My email was used as the From: address on a spam and now I'm getting hundreds of auto-replies

2

1

I have a vanity domain with email hosted by GMail and forwarded to my regular Gmail account. It appears that the From: line of the primary address I use has been spoofed on multiple Spam messages, and lately I have been receiving a ton of auto-replies from random addresses (i.e. not ones in my addressbook).

While most of the bounces (e.g. from Postmaster, MAILER-DAEMON, Mail Delivery System, etc.) are caught by the first gmail account and not forwarded on, a small number of them are still getting through to my regular account. Is there anything I can do at this point to stop this or prevent the emails from being created in the first place?

I've got two-factor authentication set up in both places, strong passwords, and there's nothing in the Sent Mail outboxes of either of the accounts.

Aphoid

Posted 2013-01-25T15:42:06.560

Reputation: 41

Answers

1

This is not unusual. However, usually this is a one time spam and the spammer moves on. It should stop soon. There is no way to stop a spammer form pretending to come from your address.

Xavierjazz

Posted 2013-01-25T15:42:06.560

Reputation: 7 993

I just added an SPF record to my DNS. Will that help? Would a DKIM be possible? I don't normally actually login to my domain account, but use Gmail's "Send Mail As" feature to spoof my vanity domain address. – Aphoid – 2013-01-29T16:44:12.203

I just added DKIM to my DNS entries as well, and at least I can send/receive messages on there to/from my work accounts. – Aphoid – 2013-01-29T19:01:10.787

Does this have anything to do with the spam problem? – Xavierjazz – 2013-01-29T20:14:31.867

My understanding is that having SPF and DKIM in your DNS should help as both purport to be technologies that help confirm that an email is legitimately sent and not a spoofed message.

While I also understand that a receiving server might just ignore them, if mail servers silently discarded the spams rather than replying with postmaster or unknown account emails, that would help. I simply don't know if spam filters/mail servers silently discard SPF or non-DKIM validated messages or if they still respond with bounces – Aphoid – 2013-01-30T21:53:19.540