Re: Fake paypal email triggers -7.5 USER_IN_DEF_DKIM_WL From: address is in the default DKIM
| Newsgroups | gmane.mail.spam.spamassassin.general |
|---|---|
| Message-ID | <[email protected]> |
On 1/30/25 1:53 AM, Greg Troxel wrote: > Mark London <[email protected]> writes: > >> Alan, you’ve pointed out the issue with the scam emails. Specifically >> with the phone number. Venmo emails are doing something similar. I’m >> sure thst PayPal and Venmo will not do anything to stop these. PayPal >> knows about it. They have warnings on their website about the >> scams. That’s all they will do. > > If paypal is allowing user-generated content to leave @paypal.com with > valid DKIM, then they should be immediately removed from default WL. > The usual responsible practice is to have a separate domain for customer > mails and company-originated mail. E.g. verizon.com vs verizon.net, > google.com vs gmail.com. Paypal[.]com has been removed from default WL in November (https://github.com/apache/spamassassin/commit/76906e0c7c064391bf832b3eb885ae74aed6c8b5) With updated rules USER_IN_DEF_DKIM_WL should not hit. Regards Giovanni
OpenPGP_signature.asc
(application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEEqg3TnG6R3qYMxl94+r7qCYlyWOUFAmebjIMFAwAAAAAACgkQ+r7qCYlyWOXn fhAAqFKbaF7kh098Ytepl114DPE5SZ6pZ2x8Q3WEZxbm2UYtedMNWM+1WXWCOOAaIYmF8BCE2tuZ mjzznDXw6bcqUfypU6hfVx3DkmzIZoDWzgUQGoCbiOH+2FKbrU+CyTuC3AIHqNqtxsUa870v847G jZ4rq8xPHv8k4qypdWxIZWzGrpO/yh9oxmap5yG4s3IPzSdtAxRJJKw+l9tDOYNLAl04pq3oiFjJ Tb/9haPXkPgGxsSmLiWPD2j9Oatuuv+55FnfAgJ2xPYjhYKmSESSpfqbi0ho/i2d02/0tJKKNLPn 71GGDJudIf/+6MIYMGW1uJK0sKbkuc7spccGeM7HtK/WbZkfyBHxfQBVlbMQnkTdyYdFYI4gx0Vc 9mUCGz7hW+KDroz2M2wR0o+2hkIodiihdNWOP3Q4/dsNweslihQRA2jVhNxRQ8aBjC561XBRaFc7 uLeUg6LJ5VMKdyNHuh7DLPwFSbGTYjBIRsbgbFxNJ+EYy2dZ0W6/7ei2+mM9CGtaSoh/eYJi2tVB wgzsDDS6nrHC3fpLVWjtQ7iT0gzUpkTpvNVeDAvxQyCVyK+h/FrC/xorSdMT8lt5PVtedL4exTBE wNkmNKl5PzH9jeMT5faaxus1gIudJ+WwVeLucBifhfBAdvJVTrTUs0RXlWUT7dnnZveBT62NNo3m vII= =aTEd -----END PGP SIGNATURE-----