TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

My account is sending spam emails

647 pointsby benpinkabout 7 years ago

45 comments

laurenceiabout 7 years ago
Exact same thing for me.<p>Noticed I was getting emails being sent from myself. More worringly was the emails appeared in my SENT folder. For 5mins I was freaking out thinking I was hacked, because I didnt think spoofing emails would show up in MY &quot;sent&quot; folder.<p>But I run 2FA, long complex unique password etc. I treat OpSec really highly. I checked all Google security settings, no unauthorised access, no apps using my account etc. Still did a password reset &quot;just in case&quot;.<p>However one interesting part is after about 4 hours the emails automatically became marked as &quot;spam&quot; - and they disappeared from my &quot;sent&quot; folder simulatenously.<p>So it would seem the likely issue is someone worked out a way around the &quot;Spam&quot; setting for Gmail - and a by-product of not flagging spoofed emails as spam is Gmail marks them as &quot;Sent&quot; by you in the labels.<p>Seems this was flagged as a security risk over a year ago - and Google declined to fix? <a href="https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;spammers-delight-gmail-weirdly-doesnt-see-spoofed-gmail-com-addresses-as-junk&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;spammers-delight-gmail-weirdly...</a>
评论 #16899823 未加载
评论 #16896865 未加载
评论 #16894968 未加载
评论 #16894947 未加载
评论 #16895296 未加载
评论 #16898059 未加载
评论 #16895797 未加载
jlgaddisabout 7 years ago
Don&#x27;t freak out about them being in your Sent folder. Remember that Gmail doesn&#x27;t have &quot;traditional&quot; mail folders -- just a huge pile of all your e-mail messages with &quot;labels&quot; attached to them. Apparently Google decides that if the From: address is yours, then you &quot;sent&quot; the message.<p>Note that in SMTP there are <i>two</i> &quot;from addresses&quot;: the envelope sender (which you don&#x27;t see) and the &quot;From:&quot; address&#x2F;header (which you do see) that everyone is familiar with. In most (but not all) legitimate e-mail, they will be the same.<p>In these cases, your e-mail address is being used in the &quot;From:&quot; and &quot;To:&quot; headers but a different address is being used in the envelope sender (which is the one that the MTA uses).<p>Google does seem to be checking SPF correctly (i.e., according to RFC, which says to use the envelope sender) -- since (it seems that) the result of check_host should be &quot;softfail&quot; and the RFC says that one &quot;SHOULD NOT&quot; reject a message based on that... but Google apparently logged &quot;pass&quot;. Odd.<p>---<p><i>ETA</i>: See a comment from <i>ryan-c</i> below about the funky &quot;exists:&quot; mechanism in Telus&#x27; SPF record; it explains why check_host() passed.
评论 #16903467 未加载
评论 #16898270 未加载
mike-cardwellabout 7 years ago
Some of you posting raw message sources might find a website I built useful:<p><a href="https:&#x2F;&#x2F;www.parsemail.org" rel="nofollow">https:&#x2F;&#x2F;www.parsemail.org</a><p>From my about page:<p>&quot;Paste the raw source of an email into the form on the front page. The email will then be parsed, decoded, separated into its various MIME parts, and displayed in an easy to view fashion. Image attachments will be displayed as images. HTML parts will be rendered in webkit (with javascript and plugins disabled) and then also displayed as an image. IP addresses in headers and message bodies will be identified and highlighted along with a flag representing their origin country. Hostnames and email addresses will also be identified and highlighted.&quot;
评论 #16895410 未加载
sethvargoabout 7 years ago
Hi all,<p>Seth Vargo here from Google. Thank you all for taking the time to report the issue, and thank you for your patience as we fix it. Our engineering teams are aware of this issue and they are working to resolve it as quickly as possible. You should no longer see new spam messages appear in your sent box, and existing spam messages will be automatically removed over the next few days.
