Ask HN: How did Microsoft email services became the primary source for spam?
And most important question: is Microsoft going to do something about it, as service abuse reports seem to make no difference.
And most important question: is Microsoft going to do something about it, as service abuse reports seem to make no difference.
The activity reported is associated with a customer account within the Microsoft Azure service. Microsoft Azure provides a cloud computing platform in which customers can deploy their own software applications. Customers, not Microsoft, control what applications are deployed on their account.
So why are even we using DKIM at all if bad actors can abuse an open cloud TOS.
I expect any sort of abuse report to Microsoft wouldn't result in any action on their part, just as reporting these messages as spam for about a month did nothing on the Gmail side.
False positives are similarly annoying. I spent years reporting emails from Kijiji (while they were an eBay subsidiary) to gmail as "not spam". Set up a rule to redirect them from the spam folder to inbox, but they still get tagged as spam when I open them.
But yeah, now anyone can buy a domain for dirt cheap, setup DKIM, and start spamming away.
At least with DKIM, you have a basis for blocking a domain outright. That is, until they buy up another domain and repeat their spamming activities again.
Email has really fallen apart in the past decade. When it's not spam, it's retailers and other companies sending me unsolicited, unwanted marketing emails, entirely without my consent. They are the bulk of the garbage in my inbox today.
It's amazing to think that companies still think this is a valid way to advertise products and services. At best, people get annoyed and dump you in the Junk folder. At worst, they view it as a form of begging by a desperate company looking for money, and those people definitely won't be interested in buying anything from you ever again. If there was a way to measure it, I would be that companies are losing more money from annoying spam marketing campaigns than from the .00001% that do convert.
Mailchimp, Constant Contact and their ilk are truly a scourge upon our inboxes. You know they're truly terrible companies because if they ever provided a global opt-out of all their email lists from all their clients, they'd go out of business.
One of these days I will just create another self-hosted email service of my own with a fresh domain and only whitelist it with recipients that I actually care to hear from.
$250 for a domain is prohibitively expensive.
I don't think the majority of internet users supports that view. I know many people who are subscribed to countless newsletters but don't want to unsubscribe, even if it's very easy. They like receiving offers from companies they bought from years ago. That's also why newsletters work so well for many companies.
So while many people here might dislike any email they didn't ask for, that's not necessarily the view of internet users as a whole.
Google has a problem where if you pay for a workspace account (or maybe even trial?) you get a temporary trust, which you can abuse for spamming, that gmail.com users don't get. So people open farms of workspace accounts (with fake id/ stolen CC?) and go wild.
Not sure why they allow people to send from known spam accounts on their own system.
Like 99% of it is coming from a gmail account. And very formulaic. I wonder why gmail claims to have an excellent spam checker, but they don't check for outgoing spam from their platform.
They also host known spam operations like Advids for years. They’ve basically become a bulletproof spam hoster.
My guess is that the Gmail team doesn't have any OKRs about spam prevention any more, or else they'd be able to pretty quickly put a stop to the top ~90% of the spam that's currently getting through.
I wish the anti-trust regulators were competent and paying attention. If so, they might be able to do something about the fact that Google—unlike pretty much every other large mail sender in existence—fights really, really hard to avoid taking abuse reports. Gmail is "too big to fail" so we can't just block them outright, like Google would do to us if we were the ones sending a bunch of spam and ignoring abuse reports.
[0] (edited to add) For those who are curious or wish to share the fruits of my labor:
body __DWP_BIZ_PROPOSAL /\b(business|confidential|discrete|mutual|beneficial|profitable|investment|favou?rable)\s+(proposals?|opportunit(y|ies)|friendships?|director(y|ies)|intentions?|introductions?|relationships?|business(es)?|investments?|transactions?)\b/i
body __DWP_DECEASED /\b((deceased|deposed|exiled|late)\s+(former\s+|ex[ -])?(ceo|husband|client|(vice[ -])?president|senator|[mb]illionaire|brother|sister|(great[ -])?((grand-?)?((fa|mo)ther|parent)|uncle|aunt)s?)|widow(er)?|beneficiar(y|ies)|inherit[ea]nce|last will and testament)\b/i
meta DWP_419 __DWP_DECEASED && __DWP_BIZ_PROPOSAL && (FREEMAIL_FROM || FREEMAIL_REPLY)
There are some other rules this works in conjunction with, but stopping the obvious spam is really not rocket science.What happened to Bayesian detection and AI?
