Mailing List Archive

Spam DKIM signed by Paypal coming from their Microsoft Tenant?
How do I stop this? paypal.com is in the default DKIM whitelist!

X-Spam-Status: No, score=-107.7 required=6.0 tests=DKIM_VALID,DKIM_VALID_AU,
,FREEMAIL_FROM,SHORTCIRCUIT,SPF_HELO_PASS,
USER_IN_DEF_DKIM_WL,USER_IN_DKIM_WHITELIST shortcircuit=ham
autolearn=disabled version=3.4.4
X-Spam-Relay-Country: US US US US
Received: from GBR01-LO2-obe.outbound.protection.outlook.com (
mail-lo2gbr01on2073.outbound.protection.outlook.com [40.107.10.73])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(No client certificate requested)
by xxxxxxxxxx (Postfix) with ESMTPS id 4BF1F1480FCB
for <xxxxxxxxx>; Mon, 14 Nov 2022 13:02:57 -0600 (CST)
Authentication-Results: xxxxxxxxxxxx
dkim=pass (2048-bit key) header.d=paypal.com header.i=@paypal.com
header.b="r6hmfVu3"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=OVohkgjr3UJbiohxx1KCrPdnaD1WXK9mrLMvZ4VloK9eudd9Gkh7tImMPXIN1iOrETjNj59A47N+uJqf4kZFPVUGJS6KAdzWZczL7LiBaIsg1uSQwoD60Z7heKEjC5cfOLsXZhwf0nhhwzbXpjXltGfYn0Jd8VQGxT64hKtfyVoP9JpRyF6h8I9FnCxfVvRbP4i8iYk5zkdvi4I9eR7z4dXeB9vLwZv5hb6nIt6le9lMJriMoM11QYHcLlqZqj9S8L1pN9ynLzAVezxmWmH9YDKyB9aKf4vJP32HHLmzPCCgnqplW6xObPUI5Wt5HagqD+ImpgKMQ1JgM86tq+Tuzg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com
;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=o8/9XRPNBSb6rQV6HcDwELycPOzUJqxucQ/nMDyby+o=;
b=XYTuQtEngNxrDz/McbFCv0GHj1RQ59jBE0nCMgxzQivSL51NnzAFIjsVs0BMxFtLPZmdwxx6fRBkRe6OLtpjUzut7MBMX0jYenXqsHZfLodWIT51fjG6JcEO1LPFvIJkl0WHl9w+agVHgUZy+c7TcADN5IdHh+/wDy5Pyh8iuEAE7g4+fPPaehKGfwLzqZJ+TdZKyXgbxbCMUCYrRjQvkV2xUqI+cTwZolauv847RlgIUqwG9OWiImbcruwIexjn+cOb1eidxluPnHVXILS/+AH6TVAz7oIsoCXB8rjBFrVCyGU1HTAYvLTDN31F7/QDMbDaiAHGTtbbvvAT7eZqig==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
173.0.84.228) smtp.rcpttodomain=duta788.onmicrosoft.com
smtp.mailfrom=paypal.com; dmarc=pass (p=reject sp=reject pct=100)
action=none
header.from=paypal.com; dkim=pass (signature was verified)
header.d=paypal.com; arc=none (0)
Resent-From: <Shannon@DUTA788.onmicrosoft.com>
Received: from CWLP123MB6161.GBRP123.PROD.OUTLOOK.COM
(2603:10a6:400:1a5::13)
by LO0P123MB5990.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:280::12) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5813.17; Mon, 14 Nov
2022 19:02:54 +0000
Received: from CWLP123CA0130.GBRP123.PROD.OUTLOOK.COM (2603:10a6:401:87::22)
by CWLP123MB6161.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:1a5::13) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5813.17; Mon, 14 Nov
2022 19:02:52 +0000
Received: from CWLGBR01FT040.eop-gbr01.prod.protection.outlook.com
(2603:10a6:401:87:cafe::11) by CWLP123CA0130.outlook.office365.com
(2603:10a6:401:87::22) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5813.17 via Frontend
Transport; Mon, 14 Nov 2022 19:02:52 +0000
Authentication-Results: spf=pass (sender IP is 173.0.84.228)
smtp.mailfrom=paypal.com; dkim=pass (signature was verified)
header.d=paypal.com;dmarc=pass action=none header.from=paypal.com;
Received-SPF: Pass (protection.outlook.com: domain of paypal.com designates
173.0.84.228 as permitted sender) receiver=protection.outlook.com;
client-ip=173.0.84.228; helo=mx3.slc.paypal.com; pr=C
Received: from mx3.slc.paypal.com (173.0.84.228) by
CWLGBR01FT040.mail.protection.outlook.com (10.152.40.168) with Microsoft
SMTP
Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.20.5813.12 via Frontend Transport; Mon, 14 Nov 2022 19:02:51 +0000
DKIM-Signature: v=1; a=rsa-sha256; d=paypal.com; s=pp-dkim1;
c=relaxed/relaxed;
q=dns/txt; i=@paypal.com; t=1668452569;
h=From:From:Subject:Date:To:MIME-Version:Content-Type;
bh=o8/9XRPNBSb6rQV6HcDwELycPOzUJqxucQ/nMDyby+o=;
b=r6hmfVu3PlK5UN/X+kDNdo8TkUbOkfVn6+tT3VtTr30ic5BMR9vuyrZED4ARPF74
eywsS4yJTH3S3EB0IBX5yao3SN0WFNR23EUszb8LWgSpL0lz4+ZGqAfbjWP6UvI8
2XVzbjiT2tDP2ONkvM5e9g06CuC1VH2Bte5+S/Qke61W8OaagNu8sIcu6MNfoUiO
b/esckpPfghQtqDs693+pxDtuk9SBrbf14qZ2ih9eVV/38dRdz5B22pq8Kfws9yZ
hjvQlCDfovONXEEf6+lD1rs9p0NvKEIeIK/BFxbUmShXAyL3/LlYVLELEwzQ/mnl
zoIwzGQJ9u8i005oZVUnJA==;
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="UTF-8"
Date: Mon, 14 Nov 2022 11:02:49 -0800
Message-ID: <67.91.14851.9D092736@ccg13mail05>
X-PP-REQUESTED-TIME: 1668452563268
X-PP-Email-transmission-Id: ed77fc42-644e-11ed-9b35-3cecef442a74
PP-Correlation-Id: f452526a2e2b2
Subject: Billing Department updated your invoice ( ALS56730 )
X-MaxCode-Template: PPC001082
To: PayPal User <Shannon@DUTA788.onmicrosoft.com>
From: "service@paypal.com" <service@paypal.com>
X-Email-Type-Id: PPC001082
MIME-Version: 1.0
X-PP-Priority: 0-none-false
AMQ-Delivery-Message-Id: nullval
X-XPT-XSL-Name: nullval
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: adbfa5e6-3343-4fe0-8aa8-9f0cc484823f:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic:
CWLGBR01FT040:EE_|CWLP123MB6161:EE_|LO0P123MB5990:EE_
X-MS-Office365-Filtering-Correlation-Id:
452e8e78-adb1-4e0a-a2a8-08dac672d498
X-LD-Processed: adbfa5e6-3343-4fe0-8aa8-9f0cc484823f,ExtAddr,ExtFwd
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info:
2o8K8GPepKbvSuDzcJSJEaPPJUjSF0Pz2lXFCuD3ntk2FbMxdmjCJ+L9Vd5xoRsR/U1olPVmhvPDe2wI+UBuNKyCRH10ZBldcYIq5hygqdSUJrM+y1ihGMFqJe4jzCEI9Z9+YuSis3p1RLiObrP4ou7sp2CA+75F+gRhk2pIRwV4h27qMWGC2TkxbCuZkP1ueui8m7FKziGkgaBkediwjhKsk4ZNJBOB/dNNetHfNTHFnVd6WhcxWKIn2ZplOIO8q0UWStiezMYesq/of/8Qp75xOctr42bPumqqYo04CUk232E/YkWf97+7UmXla1wg097taHt3gPMDzQ3MfgX24cYcIlYgL/4T0nfBQm2PwtkxzW8qKdxv/1UjU3vQNae+ip/k+UWfM72lNF8rpRZKAyBvwrdKljVJ1XV4ZIplbjYpnptKlqGt9XTXDNEzHCxBYtq0ToNon9k1FRUZYi2otTDvXmCsSn48mPkZOjjKzp6MnvfWO/uevZQBm/dcGNX/5y6GfWsPpkEnhQEx9abVqadhIKU5uaS754VFK+GkqFVQEPbq5HTnlCSVwVlzEswvE0mlavXinvSh940NhV0gQ2CjehU9qOHlrdb9iDTdTHVuV2gjPLCi4MUmdiEHl0QdeixCM9XFwo5BekIbL3sXVfhOaQ8xE7sO/YVs/weLJyjfAV2EJ1qNwoZypiOH8wDuu4r5F43QXA2R/jq+ytHfQBOmFF7pByHyPL94mJK23PfpxjeSx2DUGNB3OqEJyRMeZzZgl5juDnPohiJXw0fASMdhScb6I0WPZ1JDHmV0xDHCrNQjrpeGH4iZoRBMTqreiXfSktAPxKDgdTCzP+gkzW2P5TX0lDClrKSNgACTpdJLYkNCJLcZtm5K12mSMdooJe/haV0wadI0QBQtZhox1dEA3SkGgA2abM6XQRZOLTw=
X-Forefront-Antispam-Report:
CIP:173.0.84.228;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:
mx3.slc.paypal.com;PTR:mx3.slc.paypal.com;CAT:NONE;SFS:;DIR:OUT;SFP:1101;
X-ExternalRecipientOutboundConnectors: adbfa5e6-3343-4fe0-8aa8-9f0cc484823f
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: DUTA788.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Nov 2022 19:02:51.5597
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id:
452e8e78-adb1-4e0a-a2a8-08dac672d498
X-MS-Exchange-CrossTenant-Id: adbfa5e6-3343-4fe0-8aa8-9f0cc484823f
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-CrossTenant-AuthSource:
CWLGBR01FT040.eop-gbr01.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LO0P123MB5990

