TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How best to report phishing emails to a domain holder?

11 点作者 Swinx43将近 8 年前
I have received a phishing email from an email address using the Northeastern Illinois University. I cannot find and address to which to send an email regarding this and get no response on Twitter.<p>What is the best way to report this?

7 条评论

devillius将近 8 年前
I would send emails to abuse@neiu.edu and phishing@neiu.edu. In addition, you could perform a whois lookup on the domain to get the Technical Contact: <a href="https:&#x2F;&#x2F;who.is&#x2F;whois&#x2F;neiu.edu" rel="nofollow">https:&#x2F;&#x2F;who.is&#x2F;whois&#x2F;neiu.edu</a> and send an email to admin@neiu.edu<p>If you wanted to take it another step forward, here are the folks you could probably contact: <a href="https:&#x2F;&#x2F;ssb.neiu.edu&#x2F;mercury_neiuprod&#x2F;GZKDIRL.P_DISPLAY_DEPT_DETAILS?alpha_in=Technology+Services" rel="nofollow">https:&#x2F;&#x2F;ssb.neiu.edu&#x2F;mercury_neiuprod&#x2F;GZKDIRL.P_DISPLAY_DEPT...</a><p>Hope this helps.
评论 #14762175 未加载
jlgaddis将近 8 年前
If nothing else, send a report to soc@ren-isac.net. If NEIU is a member, the folks at the watch desk will have te ability to immediately get in touch with someone in security there.<p>I&#x27;m no longer at an .edu (and so no longer a member of REN-ISAC) but this was a great, quick way to get ahold of someone at another institution quickly.<p>(n.b.: This goes for pretty much any .edu.)
twobyfour将近 8 年前
It&#x27;s also entirely possible that the email isn&#x27;t being sent by them or anyone affiliated with them. FROM headers on email are miserably easy to spoof.<p>I&#x27;ve had thousands of spam emails sent with senders listed as nonexistent addresses from one of my domains. They were sent from third-party servers (my servers were not compromised and I had no open relays), and I only found out because of all the bouncebacks from naive receiving servers.<p>The only thing the domain holder can do at that point is to set up DomainKeys and similar measures - which still won&#x27;t prevent spammers from using the domain, it&#x27;ll just cause more of the mail to bounce back as spam.
评论 #14762414 未加载
bjpbakker将近 8 年前
First check the domain registration record. Many domain registrations include an abuse or technical contact, or at least an administrative contact.<p>If not, try abuse, postmaster, webmaster, et al like suggested by others already.
lm_nop将近 8 年前
Additionally, I send phishing emails to reportphishing@apwg.org which alerts the Anti-Phishing working group... Not sure what happens once they get my forwarded emails...
cypherg将近 8 年前
I normally send to admin@, abuse@, phishing@, and hope that at least one don&#x27;t get kicked back.
ryanlol将近 8 年前
&gt;What is the best way to report this?<p>Flag as spam and move on with your life.
评论 #14768209 未加载