Clément VILLISEK [Old account]

u/clement@ck.villisek.fr
5 posts · 11 comments

Recent posts

Recent comments

Hi, thank you for the answer, and sorry for the late reply :( ...

I analysed the logs thoroughly, and I can confirm my SMTP server hasn't sent any email aside the legitimate ones.
And u/voracitude 's answer confirmed my thoughts, being that the emails were sent from somewhere else.

I don't think it's that much unusual to use a "small" domain for spoofing: SMEs are "easy targets" usually, and if the recipient's anti-spam isn't configured properly then the attackers could benefit from a domain which may be small but has a good reputation.

@intelisense
Hello, thank you for your answer and sorry for the late reply.

I took some time analyzing my SMTP server logs, and it contains 100% legit outgoing traffic. And no successful SSH connection for weeks on the server so it can't have been erased.
u/voracity confirms my thoughts as well. I think the issue is outside and unrelated to my server. And the e-mail address in question seems to have leaked from several places according to haveibeenpwned (the password is safe though).

RE: lemmy.world/comment/7170785