SpamAssassin assigns a score (positive = more spammy, negative = more hammy) to each rule. So the above-quoted rules work in conjunction with other rules, the Bayes filter, IP/ASN reputation data, etc. DWP_419 has a really high score in my setup right now because the false positive rate is currently zero, but it could theoretically be canceled out by other signals.
Another possibility could be that receivers of email from O365 may not see an easy way to report the spam to Microsoft or perhaps Microsoft do not have enough folks dedicated to dealing with UCE/malware reports. Just my own experience, but when talking to Microsoft about this topic they would refer me to a partner Proofpoint which a former company ended up using to front-end O365. That left me with the impression they did not want to be in the business of dealing with UCE/malware reports and wanted to either automate it or outsource to a partner.
Thanks!
We also never get any response from Google when reporting spam campaigns or GApps compromises.
I think at the time I went through Github's sign-up flow, and you didn't have to even verify your email address to be able to OAuth with your Github account. (I didn't try signing up for an outlook.com email address, so I'm not sure what that entails.) GMail, comparatively, appeared to be more paranoid. We eventually prevented outlook.com addresses from getting a free trial without talking to a human first, and the people looking for a free crypto-miner didn't come back. (They tried Proton as their second choice.) We never banned GMail, so I can only assume that people had a harder time signing up, which is pretty impressive on Google's part.
There's also number of throwaway temp mail providers, and 33mail (If I recall correctly, gives a subdomain and all emails to that domain get forwarded to your original email.).
Microsoft has needed to fix this for years.
Training? Everytime a user has been phished their manager says "nono it cant be that they clicked something and logged in, they are very careful :)" Its never the users fault.
IT is not making excuses, the business is. No business wants to say "yea we have shit security and we hire numbnuts"
MFA + AAD risk users block + impossible travel block + turn off basic auth w conditional access helps a lot.
Every time they think they've got the bastard, he changes Goods to G00ds, or changes the subject line to "Confirmation Email", and it slips through again and hits my Primary, easy as pie. This happens at least a couple times a week.
All the cheesy tricks we thought stopped working 20 years ago are back in play for this one intrepid spammer. GMail just can't seem to stop itself from completely trusting just about any email from Outlook.com.
Now I'm wondering why more people haven't figured this out.
From 10/18 - 𝘠𝘌𝘛𝘐 𝘏𝘰𝘱𝘱𝘦𝘳 𝘔20 𝘊𝘰𝘰𝘭𝘦𝘳 - 𝘠𝘰𝘶𝘳 𝘰𝘳𝘥𝘦𝘳 𝘩𝘢𝘴 𝘴𝘩𝘪𝘱𝘱𝘦𝘥!## https://ns(x)hn/WxXqK which redirects to https://yuzuapples(x)com/0/0/0/ecf39df03591d83ed90be8d40d962...
There is also ways to get unlimited free premium exchange accounts.
Also most microsoft users are technically inept, so their accounts probably get hacked more often than other people.
These people coded Windows. No wonder nothing works as intended.
The first link still works and it seems to redirect to a random scam page each time.
Most of the ones from Microsoft servers are old Mailchimp messages (headers and body, hours to 10 years old) with 2 image links and 2 shortened links added.
Yahoo/AOL/Verizon does not detect them as spam.
I report to all involved and receive auto-responses and canned text. AWS is helpful, but Microsoft, Cloudflare and Zendesk are less than helpful.
The spam messages are useless without the images, so I concentrate on the image links. There seems to be an endless supply of free image hosting services.
> "service abuse reports seem to make no difference"
Microsoft email services are being used to create these spam accounts as they are much more easier to setup and get running. And if a spammer is using a Windows based OS, setting up multiple mail accounts using the Mail app is almost a breeze (including managing those multiple email accounts).
Microsoft is pretty rare for me to see in spam.