It looks to me that Paypal is not sending the emails in a secure and verifiable method. Emails that are sent from a domain that's different than the from address are legitimately suspicious, especially when they contain financial keywords.
It looks to me that Paypal is not sending the emails in a secure and verifiable method. Emails that are sent from a domain that's different than the from address are legitimately suspicious, especially when they contain financial keywords.
I suppose someone might've taken over your browser or email client, but then it is game over anyway.
Perhaps PayPal should start MIME signing whole messages...
> 'service@paypal.co.uk' via Paypal-Admins <paypal-admins@company.example.com>
namely:
> 1) The domain it was sent from doesn't match the domain in the "From:" address'
> 2) The email was sent to a Google Group from a domain that has a "p=reject or p=quarantine" DMARC policy
In my case, it's (2): The target email is a Google Group email (e.g. paypal-admins@company.example.com).
Should that make the email more spammy though?
That’s not how this works. The “from” email header has nothing to do with the actual sender due to the email standard. The actual sender is specified in the SMTP command.
This is why SPF and DKIM for example have nothing to do with “from” either. SPF refers to the sender in the SMTP command and DKIM signing can use the keys of a domain unrelated to “from” and it’s all legal.
It’s very easy actually to spoof the “From” header and Gmail won’t complain.
That “via” information you’re seeing is just another header that doesn’t have much to do with Gmail. If you’re seeing it, that’s because the sender wants you to see it.
From on the envelope will be address of the mailing list, and from in the headers will be the original sender. Perfectly legitimate and extremely annoying if anythig uses this as a SPAM signal.
Emails then bounce to no-reply@ and any legitimate email client will auto-populate support@ as the To address when the user clicks reply.
Also PayPal was a contributor to DMARC RFC, so they presumably know what they're doing too around e-mail, wouldn't you say?
I get confirmations of flight reservations where env-From is mandrill app and From is kiwi.com. DMARC passes. Some of my banks do this, too. Registrar of my domains does this. Many others too.
It's just not suspicious and these are very important senders to me (I mean I'd hate to fail to renew my domain, or miss that one-in-a-lifetime e-mail that someone is withdrawing money from my bank account other than me, because of a braindead SPAM policy) and google should not care.
With DMARC SPF protects the From header as well.
SPF, DKIM, and DMARC maybe useful against fishing. In the long run it doesn't do anything against spam. So it is rather unfortunate that gmail (certainly on IPv6) is so eager to classify mail without those headers as spam.
Which is why Gmail will use this as a signal for spam and why Papal should have them match.
This is not a registration email that you expect to receive after clicking somewhere on a website.
This is the kind of email that says "something important happened to your account you may not be aware of, you should really know this; if it wasn't you, you are now in danger".
(Of course in this case it was me, but the whole purpose of this type of email is to alert you promptly in case it wasn't you.)