评论 #16896987 未加载
评论 #16896985 未加载
dawnerdabout 7 years ago
Just wanted to say, the top response on the google forum is exactly why google needs real support and not community members copy-pasting “solutions”.
评论 #16895945 未加载
评论 #16896839 未加载
FuckOffNeemoabout 7 years ago
My house mate has had the same issue today on both of his Google accounts. He is both the sender and recipient and there were several other nonsensical email addresses being CC&#x27;d in.<p>SMTP headers show the emails are relayed from Telus. I&#x27;ll provide the SMTP headers when I get home.<p>= = =<p>No unauthorised attempts to log in from third party sources, seperate passwords and MFA on both services.<p>It doesn&#x27;t seem to me that the accounts have been compromised, instead the emails are spoofed. They have all been forwarded from Telus.com. The forum OP posted shows everyone else has the same issue.<p>Both accounts were sending hundreds of emails today and Google flagged the emails as likely having not been sent by him, but still did not place them in an appropriate spam filters and allowed them through to his inbox?<p>Edit:<p>= = = = =<p>I won&#x27;t bother adding my headers now, the others that have even added theirs are almost identical to our own, here&#x27;s a snippet of some one who posted below:<p>SPF and DMARC results<p>ARC-Authentication-Results: i=1; mx.google.com;<p>spf=pass (google.com: domain of reply@telus.com designates 69.64.35.11 as permitted sender) smtp.mailfrom=Reply@telus.com; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com<p>Authentication-Results: mx.google.com;<p>spf=pass (google.com: domain of reply@telus.com designates 69.64.35.11 as permitted sender) smtp.mailfrom=Reply@telus.com;<p>dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com<p>Received: from gown.ShoppingBrew.com (ec2-13-58-85-245.us-east-2.compute.amazonaws.com. ) by mx.google.com with ESMTP id n59-v6si5794010qtd.116.2018.04.20.00.37.14 for &lt;&lt;myemail@gmail.com&gt;&gt;;<p>Received-SPF: softfail (google.com: domain of transitioning nkhpw@google.com does not designate 69.64.35.11 as permitted sender) client-ip=13.58.85.245;
评论 #16894934 未加载
Operylabout 7 years ago
This is spoofed email, with you also being the recipient as far as I can tell... Am I missing anything else in this matter? If not, this isn&#x27;t new.<p>EDIT from below: &quot;If I remember correctly, if you are the recipient of an email from &quot;yourself&quot; Google automatically puts it in the sent items label as well.&quot;
评论 #16894855 未加载
评论 #16894859 未加载
评论 #16894872 未加载
some1elseabout 7 years ago
Most people don&#x27;t realize some services you &quot;Logged into with Google&quot; can also send emails in your name. I didn&#x27;t come across anyone checking authorized apps in that thread. While this appears to be a spoofing issue, I suggest pruning the list of authorized apps frequently: <a href="https:&#x2F;&#x2F;support.google.com&#x2F;accounts&#x2F;answer&#x2F;3466521?hl=en" rel="nofollow">https:&#x2F;&#x2F;support.google.com&#x2F;accounts&#x2F;answer&#x2F;3466521?hl=en</a>
评论 #16897202 未加载
评论 #16896956 未加载
kerngabout 7 years ago
Relevant security issue Gmail declined to fix over a year ago: <a href="https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;spammers-delight-gmail-weirdly-doesnt-see-spoofed-gmail-com-addresses-as-junk&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;spammers-delight-gmail-weirdly...</a>
评论 #16896497 未加载
tytsoabout 7 years ago
So it&#x27;s not so simple. You could use DMARC to tell mail servers which honor DMARC to drop all e-mails that have @gmail.com addresses that don&#x27;t come from gmail.com servers. In fact, this is how @google.com e-mail addresses are treated, and I believe this is a setting which G-Suite administrators can set up for their domains.<p>BUT. It comes with a downside. Suppose you want to send e-mail from your Linux laptop, or from a Linux mail server you control, without hard-coding your account password in a text file so you can send e-mail via a GMail server. Or suppose you want to subscribe to a mailing list which rewrites the subject line to include the mailing list name. DMARC breaks all of this. Horribly. So yes, it&#x27;s more secure, but it comes with a massive cost.<p>What this means, for example, is I recommend people who work at Google, and who want to interact with either IETF mailing lists or the Linux-kernel mailing lists at vger.kernel.org to send their patches and PULL requests using their @gmail.com address. If they send it using their @google.com address, the same security settings that will prevent this spammers from &quot;faking&quot; e-mails that didn&#x27;t come from gmail servers, will also break git send-email (unless you want to save your password into at text file --- which is against policy and common sense) and it will break traditional mailing lists.
