PDA

View Full Version : How do I stop Spam Emails from my own Email Address?



BladesNBarrels
12-04-2016, 10:07
Newest spam emails started two days ago.
Different Subjects are sent to my email address from my own email address.
Any ideas on how to block or stop that?
Thanks in Advance!


[Help]

cysoto
12-04-2016, 10:27
Did you try updating your password?

BladesNBarrels
12-04-2016, 10:46
Good suggestion - did that and ran CC Cleaner.
I don't know if that will stop the spam emails, but I have my fingers crossed (probably not a technical solution:})

ChadAmberg
12-04-2016, 10:47
Post the full set of email headers and I'll take a look and let you know if it's someone simply spoofing your address, or someone who has access to send emails from your actual account.

How to see your headers actually depends on what email you have and such.

BladesNBarrels
12-04-2016, 10:56
I sent the spam emails to my spam folder then deleted them.
I then ran cc cleaner and it cleaned out all of the junk, spam, cookies, etc.
If I get another, I will try to determine how to see the email headers for comcast emails.

BladesNBarrels
12-05-2016, 10:03
Updated and ran malwarebytes program yesterday.
Got another spam email in this morning's bunch.
I sent it to a friend who is checking the header.
My wife got one last night from her email address.
The subject of the repeats is "Wife Out of Control" and contains a video about christian couples.
Hopefully, something can be accomplished without blocking my own emails.

CS1983
12-05-2016, 10:12
Updated and ran malwarebytes program yesterday.
Got another spam email in this morning's bunch.
I sent it to a friend who is checking the header.
My wife got one last night from her email address.
The subject of the repeats is "Wife Out of Control" and contains a video about christian couples.
Hopefully, something can be accomplished without blocking my own emails.

Did you simply forward him the email or send the email itself as an attachment? If you just fwded him the email, it's unlikely the headers would be retained. Most email needs to be attached to the email you send to retain the headers.

It's unlikely your account is sending them. Most likely the sender is spoofing your address as a "from", but sending from another domain.

According to this page:



How to View a Comcast Email HeaderIf you want to perform a Comcast user lookup using the information in an email header, you need to know how to read it. Viewing the full header depends on how you access your mail.
If you view your mail in the SmartZone Communications Center at Comcast, you will first need to right-click on the message. Then select "view source" from the menu. A separate browser window will open, allowing you to see all of the headers. You will then also have the option to inspect the HTML code if the message is formatted.
If you use Comcast's Lite version, the method is a slightly different. First, open the message you wish to inspect. Next, click the view source icon (this may appear as a small envelope) in the far right corner of the toolbar. This will open a separate browser window and allow you to view all headers.


https://www.emailfinder.com/resources/art-email-headers-for-comcast-users.html

You could just post the header info in the thread (feel free to redact your name -- we only need to see the sender's domain)

BladesNBarrels
12-05-2016, 10:47
I copied the header information after right clicking the email and hitting View Source and sent it to my friend that said he would look at it.

Here is what I have:

