TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Fake email using my domain

1 点作者 code_Whisperer超过 1 年前
Weird. Someone has created an account with one of the major money-sending apps using a fake email on a domain name I own. I can see this because I receive the emails sent by the app vendor via the domain&#x27;s catchall account. So whenever this person tries to login or change their password, I see the confirmation emails sent by the app vendor.<p>To be fair, it could have been an innocent mistake on the part of the person who signed up... maybe they meant to type .net instead of .com or something like that.<p>I contacted the vendor to tell them that the account is not authorized or known on my domain, and asked them to cancel, but they will not unless I send them an email using the &#x27;from&#x27; address of the unauthorized account.<p>So, questions:<p>1) Is this a common thing? And if this is potentially illicit activity, what is this person thinking or hoping they&#x27;ll be able to commit?<p>2) Even though I&#x27;d be using my own domain, should I intentionally impersonate someone who may (or may not) be attempting inappropriate activity in order to get the account removed? Wouldn&#x27;t that - on its own - be a potentially dangerous or illegal act?<p>{sigh} modern problems.

3 条评论

bell-cot超过 1 年前
This kinda stuff is why I don&#x27;t like catchall email accounts.<p>IANAL...but there can be some legal exposure here, too. Mr. Bad Actor is up to shady sh*t, using a fake bactor@YourDomain.com account as part of that, and some less-than-friendly Feds (or lawyer for a victim, or ...) could be knocking on your door.<p>Yes, fake-account and typo&#x27;ed -address email can be kinda entertaining to read. But better to lose no time, need no lawyer, set things to auto-bounce with a &quot;No Such Account&quot; error, and keep email logs for ~3 months or so - to play the random clueless honest bystander part.
mtmail超过 1 年前
If it&#x27;s only &quot;please confirm your account&quot; and password reset emails then the user probably just mistyped the email address.<p>If their username is go-to-ydotcom-for-free-cash then it might be spam. It doesn&#x27;t seem very effective but I know a company where a spammer created 10.000 accounts overnight to be sent to random people.
rini17超过 1 年前
Were they able to verify the fake email address somehow? If not they can&#x27;t actually use the account and you can safely ignore it.
评论 #38600289 未加载