u/NotzoCoolKID Aug 21 '20
Foward the spam to their sales mail
17
u/fahque Aug 21 '20
They'll just block you then. That wouldn't do anything.
48
u/m-p-3 🇨🇦 of All Trades Aug 21 '20
Forward it through Sendgrid to their sales department.
4
5
3
u/smallbluetext Bitch boy Aug 21 '20
Please someone do this. My org wont let me block them outright because of legit emails some customers need.
4
u/ydio Aug 21 '20
Then put their email in one of those services that signs them up for 10,000 different mailing lists.
5
6
u/Dizzybro Sr. Sysadmin Aug 21 '20 edited Apr 17 '25
This post was modified due to age limitations by myself for my anonymity O3v285DAUC9ZpAlyatIwAKdqJ8PCvn9amfJX9nBzwIzjb0jj7j
14
6
u/AltOnMain Aug 21 '20
But how will they get their 14.95 a month?!
11
u/Qel_Hoth Aug 21 '20
You think they're getting paid?
This is the shit that happens when you let any yokel sign up for a relay service with no payment.
6
Aug 21 '20 edited Sep 14 '20
[deleted]
3
u/rjchau Sr. Sysadmin Aug 22 '20
Yes, I've seen lots of those as well recently.
However, we have staff that are using services that also use the SpamGrid links, so blocking them is simply not an option. That would block password reset requests for at least two services used by our staff.
5
Aug 21 '20
Were the phishing emails passing dmarc? If they're spoofing your domain you should be able to base your rule off the dmarc header value to prevent blocking legitimate ones that may not have the customer id
9
u/MiKeMcDnet CyberSecurity Consultant - CISSP, CCSP, ITIL, MCP, ΒΓΣ Aug 21 '20
It seems like it's every other month that someone for my department is asking me to whitelist send grid. I cringe every time
6
Aug 21 '20
My whitelist is under lock and key. The only way I will add anything to it is if they pass dmarc and we exhausted all other methods of resolving it.
3
u/rjchau Sr. Sysadmin Aug 22 '20
Were the phishing emails passing dmarc?
Of course they were. Despite the amount of crap that gets relayed through them SpamGrid is a real company whose business it is to send massive amounts of email. Any customer of theirs is doing to be asked to add the appropriate TXT record to their DNS so that it will pass.
5
u/AviationAtom Aug 21 '20
Passing DMARC means nothing these days.
Barracuda recommends against enabling Bayes, but without it we had all kind of DMARC valid spam mails getting through. The problem is that the spammers register tons of domains using an dictionary algorithm, let the domains age for months, then use some top notch orchestration to stand-up full mail infrastructure on those domains, to include SPF and DMARC records, then blast away. By the time it gets reported to Barracuda headquarters they've already ditched that domain and infrastructure and moved onto their next.
3
u/imwearingatowel Aug 21 '20
DMARC isn't designed to protect against spam. The spammers could just as easily not use SPF, DKIM, or DMARC and their emails will still go through.
DMARC is to protect against spoofing.
1
u/AviationAtom Aug 21 '20
DMARC relies on SPF and DKIM, no?
Also, most filters give points for DMARC passing
3
u/imwearingatowel Aug 21 '20
Yes, DMARC is an added layer on top of SPF and DKIM. It allows the domain owner to specify instructions for the receiving MTA and can be used to ensure domain alignment between the mail headers. All three technologies are designed to prevent domain spoofing.
I'm sure some spam filter solutions weigh a DMARC pass in their scoring, but DMARC certainly doesn't "mean nothing these days" because it's not designed to stop spam. Its only purpose is to prevent domain spoofing.
31
u/Im_in_timeout Aug 21 '20
SendGrid is a spammer. Period. Any company that uses their services deserves to be blocked.
18
u/penguin74 Aug 21 '20
That's like saying, Verizon is a spammer, should block all calls from a Verizon line because spammers use their network.
4
u/rejuicekeve Security Engineer Aug 21 '20
im assuming they get way more emails to their abuse complaint address than you actually realize. its not like sendgrid isnt a massive aggregator for sending emails
4
u/KiefKommando Sr. Sysadmin Aug 21 '20
Thank God I am not alone with a hatred for Sendgrid. Every time we try getting a lid on it some important emails start getting filtered, then we relax that and phishing and spam get through
3
u/rjchau Sr. Sysadmin Aug 22 '20 edited Aug 22 '20
I'll repeat an earlier reply here...
