hard2reg
V2EX  ›  问与答

收到一份来自自己邮箱的勒索邮件?

  •  
  •   hard2reg · May 20, 2025 · 668 views
    This topic created in 388 days ago, the information mentioned may be changed or developed.
    我不知道是真的还是假的,发件人是自己。正文就跟常规的勒索文案一样,他还附上了钱包地址。

    怎么判断是密码泄露还是对方利用某种技术漏洞进行诈骗?

    ____________________________________________________

    OK, 把邮件源扔给 gpt 确认是伪造的了。

    SPF 认证失败:
    Received-SPF: Fail (protection.outlook.com: domain of hotmail.com does not designate 195.96.149.33 as permitted sender)

    DKIM 和 DMARC 都失败:
    dkim=none (message not signed)
    dmarc=fail

    发件服务器与域不匹配:
    Received: from fairwillow.net (195.96.149.33)

    SCL (垃圾邮件信任等级)为 5:
    X-MS-Exchange-Organization-SCL: 5
    Microsoft 的评分系统中,SCL ≥ 5 表示该邮件很可能是垃圾邮件或钓鱼邮件。

    匿名身份投递:
    X-MS-Exchange-Organization-AuthAs: Anonymous
    MFWT
        1
    MFWT  
       May 20, 2025
    SPF 失败,基本上可以认为是 SMTP 发信人伪造
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   3188 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 31ms · UTC 03:54 · PVG 11:54 · LAX 20:54 · JFK 23:54
    ♥ Do have faith in what you're doing.