Keverwabout 7 years ago
I got 2 of these a hour ago.<p>&quot;This may be a spoofed message&quot; Google says, I clicked spam even though it&#x27;s from myself. It was to me and a bunch of other emails. Wasn&#x27;t in my sent folder though and no one else has accessed my account.<p>&quot;Sexy Girls Asian Girls Looking for US Men&quot; is the subject and says it&#x27;s sent from &quot;----------------- via telus.com&quot;<p>Really odd, seems to be some ISP in Canada and I live in the USA... Wonder how they got my email.
评论 #16897051 未加载
评论 #16894878 未加载
评论 #16895897 未加载
SyneRyderabout 7 years ago
Another HN thread with more comments about this: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=16894593" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=16894593</a>
DanielDentabout 7 years ago
Probably unrelated, but telus.net&#x27;s SPF record appears to authorize RFC6598 (<a href="https:&#x2F;&#x2F;tools.ietf.org&#x2F;html&#x2F;rfc6598" rel="nofollow">https:&#x2F;&#x2F;tools.ietf.org&#x2F;html&#x2F;rfc6598</a>) IP space:<p>&quot;v=spf1 ip4:199.185.220.0&#x2F;24 ip4:198.161.157.0&#x2F;24 ip4:198.161.156.0&#x2F;24 ip4:204.209.205.0&#x2F;26 ip4:209.171.16.0&#x2F;24 ip4:100.64.0.0&#x2F;24 mx ?all&quot;<p>100.64.0.0&#x2F;24 is within 100.64.0.0&#x2F;10<p>Either I&#x27;m missing something, or Telus appears quite confused about the purpose&#x2F;nature of SPF.
criley2about 7 years ago
I woke up this morning to several new labels in my gmail to delete all emails for &quot;bank&quot; &quot;card&quot; &quot;paypal&quot; etc, and paypal was hacked with purchases.<p>But my gmail has zero new logins, my 2fa wasn&#x27;t triggered, etc.<p>How does a hacker create labels to delete my email but not register a login attempt or trigger my 2fa? I wish I was able to contact google.<p>EDIT: my only guess was accessing my PC where logins are saved, but I sleep in the same room and I don&#x27;t think ninja spies broke in. Remote login? Seems farfetched.
评论 #16898019 未加载
tloganabout 7 years ago
The emails are spoofed. The bug is Google is labeling emails with &quot;Sent Mail&quot; because &quot;from:&quot; header matches your email.<p>I think the &quot;bug&quot; was that not all &quot;Received-SPF&quot; headers are not correctly checked (only first one was checked). However, I&#x27;m not even sure if this is a bug since I&#x27;m not sure if their migration of emails into G Suite will work if they start not trusting &quot;from: header.<p>The real bug is probably that email is not marked as spam :)
aquovaabout 7 years ago
I had some of these earlier today as well. Mine wasn&#x27;t from telus however, it was from some .science account. I use a password manager and have 2FA enabled, but I quickly switched my password just to make sure. Sure enough, a few hours later I got another one, for about 5 in total. They seemed to have stopped however.
marsroverabout 7 years ago
Something funny I&#x27;ve noticed is my business account is not receiving any spam but my free gmail account is.
jimrandomhabout 7 years ago
If you have a suspicious or spoofed email and you want people to analyze what happened, it helps a lot if you include the full headers. To do this in gmail, open the menu and pick &quot;Show Original&quot;. Particularly useful are the lines that start with &quot;Received:&quot;.