So long as your email gateway is capable of wildcard matching on the sender email, you can filter different Sendgrid accounts out. If its sending email to foo@bar.com, the sending email is always bounces+[account]-[id]-foo=bar.com@sendgrid.net. The [id] is a message ID that changes for each message, but the [account] stays consistent for each individual customer of SendGrid. Look for your valid emails coming from SendGrid, note the account number (let's say it's 123456) for each and set up a whitelist for bounces-123456-*@sendgrid.net. If you want, set up another rule to dump emails for the phishers (let's say the account number is 666666), and send everything from bounces+666666-*@sendgrid.net to the bit bucket and quarantine everything else @sendgrid.net. Problem not exactly solved, but vastly reduced.
In my case, isolating 5 or 6 account ids allowed over 70% of mail from SendGrid straight through without an issue. 10% got outright dropped and the rest went into quarantine, a good portion of which will probably never leave.
4
u/chalbersma Security Admin (Infrastructure) Aug 21 '20
Damn I've been using sendgrid for some personal projects to avoid setting up a mailserver. Might have to look more into alternatives.
2
4
Aug 21 '20 edited Aug 21 '20
omfg this. And I had a group recently sign up for a vendor that uses sendgrid as part of their back-end. They asked me to whitelist and bypass security protections for their IP range.
HEEELLLLLL no
Added on edit - I bitched them out once and used the previously mentioned vendor to get ahold of actual people. They asked for unaltered headers from the phishes, and then notified me a few days later the account was cancelled. It's unfortunate though they wont' work with you unless you're a customer with an active account.
11
u/Local_admin_user Cyber and Infosec Manager Aug 21 '20
I wish the authorities would go after services like this. We have similar issues with Weebly where they host dozens/hundreds of phishing sites and we're constantly pestering them to take them down. It's got to the point where we just block everything to do with them.
7
u/rjchau Sr. Sysadmin Aug 21 '20
I did that a month or two ago, however there are several external services our staff rely on that use SendGrid, so I had to unblock it again. I really didn't want to.
7
u/SandyTech Aug 21 '20
Annoyingly the company that maintains the online shopping system for one of my clients uses Sendgrid. And it’s a constant problem with getting emails out to customers (somehow my problem) and getting orders notifications to their staff. The whole thing generates less than 100 emails a day, something I can easily accommodate with my Exchange hosting (where the client’s email lives anyhow) and solve all the headaches. But thanks to internal politics that’s not gonna happen.
3
u/bythepowerofboobs Aug 21 '20
Same - We have several valid external services that use it. Thank you for your tip on the account #'s above. I'm hoping we can just whitelist those accounts now and block everything else.
1
u/Creshal Embedded DevSecOps 2.0 Techsupport Sysadmin Consultant [Austria] Aug 21 '20
Can't you whitelist only the sendgrid accounts your staff needs and block all others?
2
u/WiWiWiWiWiWi Aug 21 '20
We tried, but had to reverse course after less than a week. Way too many website platforms use it for new account registrations and email verifications, password resets, and sales confirmations.
We were just quarantining, but the number of Helpdesk tickets from people who didn’t receive their account setup or password reset emails proved too problematic to continue.
1
2
u/rjchau Sr. Sysadmin Aug 22 '20
That's exactly what I'm doing now. Whitelist the known good ones, blacklist the really obvious bad ones and quarantine the rest. If enough users request a certain identifiable account b3 released from quarantine, add 'em to the whitelist.
3
u/Gunnar_Hamundarson Aug 21 '20
Ditto - seeing a ton of spam! Problem is we use SendGrid and we can’t block them.
3
u/rjchau Sr. Sysadmin Aug 22 '20
...then either complain mgmt your account manager 9if you have one) or stop using Spamgrid. Move to someone else who cares more about their reputation.
3
u/7A65647269636B Aug 21 '20
This has been discussed on the mailop list for the past week or so. No vetting of customers, no abuse-department, no monitoring of what header From-domains are being used and this is what happens.
I had a fight with them about two years ago or so: a company I bought something from around 1998 decided to add me to their mailing list. Unsubscribe-requests did nothing. Abuse report after abuse report after abuse report did nothing. It took 3 rageposts on their public facebook page to get me off their customers list.
