Comcast recently published a statement on DMARC over on their postmaster page. The short version is that Comcast is publishing a DMARC record, but has no current intentions to publish a p=reject policy for Comcast user email. Comcast will be publishing a p=reject for some of their domains that they use exclusively to communicate with customers, like billing notices and security notices. Comcast...
AOL admits to security breach
According to Reuters AOL has admitted there was a breach of their network security that compromised 2% of their accounts. Users are being told to reset their passwords, and security questions. AOL started investigating the attack after users started reporting an uptick in spam from aol.com addresses. This spam was using @aol.com addresses to send mail to addresses in that user’s address...
Is gmail next?
I’m hearing hints that there are some malware or phishing links being sent out to gmail address books, “from” those gmail addresses. If that is what’s happening then it’s much the same thing as has been happening at Yahoo for a while, and AOL more recently, and that triggered their deployment of DMARC p=reject records. It’s going to be interesting to see what...
Why do we "warmup" IP addresses
IP address warmup is a big issue for anyone moving to a new IP address for sending. I’m constantly being asked how to warm up an IP. My answer is always the same. There’s no right way to warm up an IP nor is there a specific formula that everyone should follow. What warming up is about is introducing mail traffic to receiving spam filters in a way that lets the filter know this is a...
More on spam traps
A couple weeks ago I had a discussion with Ken Magill of the Magill Report about spam traps. He had moderated a webinar about spam traps and I publicly contradicted some of the statements made about spam traps. He contacted me and interviewed me for an updated article about traps for his newsletter. The next week he had a rebuttal from Dela Quist of Alchemy Worx, taking anti-spammers (and...
AOL publishes a p=reject DMARC record
Yesterday I mentioned that there were reports of a compromise at AOL. While the details are hazy, what has been reported is that people’s address books were stolen. The reports suggest lots of people are getting mail from AOL addresses that they have received mail from in the past, but that mail is coming from non AOL servers. In an apparent effort to address this, AOL announced today they...
AOL compromise
Lots of reports today of a security problem at AOL where accounts are sending spam, or are being spoofed in spam runs or something. Details are hazy, but there seems to be quite a bit of noise surrounding this incident. AOL hasn’t provided any information as of yet as to what is going on.
ReturnPath on DMARC+Yahoo
Over at ReturnPath Christine has an excellent non-technical summary of the DMARC+Yahoo situation, along with some solid recommendations for what actions you might take to avoid the operational problems it can cause.
Is volume a problem?
Volume in an of itself is not a problem. Companies sending mail people want can send multiple emails a day to every user. The volume isn’t a problem because the mail is wanted. Many senders are confused and think volume is a filtering criteria. It’s not. Send all you want; just send it to people who actually want the mail. A lot of companies in their growth phase find they do have...
A good example of 3rd party email
This morning I received a great example of a 3rd party email that I thought I’d share with all of you. What’s so great about it? It’s sent from the company I actually gave my email address to: Macheist. It tells me why I’m getting this email: I purchased Fantastical back in 2013 It introduces me to Fantastical’s new product: Fantastical 2 for iPad and iPhone...