Snippet from body:

Seller note to customer

Congratulations! Your subscription with Norton Security is now auto renewed
as per your selected plan. You can now continue enjoying our services
smoothly. If you have not authorized this transaction or want to cancel the
subscription, call us immediately -: +1 (888) 731-6375 .
RE: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
>
> How do I stop this? paypal.com <http://paypal.com> is in the default
> DKIM whitelist!
>
>


score USER_IN_DKIM_WHITELIST 0

?
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
> How do I stop this?? paypal.com is in the default DKIM whitelist!
>

That message really looks like it came from Paypal and then was
forwarded by Microsoft to your server. Was it really a fake? That's a
lot of headers to fake if so.

If it was really fake and that paypal-supplied DKIM signature doesn't
validate (I didn't check that), then checking DMARC when you receive
mail and rejecting on p=reject failures would block it.
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
Are you asking me to rescore these back to 0? That will take some effort
to do, but if that's what it takes...

On Mon, Nov 14, 2022 at 3:42 PM Marc <Marc@f1-outsourcing.eu> wrote:

> >
> > How do I stop this? paypal.com <http://paypal.com> is in the default
> > DKIM whitelist!
> >
> >
>
>
> score USER_IN_DKIM_WHITELIST 0
>
> ?
>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
The DKIM signature looks valid.

On Mon, Nov 14, 2022 at 3:43 PM Alan Hodgson <ahodgson@lists.simkin.ca>
wrote:

> On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
> > How do I stop this? paypal.com is in the default DKIM whitelist!
> >
>
> That message really looks like it came from Paypal and then was
> forwarded by Microsoft to your server. Was it really a fake? That's a
> lot of headers to fake if so.
>
> If it was really fake and that paypal-supplied DKIM signature doesn't
> validate (I didn't check that), then checking DMARC when you receive
> mail and rejecting on p=reject failures would block it.
>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
So what I'm going to do is turn shortcircuit off for USER_IN_DKIM_WHITELIST

Create a meta to catch papal.com as the from address and score appropriately
Create a counter meta to score other deserving DKIM-signers appropriately

On Mon, Nov 14, 2022 at 3:43 PM Alan Hodgson <ahodgson@lists.simkin.ca>
wrote:

> On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
> > How do I stop this? paypal.com is in the default DKIM whitelist!
> >
>
> That message really looks like it came from Paypal and then was
> forwarded by Microsoft to your server. Was it really a fake? That's a
> lot of headers to fake if so.
>
> If it was really fake and that paypal-supplied DKIM signature doesn't
> validate (I didn't check that), then checking DMARC when you receive
> mail and rejecting on p=reject failures would block it.
>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
Bottom line is I don't think paypal deserves to be default whitelisted in
recent history. I've received a lot of spam actually from paypal and
judiciously report it to phishing@paypal.com with no apparent action or
response.

On Mon, Nov 14, 2022 at 3:56 PM Shawn Iverson <shawniverson@gmail.com>
wrote:

> So what I'm going to do is turn shortcircuit off for USER_IN_DKIM_WHITELIST
>
> Create a meta to catch papal.com as the from address and score
> appropriately
> Create a counter meta to score other deserving DKIM-signers appropriately
>
> On Mon, Nov 14, 2022 at 3:43 PM Alan Hodgson <ahodgson@lists.simkin.ca>
> wrote:
>
>> On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
>> > How do I stop this? paypal.com is in the default DKIM whitelist!
>> >
>>
>> That message really looks like it came from Paypal and then was
>> forwarded by Microsoft to your server. Was it really a fake? That's a
>> lot of headers to fake if so.
>>
>> If it was really fake and that paypal-supplied DKIM signature doesn't
>> validate (I didn't check that), then checking DMARC when you receive
>> mail and rejecting on p=reject failures would block it.
>>
>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
I have also seen the PayPal ecosystem being abused by bad actors sending
things like fake invoices. I am also +1 to remove the domain from the dkim
wl.