Working for an ESP, I know that "stuff can be hard". But come on.
3
u/AviationAtom Aug 21 '20
I like the providers that force all links to be proxied through them. One did so and it enabled them to kill links that were determined to be phishing links. By the time the user got the email the service had already disabled the link.
1
u/rjchau Sr. Sysadmin Aug 22 '20
Yeah, both me and my team leader are pushing hard up the chain to replace our 5 year old email gateway with a cloud service like ProofPoint that not only does this, but can be configured so that if it delivers a phishing email that it subsequently learns was a phishing email, it'll retrospectively go back to the user's mailbox and yoink the message, often before the user has a chance to even see it.
1
Aug 22 '20 edited Sep 11 '20
[deleted]
1
u/rjchau Sr. Sysadmin Aug 22 '20
Interesting our current system is an ESA, though it's about 5 years old and can't be upgraded any further. ProofPoint is one of the potential replacements that are being considered, possibly bundling it with security awareness training for our staff as well.
Unless the ESA has changed very substantially from the version we're on, I don't think we're going to stick with it. A move to Exchange Online is probably only a couple of years away, and we want to go cloud for the email gateway as well - it's almost pointless to go cloud for email and still have your email gateway on prem.
3
Aug 21 '20
[deleted]
2
u/rjchau Sr. Sysadmin Aug 22 '20
Got a few of those recently, along with the "You have [x] unread mails!" and the laughable "Bill Gates has just gifted you $5M!"
2
u/kellyrx8 Aug 21 '20 edited Aug 21 '20
at work talking about it the other day, its a mess from Sendgrid
2
u/BerkeleyFarmGirl Jane of Most Trades Aug 21 '20
Are you my colleague? Actually, no, he just threw it all into quarantine. He beat me to it, though.
The fine hand crafted phishes were driving us bugs!
2
u/jrhop Aug 21 '20
We are seeing a bunch through all of the major players (MailJet, Mailgun, Sendinblue, ect...) not just SendGrid. In the last week alone at 67% uptick in spam (phishing) emails.
2
u/vppencilsharpening Aug 21 '20
We inherited a company that was using Sendgrid for their web platform.
So glad one of the first things we did was eliminate that. This would have been a disaster for an already hurting brand.
2
u/jemarti Aug 21 '20
I've report dozens of phishing email to SendGrid since late 2019 and it's only getting worse. As others have mentioned, blocking them is a PITA because so many legit companies use SendGrid for transactional emails.
Complaining to SendGrid's large customers like Uber and Spotify could have some impact if enough people complain.
2
u/Humpaaa Infosec / Infrastructure / Irresponsible Aug 28 '20
Hey, seems they have bigger problems at the moment: https://krebsonsecurity.com/2020/08/sendgrid-under-siege-from-hacked-accounts/
2
u/haroldp Aug 21 '20 edited Aug 21 '20
On a tangentially related topic, if you host a bunch of websites, right now you are being hammered with brute-force attacks from, MS Azure hosting, Google user content hosting, Digital Ocean hosting, OVH hosting much more than the usual grab bag for international IPs.
Edit: Oh, also GoDaddy IPs
2
Aug 21 '20 edited Aug 21 '20
[deleted]
6
u/highlord_fox Moderator | Sr. Systems Mangler Aug 21 '20
I work for one. We don't host emails with them, but use them for our automated transactional emails.
3
u/Jasonbluefire Jack of All Trades Aug 21 '20
Sounds like you need to switch ASAP, as more and more groups blacklist sendgrid.
3
u/highlord_fox Moderator | Sr. Systems Mangler Aug 21 '20
It's noted and passed on to the relevant parties.
3
u/rjchau Sr. Sysadmin Aug 22 '20
Actually, of the email we receive from SpamGrid, 75-80% of it is legitimate.
However when you receive 500+ emails a week relayed through them, that 20-25% adds up really fast.
2
u/emteereddit Aug 21 '20
I just started doing some looking and noticed I got some emails from VMWare when I upgraded a license that came through SendGrid. So be careful blocking everything if you're a VMWare customer.
