I did not get todays "accountprotection.microsoft.com" spam.
Previously I have had these and they were from account-security-noreply@accountprotection.microsoft.com
I have found on these particular spam that blocking the whole account not the domain seems to be effective whereas the domain on it's own is not. They always seem to use the same account/domain combos - except for the *.onmicrosoft.com ones
It is obviously spoofed but I guess harder for BT' s spam filter to detect as these are actually being delivered via Microsoft's IP addresses acting as relays. So...
1. Microsoft need to stop spammers from using their IP addresses as relays.
2. It woud kind of be nice if BT could dectect when they do. SpamCop does.
You can forward these as attachments to phish@office365.microsoft.com As per Reporting Spam here:
https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/phishing
Thanks everyone for your interesting comments and suggestions.
Since 19th January I have received 16 messages from CouponandGo. Headed with all the shops I might look at...
Marks and Spencer at CouponandGo; Next at CouponandGo; Aldi at CouponandGo; The North Face at CouponandGo; Currys at CouponandGo; Lakes Cottage Holidays at CouponandGo; B&Q at CouponandGo; Currys at CouponandGo......
Just added three more domains to my blocked senders list in the past hour:
*@ingalactus.co.uk
*@promotion.newchic.com
*@sdmt-mk.com
Two had gone in to spam anyway, but one managed to get through to my inbox, despite the various rules I have now set up to try and divert these to a special 'spam' folder I have set up myself.
Yep, I've started getting them from *@sdmt-mk.com and *@ams-mk.com
Nothing for 10 days now they're back.
Different ones from Brazil with malware laced attachments (diagnosed by remote sandbox). Spoofing Argos offers
The same ones from @*onmicrosoft.com offering anti-virus renewals but instead of linking to sites hosted on Digital Ocean they go to a redirect site hosted by OVH and then on to Hetzner except they are broken, so no payload "for now". Suspect the operation has been shutdown/moved and they are starting up again.
Add me to the list of unhappy BT customers fed-up of getting spam from domains & senders I've already marked as Spam & blocked. 8 new messages in my spam folder & 1 in my inbox today alone. BT are failing to protect their customers at a pretty fundamental level but not having sorted this out. A provider the size of BT should have the resources and mechanisms already in place to prevent their customers being exposed to security risks in this way and not be endlessly repeating "we're working on the problem".
Ian
Latest ones this morning claiming to be from McAfee and Martin Lewis all (allegedly) from the email address noreply@r.groupon.com, and which all got through the spam filters and were only diverted to another folder by the rules I have had to set up myself to overcome the current weaknesses in BT's spam filters at the moment. One even came through AFTER I had blocked the r.groupon.com domain!
A coincidence, perhaps. I got exactly the same junk today. Report them as spam.....if you try to add them to blocked senders list, an error report appears.
Report as spam, until the System learns!
Yep, after 3 weeks of nothing. Along comes "Martin Lewis" for me too....
Me too.
@ Ribblelancs
Does clicking to report as spam not verify that you have opened the email?