Regards, KAM

On Mon, Nov 14, 2022, 16:01 Shawn Iverson <shawniverson@gmail.com> wrote:

> Bottom line is I don't think paypal deserves to be default whitelisted in
> recent history. I've received a lot of spam actually from paypal and
> judiciously report it to phishing@paypal.com with no apparent action or
> response.
>
> On Mon, Nov 14, 2022 at 3:56 PM Shawn Iverson <shawniverson@gmail.com>
> wrote:
>
>> So what I'm going to do is turn shortcircuit off for
>> USER_IN_DKIM_WHITELIST
>>
>> Create a meta to catch papal.com as the from address and score
>> appropriately
>> Create a counter meta to score other deserving DKIM-signers appropriately
>>
>> On Mon, Nov 14, 2022 at 3:43 PM Alan Hodgson <ahodgson@lists.simkin.ca>
>> wrote:
>>
>>> On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
>>> > How do I stop this? paypal.com is in the default DKIM whitelist!
>>> >
>>>
>>> That message really looks like it came from Paypal and then was
>>> forwarded by Microsoft to your server. Was it really a fake? That's a
>>> lot of headers to fake if so.
>>>
>>> If it was really fake and that paypal-supplied DKIM signature doesn't
>>> validate (I didn't check that), then checking DMARC when you receive
>>> mail and rejecting on p=reject failures would block it.
>>>
>>
RE: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
There is no such thing as a default whitelist.

> >>
> >> How do I stop this? paypal.com <http://paypal.com> is in the
> default
> >> DKIM whitelist!
> >>
> >
> >
> > score USER_IN_DKIM_WHITELIST 0
>
> would affect *every* mail in the default whitelist and so be a knee-jerk
> reaction without brain
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
Oh yeah?

[xxxx@xxxxx~]$ grep DEF_WHITELIST
/var/lib/spamassassin/3.004006/updates_spamassassin_org/*
/var/lib/spamassassin/3.004004/updates_spamassassin_org/30_text_de.cf:lang
de describe USER_IN_DEF_WHITELIST Absenderadresse steht in der allgemeinen
weien Liste
/var/lib/spamassassin/3.004004/updates_spamassassin_org/30_text_fr.cf:lang
fr describe USER_IN_DEF_WHITELIST Expditeur dans la liste OK par dfaut
de SpamAssassin
/var/lib/spamassassin/3.004004/updates_spamassassin_org/30_text_pl.cf:lang
pl describe USER_IN_DEF_WHITELIST Uytkownik jest wymieniony w domylnej
white-list (biaej licie)
/var/lib/spamassassin/3.004004/updates_spamassassin_org/30_text_pt_br.cf:lang
pt_BR describe USER_IN_DEF_WHITELIST Endereo do From: est na whitelist padro
/var/lib/spamassassin/3.004004/updates_spamassassin_org/50_scores.cf:#score
USER_IN_DEF_WHITELIST -15.000 - Moved to 60_whitelist.cf
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_shortcircuit.cf:priority
USER_IN_DEF_WHITELIST -1000
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_whitelist.cf:
meta USER_IN_DEF_WHITELIST (USER_IN_DEF_WELCOMELIST)
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_whitelist.cf:
describe USER_IN_DEF_WHITELIST DEPRECATED: See USER_IN_WELCOMELIST
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_whitelist.cf:
tflags USER_IN_DEF_WHITELIST userconf nice noautolearn
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_whitelist.cf:
score USER_IN_DEF_WHITELIST -15.0
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_whitelist.cf:
meta USER_IN_DEF_WHITELIST (USER_IN_DEF_WELCOMELIST)
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_whitelist.cf:
describe USER_IN_DEF_WHITELIST DEPRECATED: See
USER_IN_DEF_WELCOMELIST
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_whitelist.cf:
tflags USER_IN_DEF_WHITELIST userconf nice noautolearn
/var/lib/spamassassin/3.004004/updates_spamassassin_org/60_whitelist.cf:
score USER_IN_DEF_WHITELIST -15.0
/var/lib/spamassassin/3.004004/updates_spamassassin_org/local.cf:#
shortcircuit USER_IN_DEF_WHITELIST on

On Mon, Nov 14, 2022 at 4:34 PM Marc <Marc@f1-outsourcing.eu> wrote:

>
> There is no such thing as a default whitelist.
>
> > >>
> > >> How do I stop this? paypal.com <http://paypal.com> is in the
> > default
> > >> DKIM whitelist!
> > >>
> > >
> > >
> > > score USER_IN_DKIM_WHITELIST 0
> >
> > would affect *every* mail in the default whitelist and so be a knee-jerk
> > reaction without brain
>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
For those fighting the same battles...

# Default Whitelist Exceptions handling -- SJI 11/14/22
shortcircuit USER_IN_DKIM_WHITELIST off
score USER_IN_DKIM_WHITELIST 0
score USER_IN_DEF_DKIM_WL 0

header CUSTOM_FROM_PAYPAL From:addr =~ /paypal\.com/
meta CUSTOM_DKIM_WL_EXCEPTIONS USER_IN_DKIM_WHITELIST && ENA_FROM_PAYPAL
describe CUSTOM_DKIM_WL_EXCEPTIONS Exception for paypal in DKIM
whitelisting
score CUSTOM_DKIM_WL_EXCEPTIONS 0.001

meta CUSTOM_DKIM_OK USER_IN_DKIM_WHITELIST &&
!CUSTOM_DKIM_WL_EXCEPTIONS
describe CUSTOM_DKIM_OK All other whitelisted senders
score CUSTOM_DKIM_OK -100

