我的域名(我们称之为 acmecorp.com)设置了通配符,这样 *@acmecorp.com 就会重定向到我的主要电子邮件[电子邮件保护]
最近收到以下电子邮件,我想知道我是否需要采取行动。我从未使用过该地址:[电子邮件保护]
我删除了一些信息以保护看似合法的 OOS 发件人的身份。
Delivered-To: [email protected]
Received: by 10.237.32.47 with SMTP id 44csp7220191qta;
Sun, 1 Jan 2017 15:51:39 -0800 (PST)
X-Received: by 10.194.58.198 with SMTP id t6mr45781381wjq.44.1483314699817;
Sun, 01 Jan 2017 15:51:39 -0800 (PST)
Return-Path: <>
Received: from hostingsmtp.register.it (hostingsmtp60.register.it. [81.88.56.20])
by mx.google.com with ESMTPS id s62si45272678wms.127.2017.01.01.15.51.39
for <[email protected]>
(version=TLS1 cipher=AES128-SHA bits=128/128);
Sun, 01 Jan 2017 15:51:39 -0800 (PST)
Received-SPF: pass (google.com: best guess record for domain of [email protected] designates 81.88.56.20 as permitted sender) client-ip=81.88.56.20;
Authentication-Results: mx.google.com;
spf=pass (google.com: best guess record for domain of [email protected] designates 81.88.56.20 as permitted sender) smtp.helo=hostingsmtp.register.it
Received: from monti-backend13.it.dadainternal ([172.20.42.13])
by paganini33 with
id TBrf1u00W0H2WSs01BrfqW; Mon, 02 Jan 2017 00:51:39 +0100
X-Sieve: Pigeonhole Sieve 0.4.6 (4b9b9a88ac9b)
Message-ID: <dovecot-sieve-1483314699-430747-0@monti-backend13.it.dadainternal>
Date: Mon, 02 Jan 2017 00:51:39 +0100
From: <gabry@marc<redacted>ia.com>
To: <[email protected]>
Subject: Fuori ufficio - Out of office
In-Reply-To: <[email protected]>
References: <[email protected]>
Auto-Submitted: auto-replied (vacation)
Precedence: bulk
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Sarò assente dal 30 Dicembre al 5 Gennaio.
<snip, redacted for privacy but looks realistic, more contact details for other people in the office>
Grazie.
I'll be away from Friday 30th December until Thursday 5th January and will not have access to e.mail until I return.
<snip, redacted for privacy but looks realistic, more contact details for other people in the office>
Thank you.
忽略这个安全吗?如果不安全,我需要采取什么进一步的措施?很高兴提供更多信息。
多谢。
答案1
是的,你应该做出改变。你应该为你的域名添加 SPF 记录,这样别人就很难冒充你了。