Received: from resimta-po-15v.sys.comcast.net (LHLO
resimta-po-15v.sys.comcast.net) (96.114.154.143) by
resmail-po-264v.sys.comcast.net with LMTP; Mon, 5 Dec 2016 07:56:20 +0000
(UTC)
Received: from mail-qt0-f229.google.com ([209.85.216.229])
by resimta-po-15v.sys.comcast.net with SMTP
id Do7bcN3hzcwKhDo8Kc51of; Mon, 05 Dec 2016 07:56:20 +0000
X-CAA-SPAM: F00000
X-Authority-Analysis: v=2.2 cv=f7A4PK6M c=1 sm=1 tr=0
a=qlXl2LpMnti+Qrs8FaoHLg==:117 a=xqWC_Br6kY4A:10 a=khwyK8DuSVkA:10
a=f1s5C7vbToMA:10 a=n5n_aSjo0skA:10 a=v0UCBxr7Q_jK4Lt5cGUA:9
X-Xfinity-Message-Heuristics: IPv6:N;TLS=1;SPF=0;DMARC=F
Received: by mail-qt0-f229.google.com with SMTP id n34so38347699qtb.2
for <loomisone@comcast.net>; Sun, 04 Dec 2016 23:56:20 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20130820;
h=x-gm-message-state:message-id:mime-version:to:from:subject:date;
bh=N6WLrYcjvMQ/0TMq4/S+0JWpnP5TAADjeGXUidGrFaU=;
b=W4r1NJVZRXEVb3zVB4pI7C1WUGV7ZR7gOrQdpz9fimUxdApn E6gMxICB1PPJ6BFhxx
uheMSk6NOrZQRk3xI8yssR27TVpHk75EhHahYQJwlsmY1R3t8F AnU6+zj5avWctPuUPh
nAnYxLpU7IEZeiTVIsHnaipdu27tfX048FQs9cLThv8flahv1n RoyuRVIQ0y2hfBa/qT
G6qdmaGwtBihWaZ0sjP9y/mOtYRsT9bPYJGzkEnHTTL9PsMBfF/sOrCdzWykE5q7+x4K
dcfWkrGDGhrgic8jq5TgRE9sXBRiPR/MYMXb9kICJrToaa8iZiq28BKnIunpVKjS1e1U
8Esg==
X-Gm-Message-State: AKaTC007ilgSY7pmwBJv4OuJUooanTLAAyeBuZK9Y61JOKGptr Lm+4RchspHFIHH+3YcHbuGy1nIgVBRBu9AyP6xa6sCClPTzQKY ZthWg0ehlJP2
X-Received: by 10.36.111.212 with SMTP id x203mr7321458itb.59.1480924275391;
Sun, 04 Dec 2016 23:51:15 -0800 (PST)
Return-Path: <>
Received: from email101-58.irvine.ilinkmd.com (opengreats.space. [2607:6880:17:1f::57])
by smtp-relay.gmail.com with ESMTPS id 195sm44279243itv.3.2016.12.04.23.51.15
for <loomisone@comcast.net>
(version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128);
Sun, 04 Dec 2016 23:51:15 -0800 (PST)
X-Relaying-Domain: hotshoptigan.com
Message-Id: <58451c73.cc06240a.f0625.f9bcSMTPIN_ADDED_MISSING@m x.google.com>
MIME-version: 1.0

BladesNBarrels
12-05-2016, 10:49
Added note:
Now, my emails that I BCC to my email address are showing up in my SPAM folder instead of the regular INBOX folder.
Thanks for your looking at this.

CS1983
12-05-2016, 11:21
I copied the header information after right clicking the email and hitting View Source and sent it to my friend that said he would look at it.

Here is what I have:

Received: from resimta-po-15v.sys.comcast.net (LHLO
resimta-po-15v.sys.comcast.net) (96.114.154.143) by
resmail-po-264v.sys.comcast.net with LMTP; Mon, 5 Dec 2016 07:56:20 +0000
(UTC)
Received: from mail-qt0-f229.google.com ([209.85.216.229])
by resimta-po-15v.sys.comcast.net with SMTP
id Do7bcN3hzcwKhDo8Kc51of; Mon, 05 Dec 2016 07:56:20 +0000
X-CAA-SPAM: F00000
X-Authority-Analysis: v=2.2 cv=f7A4PK6M c=1 sm=1 tr=0
a=qlXl2LpMnti+Qrs8FaoHLg==:117 a=xqWC_Br6kY4A:10 a=khwyK8DuSVkA:10
a=f1s5C7vbToMA:10 a=n5n_aSjo0skA:10 a=v0UCBxr7Q_jK4Lt5cGUA:9
X-Xfinity-Message-Heuristics: IPv6:N;TLS=1;SPF=0;DMARC=F
Received: by mail-qt0-f229.google.com with SMTP id n34so38347699qtb.2
for <loomisone@comcast.net>; Sun, 04 Dec 2016 23:56:20 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20130820;
h=x-gm-message-state:message-id:mime-version:to:from:subject:date;
bh=N6WLrYcjvMQ/0TMq4/S+0JWpnP5TAADjeGXUidGrFaU=;
b=W4r1NJVZRXEVb3zVB4pI7C1WUGV7ZR7gOrQdpz9fimUxdApn E6gMxICB1PPJ6BFhxx
uheMSk6NOrZQRk3xI8yssR27TVpHk75EhHahYQJwlsmY1R3t8F AnU6+zj5avWctPuUPh
nAnYxLpU7IEZeiTVIsHnaipdu27tfX048FQs9cLThv8flahv1n RoyuRVIQ0y2hfBa/qT
G6qdmaGwtBihWaZ0sjP9y/mOtYRsT9bPYJGzkEnHTTL9PsMBfF/sOrCdzWykE5q7+x4K
dcfWkrGDGhrgic8jq5TgRE9sXBRiPR/MYMXb9kICJrToaa8iZiq28BKnIunpVKjS1e1U
8Esg==
X-Gm-Message-State: AKaTC007ilgSY7pmwBJv4OuJUooanTLAAyeBuZK9Y61JOKGptr Lm+4RchspHFIHH+3YcHbuGy1nIgVBRBu9AyP6xa6sCClPTzQKY ZthWg0ehlJP2
X-Received: by 10.36.111.212 with SMTP id x203mr7321458itb.59.1480924275391;
Sun, 04 Dec 2016 23:51:15 -0800 (PST)
Return-Path: <>
Received: from email101-58.irvine.ilinkmd.com (opengreats.space. [2607:6880:17:1f::57])
by smtp-relay.gmail.com with ESMTPS id 195sm44279243itv.3.2016.12.04.23.51.15
for <loomisone@comcast.net>
(version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128);
Sun, 04 Dec 2016 23:51:15 -0800 (PST)
X-Relaying-Domain: hotshoptigan.com
Message-Id: <58451c73.cc06240a.f0625.f9bcSMTPIN_ADDED_MISSING@m x.google.com>
MIME-version: 1.0

The "from" the is actual sending domain. It's spoofing your email as the from, but the domain is right there.

ClangClang
12-05-2016, 11:51
In clearer English - you are not sending any spam. A spammer/scammer is sending emails just using your name ("BladesNBarrels") in the FROM section. There's not much you can do about it, unfortunately. Maybe call in an air strike?

BladesNBarrels
12-06-2016, 18:06
Thanks for the clarification. I am getting the same email every morning now and my wife is getting one from her email address.
It is like the phone calls from my own phone on the Caller ID.
Some days technology is very frustrating.

CS1983
12-06-2016, 18:07
Thanks for the clarification. I am getting the same email every morning now and my wife is getting one from her email address.
It is like the phone calls from my own phone on the Caller ID.
Some days technology is very frustrating.

You might be able to block the domain which is sending, but it looked like an SMTP relay from gmail, so I dunno if that's possible (sure it is) or how that would be done via comcast.

cstone
12-06-2016, 18:36
If you were working full time at fighting the growing tide of spam/phishing/fraud on the Internet you could notify one of the admins on the domain sending the emails. As an individual user, either set up a filter to handle the junk mail or just delete them manually when they come in. A couple per day is pretty simple to deal with.

Some of the phishing emails today are getting as good if not better than the emails sent by the legitimate entities they are posing as. Trust no one. Verify everything. If you don't have time to verify something, trash it.

asmo
12-06-2016, 21:22
Received: from email101-58.irvine.ilinkmd.com (opengreats.space. [2607:6880:17:1f::57])
by smtp-relay.gmail.com with ESMTPS id 195sm44279243itv.3.2016.12.04.23.51.15
for <loomisone@comcast.net>
I love seeing IPv6 spam.. Just makes me chuckle.

As someone else said, you are not doing anything. Someone is forging your email address on an open relay. It happens to all of us. The software to generate the emails just uses "random" emails that it has in its database (typically from someone else's account that has been compromised long ago that had your email address in their contacts list). You are also probably getting the bounce-back from other mail relays rejecting the spam.