On Mon, Nov 14, 2022 at 3:56 PM Shawn Iverson <shawniverson@gmail.com>
wrote:

> So what I'm going to do is turn shortcircuit off for USER_IN_DKIM_WHITELIST
>
> Create a meta to catch papal.com as the from address and score
> appropriately
> Create a counter meta to score other deserving DKIM-signers appropriately
>
> On Mon, Nov 14, 2022 at 3:43 PM Alan Hodgson <ahodgson@lists.simkin.ca>
> wrote:
>
>> On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
>> > How do I stop this? paypal.com is in the default DKIM whitelist!
>> >
>>
>> That message really looks like it came from Paypal and then was
>> forwarded by Microsoft to your server. Was it really a fake? That's a
>> lot of headers to fake if so.
>>
>> If it was really fake and that paypal-supplied DKIM signature doesn't
>> validate (I didn't check that), then checking DMARC when you receive
>> mail and rejecting on p=reject failures would block it.
>>
>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
Corrected...

Default Whitelist Exceptions handling -- SJI 11/14/22
shortcircuit USER_IN_DKIM_WHITELIST off
score USER_IN_DKIM_WHITELIST 0
score USER_IN_DEF_DKIM_WL 0

header CUSTOM_FROM_PAYPAL From:addr =~ /paypal\.com/
meta CUSTOM_DKIM_WL_EXCEPTIONS USER_IN_DKIM_WHITELIST &&
CUSTOM_FROM_PAYPAL
describe CUSTOM_DKIM_WL_EXCEPTIONS Exception for paypal in DKIM
whitelisting
score CUSTOM_DKIM_WL_EXCEPTIONS 0.001

meta CUSTOM_DKIM_OK USER_IN_DKIM_WHITELIST &&
!CUSTOM_DKIM_WL_EXCEPTIONS
describe CUSTOM_DKIM_OK All other whitelisted senders
score CUSTOM_DKIM_OK -100

On Mon, Nov 14, 2022 at 4:38 PM Shawn Iverson <shawniverson@gmail.com>
wrote:

> For those fighting the same battles...
>
> # Default Whitelist Exceptions handling -- SJI 11/14/22
> shortcircuit USER_IN_DKIM_WHITELIST off
> score USER_IN_DKIM_WHITELIST 0
> score USER_IN_DEF_DKIM_WL 0
>
> header CUSTOM_FROM_PAYPAL From:addr =~ /paypal\.com/
> meta CUSTOM_DKIM_WL_EXCEPTIONS USER_IN_DKIM_WHITELIST &&
> ENA_FROM_PAYPAL
> describe CUSTOM_DKIM_WL_EXCEPTIONS Exception for paypal in DKIM
> whitelisting
> score CUSTOM_DKIM_WL_EXCEPTIONS 0.001
>
> meta CUSTOM_DKIM_OK USER_IN_DKIM_WHITELIST &&
> !CUSTOM_DKIM_WL_EXCEPTIONS
> describe CUSTOM_DKIM_OK All other whitelisted senders
> score CUSTOM_DKIM_OK -100
>
> On Mon, Nov 14, 2022 at 3:56 PM Shawn Iverson <shawniverson@gmail.com>
> wrote:
>
>> So what I'm going to do is turn shortcircuit off for
>> USER_IN_DKIM_WHITELIST
>>
>> Create a meta to catch papal.com as the from address and score
>> appropriately
>> Create a counter meta to score other deserving DKIM-signers appropriately
>>
>> On Mon, Nov 14, 2022 at 3:43 PM Alan Hodgson <ahodgson@lists.simkin.ca>
>> wrote:
>>
>>> On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
>>> > How do I stop this? paypal.com is in the default DKIM whitelist!
>>> >
>>>
>>> That message really looks like it came from Paypal and then was
>>> forwarded by Microsoft to your server. Was it really a fake? That's a
>>> lot of headers to fake if so.
>>>
>>> If it was really fake and that paypal-supplied DKIM signature doesn't
>>> validate (I didn't check that), then checking DMARC when you receive
>>> mail and rejecting on p=reject failures would block it.
>>>
>>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
> How do I stop this?  paypal.com is in the default DKIM whitelist!
>
I'd treat it as spam because the domain name in the From header doesn't
match the domain name in the Message-ID header. 

That works for me, with virtually no false mail rejections.

Martin
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
On 11/14/22 21:14, Shawn Iverson wrote:
> How do I stop this? paypal.com <http://paypal.com> is in the default DKIM whitelist!

