0

Screenshot:

enter image description here

The text covered with red is exactly my email address except the end is @google.com instead of @gmail.com.

The suspicious link "Unsubscribe_click_here" is: mailto:cr@burlondesti.com,kz@grendeoszel.com,ma@bindolamiats.com,couar.ort@gmail.com,krandelowez@foxmail.com,3561036101@qq.com,jacques.chirac088@gmail.com,sosiea0@outlook.com?Subject=.Unsubcribe%20now//

If I expand email details to show more info:

enter image description here

Yellow is my email address. The sender's email address is legitimate, so are all the other details.

Here are screenshots of a legitimate email from Mail Delivery Subsystem that I received recently for comparison:

Legit email

enter image description here

How is this possible? I definitely did not send that email and I'm pretty sure my gmail was not accessed by someone else (Google would have alerted me). This is the first time I see this. It seems whoever did this was somehow able to trick the google delivery system to think that I sent that email.

SpaceMonkey
  • 101
  • 1
  • Does this answer your question? [Failed to send emails that I never sent](https://security.stackexchange.com/questions/211005/failed-to-send-emails-that-i-never-sent). See also [Backscatter](https://en.wikipedia.org/wiki/Backscatter_(email)), – Steffen Ullrich Mar 08 '21 at 22:13
  • @SteffenUllrich that does seem to answer my question, but how could Google be this bad? I'd have thought they have protection against forging sender address. – SpaceMonkey Mar 09 '21 at 10:40
  • @SpaceMonkey: It is the **optional** responsibility of the MTA (mail transfer agent, i.e. on hop in the delivery of a mail) to check for spoofing and not all do it. If the first MTA accepted the mail (because no spoofing checks were done) and forwards it to googles MTA and then the MTA there rejects the mail (unknown recipient) then this problem will be propagated back from the first MTA through a Delivery Status Notification - which is what you see. – Steffen Ullrich Mar 09 '21 at 11:03

0 Answers0