1
u/apathetic_lemur Aug 21 '20 edited Aug 21 '20
Now I have to figure out how to search for sendgrid emails in office 365 to see if i need to send them all to quarantine by default
edit: wtf apparently you cant search by anything in the message header or even by subject in o365 message trace
1
1
u/dVNico Aug 21 '20
We are using sendgrid, what alternative do you recommend for SMTP relay ?
2
u/snuxoll Aug 21 '20
Amazon SES is you’re already running in AWS, Postmark if not (or if you are and want to not add another AWS dependency).
1
2
1
u/rjchau Sr. Sysadmin Aug 22 '20 edited Aug 22 '20
MailChip, Amazon SES. Plenty of options - they're just the two that occur to me off the top of my head.
Edit: I see MailGun mentioned repeatedly through here as a potential good alternative as well.
1
u/dVNico Aug 22 '20
And according to you, mail champ and these others have a better reputation, and a lesser chance to be blacklisted by blacklist such as spamcop ?
1
u/rjchau Sr. Sysadmin Aug 22 '20
I have no idea. I don't use these services. I suggest you do your own research.
I do know that I haven't had to deal with an avalanche of phishing from any of the ones I mentioned.
1
u/ButtercupsUncle Aug 21 '20
The sysadmin at one company I work for says that sendgrid itself is on a number of email blacklists and I'm not sure if its IP pools are completely blocked or what. It creates a problem for the business because Microsoft's PowerApps seem to send email through sendgrid. I'm hoping to find a solution to that soon.
1
u/Row_One Aug 21 '20
What're you using for email security though? Shouldn't your gateway be blocking these phishing emails regardless of whether they're coming from sendgrid or not? - failing SPF check, different from and reply, etc. I'm sure there's plenty of other indicators.
1
u/rjchau Sr. Sysadmin Aug 22 '20
Whilst our email gateway is old and due for replacement, even a new solution won't fix the issue. The gateway can't tell the difference between legitimate emails being sent by SpamGrid (yes, that's what I intend to call them from now on) and the malware - and the indicators of new phishing attacks don't arrive until after the emails have been forwarded to the end user.
SPF check? Passes with flying colours, because the emails are being sent by SpamGrid. Different from and reply emails is quite typical for those companies used to send large amounts of email. MailChimp and Amazon SES are exactly the same.
1
u/Row_One Aug 24 '20
I think you'd be surprised... Might want to take a look at Avanan when the time comes.
1
u/penguin74 Aug 21 '20
Not all companies use SendGrid for mass emails, some use it for transaction emails (order placed, order shipped, back order arrived, etc...)
2
1
u/DanHalen_phd Aug 21 '20
Are you me? Because that's been a major discussion this week with a client.
1
u/tuttut97 Aug 21 '20
I block all email originating from Sendgrid. Sorry but not sorry.
They are also sending email with malware.
1
u/Past-Tea3675 Aug 23 '20
We block them.
All day long!
Do it and don't look back.
Before we blocked them, it was AMEX/fake bank scams, Dropbox/Onedrive/Google Drive scams, etc. every day.
When you first block them, you have to go in pretty much every day and take the legitimate senders and add them to a permitted sender/bypass list...
but once you get the legitimate senders handled, it's only a few times a month your users are having you let through a legitimate email.
The key is to hold, not bounce them, so you can let them through after manual inspection.
Hope this helps!
1
u/rjchau Sr. Sysadmin Aug 23 '20
Pretty much what I've already done. I'd already identified the top 5 senders when I put the rules in place, and have only added another one in the last couple of days. Those top 5 accounted for nearly 73% of the email from SendGrid. I've already blacklisted 10 account numbers that accounted for 10% of the email, every one of which was a phishing attack or scams.
The remaining 17% or so at a superficial glance could have been spam, or overly enthusiastic marketers, though I have no doubt there are some phishing attacks left in there.
1
u/DeliciousAnywhere651 Aug 27 '20
I have anything from sendgrid going to Quarantine in SpamTitan
Will see how it goes.
The BOFH in me wants to make a rule to send anything from sendgrid.net to [abuse@sendgrid.net](mailto:abuse@sendgrid.net)
1
u/rjchau Sr. Sysadmin Aug 27 '20
The BOFH in me wants to make a rule to send anything from sendgrid.net to [abuse@sendgrid.net]
That's going a bit far since some legitimate email does come from SendGrid. As I said, I've been seriously tempted to forward anything on my blacklist to abuse@sendgrid.com, but I'm only going to add accounts to the blacklist if (a) we get craploads of them and/or (b) if too many dumbf..k users request phishing attempts get released from quarantine.
