Ask us about your TalkTalk email account and Webmail.
on 28-03-2024 05:52 PM
hi
worrying problem started today on one of my talktalk email addresses, basically getting emails that appear to come from myself - i use outlook on my device and do not use the talktalk online web email offering - i know i have not sent these but worried someone has been able to access my online web email even though i do not use them myself - is this possible? 2 emails so far today pretending to be from me - one was trying to get me to click on a link for fake mcfeee renewal other was the usual oral b garbage obviously i did not click on these and have deleted them and will delete anymore.
I know how they spoof the email to pretend it is from my email but how do they spoof it so even in email properties check it still sppears as my email?
i appear to be getting my emails to my outlook device as normal no strange responses from anyone appear to be coming through so whats going on please have talktalk been hacked again as i have strong security and passwords on my device?
and why did i have to create a new account to access this blog?
thanks
dazza
Answered! Go to Solution.
on 31-03-2024 12:23 PM
many thanks - i wont worry about these spoofs now then but will certainly keep aware of them and delete if any more sneak through - i was surprised these made it too but as i say i am out of touch with latest stuff now so not for me to say - technology moves so fast need to be involved daily to be up to date which i am not - lets hope the team can tighten up a bit more to stop these but appreciate they already stop a load already - its not easy - you know what its like as fast as there is a defence against these scammers / fraudsters they think of another loophole - maybe AI will finally beat them one day without stopping genuine emails too
cheers
dazza
on 31-03-2024 11:56 AM
Grateful thanks for forwarding to TalkTalk Security.
I don't know why these spoofed mail messages are being accepted. No authentication, no DMARC policy and the sender is on a blacklist so, in theory, TalkTalk inbound mail servers ought to be dropping this unwanted spoofed mail. The team ought to investigate the reason for the mail being delivered.
Gondola Community Star 2017-2024
Like below to appreciate my post . . . Mark as solved Accept as Solution
on 31-03-2024 11:04 AM
thanks Gondola, sorry about delay i had already deleted the spoofed emails but another came through pretending to be from one of my talktalk email email addresses this morning, so the information i have for you is:
Return-Path: <hey_sodswko@crypto.11thcircle.com>
Received: (envelope-from <hey_sodswko@crypto.11thcircle.com>) there is also their ip and some imap info and other tech stuff in this area
From: my email only showed when double clicking the email they also spoofed the properties from the basic email - not getting involved in IT like i used to i forgot how easy this was to do and check via View Source email header, so thanks again for that you have helped so many times in the past under my other dazza name really appreciate it - also my fault i had to create another dazza as i forgot i already had an account via another talktalk email address!!
so some of the From: info
Received: from mx.tt.xion.oxcs.net ([10.93.2.3])
by imap-director-8.dovecot.shared.ns.xion.oxcs.net with LMTP
id 6PBXH0rSCGbHRwAAFvMZzQ
(envelope-from <hey_sodswko@crypto.11thcircle.com>)
if there is anything above that identifies me please delete it - i dont think there is but i am a little out of touch with these things now - if you want more info from the View Source email header let me know and i will check on next one that comes through as i will delete this one after i forward it to phishing@talktalk.co.uk
my email address appears in the for: part also X-Delivered-To: - there is a lot of other stuff but i guess talktalk phishing guys will view that when i send it to them
cheers
dazza
on 30-03-2024 02:18 PM
I think they will be filtered out because from what I've seen the senders are not authenticated.
Have a look at the View Source email header and let me know what's on the 3 lines that start:
Return-Path: don't post your own email address but indicate if that is shown by *****my email*****
Received: just the part in brackets that is like (envelope-from <email address>)
From: don't post your own email address but indicate if that is shown by *****my email*****
And please do forward the email to phishing@talktalk.co.uk so that TalkTalk Security can take a look.
Gondola Community Star 2017-2024
Like below to appreciate my post . . . Mark as solved Accept as Solution
on 30-03-2024 01:20 PM
Thanks Gondola, it has now spread to a second talktalk email address - as you know I use outlook at home rather than TT webmail but as worried I did actually login to one spoofed email and noted that there was nothing in the sent items which puts my mind at rest a bit, but always vigilent as so many criminals out there mainly organised crime groups.
However what I dont get is how the spoofed address can also be in the email sender properties not just as a spoof as a sender although thinking about it I think I am realising as I type this, but any insight you can give would be helpful, these emails are the usual garbage you know account expired must renew immediately, offers from people I never use or will use, mysterious shein prizes or you won a competition you never entered etc obviously trying to panic people and play on their greed - same old really.
Is there anyway talktalk can filter these out, the subjects and message bodies are pretty obvious? Obviously never click on anything and my opinion is dont even open them.
thanks again
dazza
on 28-03-2024 06:05 PM
Looks like there's a spate of email spoofing by spammers. You're not the first to report this. Details below for Compromised versus Spoofed email accounts.
The TalkTalk Mail Support Hub is your go to resource for information, guides and Community support for TalkTalk Consumer home broadband and MailPlus subscribers.
Select here:
TalkTalk Mail Support
TalkTalk Mail help
Using TalkTalk Mail
Phishing emails & everything you need to know
Compromised or spoofed accounts
Gondola Community Star 2017-2024
Like below to appreciate my post . . . Mark as solved Accept as Solution