2

I have received a number of phishing emails from various domains. I would like to prevent the domain from sending emails so that other people also don't get taken advantage of.

I have not been successful talking to the registrar or host to take down the domain. Is there anything an ISP could do to prevent such emails from a known malicious domain?

  • The short answer is that very few phishing emails are sent through ISP infrastructure. The From address and other information are forged. Occasionally a user's machine is compromised and their email is used to reach their contacts. But not the common case. There are now a number of trust/verification mechanisms with email; the best thing to do is for people to use email clients that perform those verifications. – Jonah Benton Jun 20 '18 at 15:21
  • Only if your email is provided by your ISP. Otherwise consult your email provider and see what spam filtering options are available and how they can be tuned. – user2320464 Jun 20 '18 at 16:01

2 Answers2

1

The short answer is; probably not. Unless of course you actually pay for that service. An ISP does exactly that, it supplies you with Internet Service - if that's all you're paying for that is all you will get.

As far as I know, at least in the UK I could not contact any ISP and ask them to help me with spam prevention because not only do I not pay for that, they don't even offer it. Obviously, this can vary depending on your location but unless your ISP explicitly offers that kind of service to you (for a fee of course) then chances are they will not even be interested to hear what you have to say.

If they don't provide the service they don't provide the service and unfortunately, they're not going to change their business model for you and start selling spam prevention as a service. Your best choice is to see what spam prevention methods your mail provider can provide you.

0

Spamming/phishing mails initiation is mostly random from several domains/IPs (attackers use BOTs to initiate these randomly), hence it may not be practical for you to block one by one and you will end up with a huge list of domain/IP list.

My advise would be to go for a proper Email Security Solution, which take cares of your headache of blacklisting to referring to threat intelligence to asses the blacklisted IP pools.

There are several solution including cloud solutions such as:

https://www.fireeye.com/solutions/ex-email-security-products.html

https://www.symantec.com/products/email-security-cloud

https://www.sophos.com/en-us/products/sophos-email.aspx

Note: Similar solutions are provided by many ISPs as well.

Hope this clarifies...

Sayan
  • 2,033
  • 1
  • 11
  • 21