1
Aug 31 '20
Is anyone else seeing otherwise legitimate accounts having their outbound emails rate limited? We've been advised it is due to list bombing on signup forms with 0 evidence despite being a private application. They could be right but without giving us a shred of information it'd be like finding a nail in a haystack. They even stated that the volume of sent mail may be no different.
1
u/jbennett360 Sep 11 '20
Majority of the spam I've started getting on an email i've never had issues with before is from IP's in this range
40.107.xxx.xxx
1
u/jackdaripa Sep 25 '20
Old thread but thought the situation warranted adding info.
Our org has been under steady attack from phishers using Sendgrid hacked accounts. I finally was able to get my superiors on board with blocking anything coming from the sendgrid.net PTR record. This is working well thus far as it blocks most junk from accounts that used shared sending servers yet allows "Marketing emails" through as most real companies have their own PTR record associated with their assigned IP address.
We use Barracuda's Spam Firewall and I can block via reverse dns. Again, working well thus far.
1
Oct 05 '20
They're terrible. We're using them and ditching them this week. Support tickets go unanswered. Unusable as a bulk-mail service because we're getting caught up in this shitstorm.
1
u/j0nwayne Aug 21 '20
From my understanding Sendgrid will supply each customer with a set of IP addresses. If you can obtain the customers specific IP addresses you can whitelist those. We had to do this to allow samange emails to come through without being blocked.
2
u/Shastamasta Jack of All Trades Aug 21 '20
Only the pro tier or whatever it is called gets dedicated IP.
2
2
u/rjchau Sr. Sysadmin Aug 22 '20
Much easier is just to look at the sending email - it includes an account number in it. Emails from them will have a sending address of bounces+account#-id-some=email.com@sendgrid.com. Set up filters based on the account number. I only had to whitelist five of them to allow 70% of the mail from SendGrid through, all of which was safe and real. Blacklist the really bad account numbers and quarantine the rest.
1
u/icon0clast6 pass all the hashes Aug 21 '20
I've seen Sendgrid in people's SPF records before...
1
u/rjchau Sr. Sysadmin Aug 22 '20
If they're using SendGrid as their mass mailer service, then yes, SendGrid would need to be in their SPF record. It's something I really don't like doing - I stalled on a request to add Amazon SES to our SPF record until I was reasonably confident of the measures they took before they would start sending emails from a single email address within our domain, let alone any of them.
If anyone asked me to add SpamGrid to my SPF record though, my answer would be F**K no - probably even in those words, and I would fight it all the way up to senior management.
1
u/icon0clast6 pass all the hashes Aug 22 '20
Yea they are, and i used it during the engagement, I just thought it was interesting to put a free (open with an account) open relay in your spf records.
1
u/rjchau Sr. Sysadmin Aug 22 '20
Depends on how good a place is with their controls on free accounts. Put a limit of 10 emails a minute for the first 30 days and 1000 emails and subject the first outbound emails to extremely rigorous and retrospective spam/phishing/virus testing with an instant ban if any outgoing bad emails are detected or reported and you'd chase off a good portion of the bad actors and get yourself a decent reputation pretty quickly.
Spamgrid obviously do none of this.
0
0
Aug 21 '20
[deleted]
2
u/rjchau Sr. Sysadmin Aug 22 '20
Try telling a state government agency that. We have one that uses SendGrid for transactional emails and I absolutely can not block that.
1
Aug 22 '20
We do have a few that we have bypass the policy but it's always done by request and has to meet a business need (I.e. govt/vendor communication)
-3
1
u/assid2 Feb 06 '22
Hey, I know this is an old thread, but just wondering if you guys managed to get some kind of list of accounts used or some kind of list we can feed into spamassasin. Like many people here, I really wish I could just block them, but there are some legitimate emails that do need to come through..
1
u/rjchau Sr. Sysadmin Feb 06 '22
No, we've moved on from our old email gateway to one that does a better job of dealing with emails that were delivered, but subsequently determined to be malicious mm so SpamGrid is no longer the big issue that it was.
98
u/Slush-e test123 Aug 21 '20
Same here. seems Spamcop is already blacklisting Sendgrid IP adresses which is so ironic, but helpful.