DrScumpabout 7 years ago
This strategy seems odd. If they had simply omitted the spoofed sending email address from the To:&#x2F;(B)cc lines, we&#x27;d never had seen them in our inboxes... right? Why call early attention to yourself?<p>I had 24 in my Inbox starting as 6:13PM (GMT-7).
评论 #16895125 未加载
4llanabout 7 years ago
I have this problem with my Hotmail&#x2F;Outlook account for almost 5 years and Microsoft team don&#x27;t even understand what&#x27;s going on. - <a href="https:&#x2F;&#x2F;answers.microsoft.com&#x2F;en-us&#x2F;outlook_com&#x2F;forum&#x2F;oemail-osend&#x2F;receiving-phishing-message-in-behalf-of-my-outlook&#x2F;8201fe49-6a67-49a0-8f7e-b03f9a3bc786" rel="nofollow">https:&#x2F;&#x2F;answers.microsoft.com&#x2F;en-us&#x2F;outlook_com&#x2F;forum&#x2F;oemail...</a>
imraj96about 7 years ago
Same thing here! I woke up this morning and saw that I&#x27;ve sent out spam emails (about 15 of them) with my email address via telus and receive responses in my inbox.
aetherspawnabout 7 years ago
To temporarily alleviate this issue, I created the following filter to stop my phone ringing constantly:<p><pre><code> from:(me@gmail.com|me@salesforce.com) to:(me@gmail.com) -{has:attachment} Mark as read Skip the inbox </code></pre> Until I added this rule I was being pinged once a minute since lunch time yesterday.<p>This ignores: emails from me, or some sales force spammer they were using, to me, that doesn’t have an attachment (so I can still email myself files).
downandoutabout 7 years ago
I had the same issue tonight. It did not appear in my sent folder, however, and was sent from the same “reply@telus.com” account that everyone else reports. The most recent one (of 5 sent so far) was sent 2 minutes ago. I changed my password an hour ago - but as I suspected that didn’t help because these aren’t being sent via compromised accounts. Someone is using an SMTP server and just spoofing the sent from address.
mediocrejokerabout 7 years ago
I had the same thing happen today. At least 6-8 emails in my inbox over the course of an hour or two, from my email address. Mostly ads for &quot;dating&quot; sites with photos of scantily-clad women. The to list includes my address, as well as about 8-10 other addresses, including one at rei.com and another at nih.gov.<p>Mine are showing Telus in the relay as well. None show up in the sent folder, and I use 2FA on the account.
dorfsmayabout 7 years ago
I wonder if telus did this to allow people using their email system to use Google calendar to send reminders.
评论 #16896876 未加载
sengorkabout 7 years ago
Some of you might want to see this as well:<p><a href="https:&#x2F;&#x2F;mashable.com&#x2F;2018&#x2F;04&#x2F;22&#x2F;google-gmail-spam-telus&#x2F;" rel="nofollow">https:&#x2F;&#x2F;mashable.com&#x2F;2018&#x2F;04&#x2F;22&#x2F;google-gmail-spam-telus&#x2F;</a>
Tempest1981about 7 years ago
So who is Telus, and why are they special?<p>Is it Google who has a relationship with Telus -- because I&#x27;m pretty sure I don&#x27;t.<p>Can Google prevent Telus from doing whatever they&#x27;re doing? Or is Telus just the victim&#x2F;conduit of the real spammers?
评论 #16897026 未加载
评论 #16897056 未加载
neop1xabout 7 years ago
A bit unrelated but requiring login to just read a forum thread is not good. :( I don&#x27;t want to login to google again on this device therefore I haven&#x27;t seen the thread.
piyush_soniabout 7 years ago
Wow. I&#x27;ve been facing this since yesterday night, didn&#x27;t know the entire internet is facing this problem. There&#x27;s still no official response from Google it seems.