Does this work on your sample ?
The body you posted is only partial.

uri __URI_IMG_PAYPAL /^https:\/\/www\.paypalobjects\.com\/(?:digitalassets|en_US|ui\-web)\/.{1,64}\.(?:gif|jpg|png)/
meta __PAYPAL_IMG_NOT_RCVD_PAYP __URI_IMG_PAYPAL && !__HDR_RCVD_PAYPAL
meta GB_PAYPAL_IMG_NOT_RCVD_PAYP __PAYPAL_IMG_NOT_RCVD_PAYP && !__HAS_ERRORS_TO && !__MSGID_LIST && !__MSGID_GUID && !__RCD_RDNS_SMTP
describe GB_PAYPAL_IMG_NOT_RCVD_PAYP Paypal hosted image but message not from Paypal
score GB_PAYPAL_IMG_NOT_RCVD_PAYP 2.500 # limit

Giovanni
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
On 14.11.22 16:39, Shawn Iverson wrote:
>Corrected...
>
>Default Whitelist Exceptions handling -- SJI 11/14/22
>shortcircuit USER_IN_DKIM_WHITELIST off
>score USER_IN_DKIM_WHITELIST 0
>score USER_IN_DEF_DKIM_WL 0
>
>header CUSTOM_FROM_PAYPAL From:addr =~ /paypal\.com/
>meta CUSTOM_DKIM_WL_EXCEPTIONS USER_IN_DKIM_WHITELIST &&
>CUSTOM_FROM_PAYPAL
>describe CUSTOM_DKIM_WL_EXCEPTIONS Exception for paypal in DKIM
>whitelisting
>score CUSTOM_DKIM_WL_EXCEPTIONS 0.001
>
>meta CUSTOM_DKIM_OK USER_IN_DKIM_WHITELIST &&
>!CUSTOM_DKIM_WL_EXCEPTIONS
>describe CUSTOM_DKIM_OK All other whitelisted senders
>score CUSTOM_DKIM_OK -100

I guess removing paypal from w*list should be easier:

% pwd
/var/lib/spamassassin/4.000000
% grep -Firh def_welcomelist_from_dkim | grep -i paypal
def_welcomelist_from_dkim *@* paypal.com
def_welcomelist_from_dkim *@paypal.com
def_welcomelist_from_dkim *@*.paypal.com
def_welcomelist_from_dkim *@paypal.co.uk
def_welcomelist_from_dkim *@*.paypal.co.uk
def_welcomelist_from_dkim *@paypal.at
def_welcomelist_from_dkim *@*.paypal.at
def_welcomelist_from_dkim *@paypal.be
def_welcomelist_from_dkim *@*.paypal.be
def_welcomelist_from_dkim *@paypal.de
def_welcomelist_from_dkim *@*.paypal.de
def_welcomelist_from_dkim *@paypal.es
def_welcomelist_from_dkim *@*.paypal.es
def_welcomelist_from_dkim *@paypal.fr
def_welcomelist_from_dkim *@*.paypal.fr
def_welcomelist_from_dkim *@paypal.ie
def_welcomelist_from_dkim *@*.paypal.ie
def_welcomelist_from_dkim *@paypal.it
def_welcomelist_from_dkim *@*.paypal.it
def_welcomelist_from_dkim *@paypal.nl
def_welcomelist_from_dkim *@*.paypal.nl
def_welcomelist_from_dkim *@paypal.pt
def_welcomelist_from_dkim *@*.paypal.pt
def_welcomelist_from_dkim *@paypal.ca
def_welcomelist_from_dkim *@*.paypal.ca

so it should be removed by:

unwelcomelist_from_dkim *@* paypal.com
unwelcomelist_from_dkim *@paypal.com
unwelcomelist_from_dkim *@*.paypal.com
unwelcomelist_from_dkim *@paypal.co.uk
unwelcomelist_from_dkim *@*.paypal.co.uk
unwelcomelist_from_dkim *@paypal.at
unwelcomelist_from_dkim *@*.paypal.at
unwelcomelist_from_dkim *@paypal.be
unwelcomelist_from_dkim *@*.paypal.be
unwelcomelist_from_dkim *@paypal.de
unwelcomelist_from_dkim *@*.paypal.de
unwelcomelist_from_dkim *@paypal.es
unwelcomelist_from_dkim *@*.paypal.es
unwelcomelist_from_dkim *@paypal.fr
unwelcomelist_from_dkim *@*.paypal.fr
unwelcomelist_from_dkim *@paypal.ie
unwelcomelist_from_dkim *@*.paypal.ie
unwelcomelist_from_dkim *@paypal.it
unwelcomelist_from_dkim *@*.paypal.it
unwelcomelist_from_dkim *@paypal.nl
unwelcomelist_from_dkim *@*.paypal.nl
unwelcomelist_from_dkim *@paypal.pt
unwelcomelist_from_dkim *@*.paypal.pt
unwelcomelist_from_dkim *@paypal.ca
unwelcomelist_from_dkim *@*.paypal.ca

with SA3.4 replace "welcomelist" by "whitelist"



--
Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Depression is merely anger without enthusiasm.
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
Thank you Matus. I was not aware of an unwelcomelist_from_dkim option.
This helps immensely.