Tempest1981about 7 years ago
If the emails are (spoofed as) from me, and I tell gmail to mark them as spam, does anything bad happen?<p>Gmail shows a weird &quot;Mute&quot; instead option -- never saw that before.
helloindiaabout 7 years ago
I’ve had similar problem a long time ago with my yahoo account. (Password change didn’t help) So, I cleared my yahoo contact list and that stopped the spam.
stanmancanabout 7 years ago
I’ve been debating leaving Google Apps for months now and oddly enough this is the straw that broke the camels back. Will be migrating to a new host today.
dman214about 7 years ago
This happened to me today as well. I also run 2FA. Did not see any suspicious devices or activity in the log, other than the sent emails.
DigitalSeaabout 7 years ago
Crazy. This was happening to me today as well. Tonnes of spam from my email, but being sent to these weird blanket emails. Worrying.
ninjaranterabout 7 years ago
I had the same thing in my account (same relay through Telus). Here&#x27;re my headers<p><pre><code> Delivered-To: &lt;myemail@gmail.com&gt; Received: by 10.74.77.209 with SMTP id p78csp1252253ood; Sat, 21 Apr 2018 19:48:30 -0700 (PDT) X-Google-Smtp-Source: AB8JxZrx9G5VDRbvtvoQWl5sUYm3w7k1TQ5f+Sd3g74T+fFLkrWnEV7qhVmFTr7X0pBQCd5q+my5 X-Received: by 2002:a6b:6f01:: with SMTP id k1-v6mr16819882ioc.221.1524365310928; Sat, 21 Apr 2018 19:48:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1524365310; cv=none; d=google.com; s=arc-20160816; b=Ry11M99U7ldzJoPvejp48dePTM&#x2F;MlHI4xQTc2jrwZR3CeugDTEfUpA783hpLnaw0gg NCsTVBtObV1GYioVRQDSxWAczHFiPQGld0u5afD+xpb2eGpr7&#x2F;eZxTwvJPHYpl&#x2F;FLwNk pNXj3w7VObPIyj43K4Zkf9rgNF1TRCYx4RbRvesaBcHMADJS1vDRB5TAsJ8DV6dF7gOB +O59qvWZzg0nE265rBJ1b8fWXWuQb4KpdVdwolZ3T3fqFDGY2cHnsmZMWTRzcjsLFWuD 86+fIW1ccWf1eIjNh3LvecY6B0zzW9LjfgQw+0IvrkEdbwDc1EAbNhWI6kilOPIsDJGD Lzng== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed&#x2F;relaxed; d=google.com; s=arc-20160816; h=date:message-id:subject:to:from:arc-authentication-results; bh=4oe6QhhObsHLHbjLfsZs16iUEYy2rMdtn0ju3umolqQ=; b=FoRwZqhc5F7H6pItUYqZ2y&#x2F;OxsZQkWNDEhj4Ody6uJ1vaC3DzUbXqa4mw1Pb0AgfZe QaBcfWaloNJJXBBWIjERShMCo3wYb&#x2F;wcXtdOlT4x3o7uhAxQJ5sGBQqnVQ4QfH&#x2F;d9pIh DaqTXWcaEieX3tsVDXO8UtZviUTsA7FjO2YGkk&#x2F;f4rj1K9VOkxqiyECGyQf1uDAI&#x2F;55d 7O1t76oCpYr&#x2F;qyAAx2YGBnz87ShD4bORPOg8iHwb9f4zAq7tfwOoF&#x2F;Z3blPFR8EA2Xam q9x+2OIRsA2oX+t&#x2F;HNsdrYOkWPkYwhiHwptl0vQZDHZn3E4Uue8DofG5sRLoAFM1rVYJ e5RA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of reply@telus.com designates 69.64.35.11 as permitted sender) smtp.mailfrom=Reply@telus.com; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: &lt;Reply@telus.com&gt; Received: from shop.eseonew.com (static-ip-69-64-35-11.inaddr.ip-pool.com. [69.64.35.11]) by mx.google.com with ESMTP id v64-v6si7872516iof.146.2018.04.21.19.48.30 for &lt;&lt;myemail@gmail.com&gt;&gt;; Sat, 21 Apr 2018 19:48:30 -0700 (PDT) Received-SPF: pass (google.com: domain of reply@telus.com designates 69.64.35.11 as permitted sender) client-ip=69.64.35.11; Authentication-Results: mx.google.com; spf=pass (google.com: domain of reply@telus.com designates 69.64.35.11 as permitted sender) smtp.mailfrom=Reply@telus.com; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from gown.ShoppingBrew.com (ec2-13-58-85-245.us-east-2.compute.amazonaws.com. ) by mx.google.com with ESMTP id n59-v6si5794010qtd.116.2018.04.20.00.37.14 for &lt;&lt;myemail@gmail.com&gt;&gt;; Fri, 20 Apr 2018 00:37:14 -0700 (PDT) Received-SPF: softfail (google.com: domain of transitioning nkhpw@google.com does not designate 69.64.35.11 as permitted sender) client-ip=13.58.85.245; from: ABC Shark Tank &lt;&lt;myemail@gmail.com&gt;&gt; To: &lt;senderus@justvaluerate.com&gt;, &lt;senderse@justvaluerate.com&gt;, &lt;monsl@50-233-80-21-static.hfc.comcastbusiness.net&gt;, &lt;mz@traveldailymedia.com&gt;, &lt;gego@nih.gov&gt;, &lt;iscontact@rei.com&gt;, &lt;mz@wp.com&gt;, &lt;info@chadog.fr&gt;, &lt;info@autotrader.com&gt; Subject: Exclusive Limited Time Online Offer Shark Tank Success Story Message-ID: &lt;NkhPw@google.com=Mx.google.com&gt; Content-Type: multipart&#x2F;report; boundary=&quot;f4f5e80f07d80f991b056a2936a0&quot;; report-type=delivery-status X-EMMAIL: &lt;@googlemail.fr &lt;myemail@gmail.com&gt;&gt; Date: Sat, 21 Apr 2018 22:48:30 -0400 --f4f5e80f07d80f991b056a2936a0</code></pre>
评论 #16894950 未加载
评论 #16894952 未加载
评论 #16894951 未加载
tomkat0789about 7 years ago
This is pretty alarming. Is there another service to switch to that&#x27;s as reliable and more generally safe as Gmail?
jlengrandabout 7 years ago
Great to see this! I was getting mad at all this SPAM coming from myself today!
jeroenheijmansabout 7 years ago
Perhaps it&#x27;s a browser extension&#x2F;plugin that got hacked?
评论 #16895006 未加载
lukeholderabout 7 years ago
My father and I have been getting these all evening.
rco8786about 7 years ago
Ditto here. 1Password generated pw, 2fa, etc.
mexicanandreabout 7 years ago
Yes my gmail spam has gone nuts!!!! Wtf has happened
hartatorabout 7 years ago
From the way the emails are sent, I bet it&#x27;s an Android security hole.
评论 #16898050 未加载
Tagoreabout 7 years ago
I remember when my mom&#x27;s machine started sending spam with my name in the address field. Clever Trojan.
c3534labout 7 years ago
There was an attack going around many years ago that was basically a spam email that had code embedded in it, which would hack your browser, causing you to send out more spam email when you logged into your account. I assume this is the same sort of thing.
评论 #16895032 未加载
Screwtellusabout 7 years ago
Hey guys, you can contact tellus via this link. You don&#x27;t need to he a customer for this.<p><a href="https:&#x2F;&#x2F;www.telus.com&#x2F;en&#x2F;support&#x2F;article&#x2F;ccts-and-cprst-feedback-and-contact-information" rel="nofollow">https:&#x2F;&#x2F;www.telus.com&#x2F;en&#x2F;support&#x2F;article&#x2F;ccts-and-cprst-feed...</a>