On Tue, Nov 15, 2022 at 4:35 AM Matus UHLAR - fantomas <uhlar@fantomas.sk>
wrote:

> On 14.11.22 16:39, Shawn Iverson wrote:
> >Corrected...
> >
> >Default Whitelist Exceptions handling -- SJI 11/14/22
> >shortcircuit USER_IN_DKIM_WHITELIST off
> >score USER_IN_DKIM_WHITELIST 0
> >score USER_IN_DEF_DKIM_WL 0
> >
> >header CUSTOM_FROM_PAYPAL From:addr =~ /paypal\.com/
> >meta CUSTOM_DKIM_WL_EXCEPTIONS USER_IN_DKIM_WHITELIST &&
> >CUSTOM_FROM_PAYPAL
> >describe CUSTOM_DKIM_WL_EXCEPTIONS Exception for paypal in DKIM
> >whitelisting
> >score CUSTOM_DKIM_WL_EXCEPTIONS 0.001
> >
> >meta CUSTOM_DKIM_OK USER_IN_DKIM_WHITELIST &&
> >!CUSTOM_DKIM_WL_EXCEPTIONS
> >describe CUSTOM_DKIM_OK All other whitelisted senders
> >score CUSTOM_DKIM_OK -100
>
> I guess removing paypal from w*list should be easier:
>
> % pwd
> /var/lib/spamassassin/4.000000
> % grep -Firh def_welcomelist_from_dkim | grep -i paypal
> def_welcomelist_from_dkim *@* paypal.com
> def_welcomelist_from_dkim *@paypal.com
> def_welcomelist_from_dkim *@*.paypal.com
> def_welcomelist_from_dkim *@paypal.co.uk
> def_welcomelist_from_dkim *@*.paypal.co.uk
> def_welcomelist_from_dkim *@paypal.at
> def_welcomelist_from_dkim *@*.paypal.at
> def_welcomelist_from_dkim *@paypal.be
> def_welcomelist_from_dkim *@*.paypal.be
> def_welcomelist_from_dkim *@paypal.de
> def_welcomelist_from_dkim *@*.paypal.de
> def_welcomelist_from_dkim *@paypal.es
> def_welcomelist_from_dkim *@*.paypal.es
> def_welcomelist_from_dkim *@paypal.fr
> def_welcomelist_from_dkim *@*.paypal.fr
> def_welcomelist_from_dkim *@paypal.ie
> def_welcomelist_from_dkim *@*.paypal.ie
> def_welcomelist_from_dkim *@paypal.it
> def_welcomelist_from_dkim *@*.paypal.it
> def_welcomelist_from_dkim *@paypal.nl
> def_welcomelist_from_dkim *@*.paypal.nl
> def_welcomelist_from_dkim *@paypal.pt
> def_welcomelist_from_dkim *@*.paypal.pt
> def_welcomelist_from_dkim *@paypal.ca
> def_welcomelist_from_dkim *@*.paypal.ca
>
> so it should be removed by:
>
> unwelcomelist_from_dkim *@* paypal.com
> unwelcomelist_from_dkim *@paypal.com
> unwelcomelist_from_dkim *@*.paypal.com
> unwelcomelist_from_dkim *@paypal.co.uk
> unwelcomelist_from_dkim *@*.paypal.co.uk
> unwelcomelist_from_dkim *@paypal.at
> unwelcomelist_from_dkim *@*.paypal.at
> unwelcomelist_from_dkim *@paypal.be
> unwelcomelist_from_dkim *@*.paypal.be
> unwelcomelist_from_dkim *@paypal.de
> unwelcomelist_from_dkim *@*.paypal.de
> unwelcomelist_from_dkim *@paypal.es
> unwelcomelist_from_dkim *@*.paypal.es
> unwelcomelist_from_dkim *@paypal.fr
> unwelcomelist_from_dkim *@*.paypal.fr
> unwelcomelist_from_dkim *@paypal.ie
> unwelcomelist_from_dkim *@*.paypal.ie
> unwelcomelist_from_dkim *@paypal.it
> unwelcomelist_from_dkim *@*.paypal.it
> unwelcomelist_from_dkim *@paypal.nl
> unwelcomelist_from_dkim *@*.paypal.nl
> unwelcomelist_from_dkim *@paypal.pt
> unwelcomelist_from_dkim *@*.paypal.pt
> unwelcomelist_from_dkim *@paypal.ca
> unwelcomelist_from_dkim *@*.paypal.ca
>
> with SA3.4 replace "welcomelist" by "whitelist"
>
>
>
> --
> Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/
> Warning: I wish NOT to receive e-mail advertising to this address.
> Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
> Depression is merely anger without enthusiasm.
>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
Thank you Giovanni, I'll give this rule a try. I think the bigger issue was
that the default welcomelist was shortcircuiting any further rule
evaluation. Now I'm able to score these emails with rules like this one :)

On Tue, Nov 15, 2022 at 2:44 AM <giovanni@paclan.it> wrote:

> On 11/14/22 21:14, Shawn Iverson wrote:
> > How do I stop this? paypal.com <http://paypal.com> is in the default
> DKIM whitelist!
>
> Does this work on your sample ?
> The body you posted is only partial.
>
> uri __URI_IMG_PAYPAL
> /^https:\/\/www\.paypalobjects\.com\/(?:digitalassets|en_US|ui\-web)\/.{1,64}\.(?:gif|jpg|png)/
> meta __PAYPAL_IMG_NOT_RCVD_PAYP __URI_IMG_PAYPAL &&
> !__HDR_RCVD_PAYPAL
> meta GB_PAYPAL_IMG_NOT_RCVD_PAYP __PAYPAL_IMG_NOT_RCVD_PAYP &&
> !__HAS_ERRORS_TO && !__MSGID_LIST && !__MSGID_GUID && !__RCD_RDNS_SMTP
> describe GB_PAYPAL_IMG_NOT_RCVD_PAYP Paypal hosted image but message
> not from Paypal
> score GB_PAYPAL_IMG_NOT_RCVD_PAYP 2.500 # limit
>
> Giovanni
>
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
On 2022-11-14 at 16:11:10 UTC-0500 (Mon, 14 Nov 2022 16:11:10 -0500)
Kevin A. McGrail <kmcgrail@apache.org>
is rumored to have said:

> I have also seen the PayPal ecosystem being abused by bad actors sending
> things like fake invoices. I am also +1 to remove the domain from the dkim
> wl.

Same.

Paypal could fix this abuse by over-signing the Resent-From header.


> Regards, KAM
>
> On Mon, Nov 14, 2022, 16:01 Shawn Iverson <shawniverson@gmail.com> wrote:
>
>> Bottom line is I don't think paypal deserves to be default whitelisted in
>> recent history. I've received a lot of spam actually from paypal and
>> judiciously report it to phishing@paypal.com with no apparent action or
>> response.
>>
>> On Mon, Nov 14, 2022 at 3:56 PM Shawn Iverson <shawniverson@gmail.com>
>> wrote:
>>
>>> So what I'm going to do is turn shortcircuit off for
>>> USER_IN_DKIM_WHITELIST
>>>
>>> Create a meta to catch papal.com as the from address and score
>>> appropriately
>>> Create a counter meta to score other deserving DKIM-signers appropriately
>>>
>>> On Mon, Nov 14, 2022 at 3:43 PM Alan Hodgson <ahodgson@lists.simkin.ca>
>>> wrote:
>>>
>>>> On Mon, 2022-11-14 at 15:14 -0500, Shawn Iverson wrote:
>>>>> How do I stop this? paypal.com is in the default DKIM whitelist!
>>>>>
>>>>
>>>> That message really looks like it came from Paypal and then was
>>>> forwarded by Microsoft to your server. Was it really a fake? That's a
>>>> lot of headers to fake if so.
>>>>
>>>> If it was really fake and that paypal-supplied DKIM signature doesn't
>>>> validate (I didn't check that), then checking DMARC when you receive
>>>> mail and rejecting on p=reject failures would block it.
>>>>
>>>


--
Bill Cole
bill@scconsult.com or billcole@apache.org
(AKA @grumpybozo and many *@billmail.scconsult.com addresses)
Not Currently Available For Hire
Re: Spam DKIM signed by Paypal coming from their Microsoft Tenant? [ In reply to ]
Shawn Iverson skrev den 2022-11-14 21:14:
> How do I stop this? paypal.com is in the default DKIM whitelist!

> DKIM-Signature: v=1; a=rsa-sha256; d=paypal.com; s=pp-dkim1;
> c=relaxed/relaxed;
> q=dns/txt; i=@paypal.com; t=1668452569;
> h=From:From:Subject:Date:To:MIME-Version:Content-Type;
> bh=o8/9XRPNBSb6rQV6HcDwELycPOzUJqxucQ/nMDyby+o=;
> b=r6hmfVu3PlK5UN/X+kDNdo8TkUbOkfVn6+tT3VtTr30ic5BMR9vuyrZED4ARPF74
> eywsS4yJTH3S3EB0IBX5yao3SN0WFNR23EUszb8LWgSpL0lz4+ZGqAfbjWP6UvI8
> 2XVzbjiT2tDP2ONkvM5e9g06CuC1VH2Bte5+S/Qke61W8OaagNu8sIcu6MNfoUiO
> b/esckpPfghQtqDs693+pxDtuk9SBrbf14qZ2ih9eVV/38dRdz5B22pq8Kfws9yZ
> hjvQlCDfovONXEEf6+lD1rs9p0NvKEIeIK/BFxbUmShXAyL3/LlYVLELEwzQ/mnl
> zoIwzGQJ9u8i005oZVUnJA==;

double From, missing message-id, potentely forged msgs can be reused
from a forgin standpoint

how to stop it ?, i can block dkim domains that makes pass on forged
content

problem with dmarc is not ditating aligment, it would stop forwarding
aswell

we all loose on forwarding emails

i give up for now :)

maybe hehe, need unmodifiede sample to help

to pmc members add funcs to test h= have minimal requered headers
signed, or as above double from, with header was later removed ?