Go Premium for a chance to win a PS4. Enter to Win


Very dodgy looking email I received (Supposably from MS!!)

Posted on 2004-10-06
Medium Priority
Last Modified: 2012-03-15
I received this email, the from address was "Microsoft [aspnetw3@email.microsoft.com]". I didnt click any of the links but noticed that they all linked to "http://r. email. microsoft. com/"
I have intentionally put spaces inside the actual linkes that the hyperlinked text pointed to so that some other user cant mistakenly come along and click on them. Does anyone know what or who ownes the site "http://r. email. microsoft. com/" or have you received something similar. There was also an embedded image in the HTML mail which pointed to <img width="1" height="1" src="http:// open . delivery . net /o?1.2.Gb.BJ.11G9*K.Buh4PE..M..1Gg0.ZD0w2r_n99" alt=" ">
The addresses in the text are legitimate MS addresses but what they actually link to appears to be some of the dodgyiest addresses ive seen.

Here is the text of the mail!!!
Dear ASP.NET Customer,

This alert is to advise you of the availability of a web page that
discusses an investigation Microsoft is currently conducting into
public reports of a security vulnerability in ASP.NET. A malicious
user could provide a specially-formed URL that could result in the
unintended serving of secured content.

This alert is also to advise you of the availability of a new
Microsoft Knowledge Base article: 887459. This article contains
prescriptive guidance with steps customers can implement on their
ASP.NET applications to help protect against a wide variety of
malformed URL attacks.

Microsoft is providing this prescriptive guidance in order to inform
customers as quickly as possible about the vulnerability and
information on how to prevent an attack. Microsoft is actively
investigating this issue and plans to release additional guidance
and a security update to remedy the issue as soon as possible.
The Microsoft Knowledge Base article can be viewed here:
(linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cide.1Gg0.30JH9u)

The web page that discusses the current investigation into the
public reports of a vulnerability in ASP.Net can be viewed here:
(linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidg.1Gg0.30fn9w)

If you have any questions, please see the discussion in the ASP.NET
Security Forums at:

(linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidi.1Gg0.310H9y)

Thank you,
The Microsoft ASP.NET Team

© 2004 Microsoft Corporation. All rights reserved. Microsoft is a
registered trademark of Microsoft Corporation in the United States
and/or other countries.

Protect Your PC: 3 steps to help ensure your PC is protected
Microsoft wants to help ensure your PC is protected from viruses and
worms like Mydoom and Blaster, as well as from future threats.
Please go to www.microsoft.com/protect (linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidk.1Gg0.31Mn9_) and follow these steps today.

     1. Use an Internet Firewall
     2. Update Your Computer
     3. Use Up-to-Date Antivirus Software

To get more information and resources about how to help protect your
PC, go to www.microsoft.com/protect (linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidk.1Gg0.31Mn9_).

Review our Privacy Statement (linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidm.1Gg0.31jHA0).

If you prefer not to receive future promotional e-mails of this type
from Microsoft, please click here (linked to: http://p. email. microsoft. com/m/u/mst/emd/m.asp?e='myemail'&cid='idno') to unsubscribe. We will promptly
update your preferences; however, you may still receive previously
initiated promotional communications from Microsoft.

This e-mail is intended for distribution within the United States.
Please contact your local Microsoft® Subsidiary for similar
offerings outside the U.S.

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052

 (embedded 1x1 image here)
Question by:stumpy1
  • 4
  • 4
  • 3
  • +2
LVL 32

Expert Comment

ID: 12239226
Hi stumpy1,

Those are the links always used in MS's e-mails. Nothing dodgy about it although I always found it pretty stupid also. I've never been able to find out why they made their links like this.

Have you subscribed to some newsletter from MS?


LVL 32

Expert Comment

ID: 12239284
Just for your information, Whois lookup for r.email.microsoft.com:

Lookup for open.delivery.net:
http://www.whois.sc/delivery.net (which is an advertizement company)


Author Comment

ID: 12239460
Im subscribed to a few of Microsofts newsletters. The emails are usually just like a normal Microsoft page on their site. Also the links in the emails usually link to http://go.microsoft.com/?linkid='linkid'

I have never seen a link to r.email.microsoft.com before, also the email was very plain as opposed to their usual emails.

Also their emails usually come from some convuluted address @newsletters.microsoft.com or @pasport.com.

Because of all these reasons I just became extremely suspicious of this email straight away!
 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.


Author Comment

ID: 12239605
I also posted this in the Lounge to get a bit more feedback.

I had my suspicions confirmed there
LVL 32

Accepted Solution

LucF earned 80 total points
ID: 12239944
Hmm... you may be right... but I'd seen them before in other mails from microsoft, all directing to the right page, which these links ultimately also do, but they're redirected :(

I've just checked and noticed Ameba is right, seems like a stupid whois site I've been using in the past...

C:\>ping r.email.microsoft.com
Pinging r.email.microsoft.com [] with 32 bytes of data:

C:\>ping -a
Pinging respond.digitalimpact.net [] with 32 bytes of data:



Expert Comment

ID: 12240871
Hi LucF, stumpy1,

Such occurances not only happen to microsoft letters... lately i've caught one email which use similar technique to goto another web to collect user data. they pose themselves as ebay tech team...

LVL 27

Expert Comment

by:Asta Cu
ID: 12242087
How to Tell If a Microsoft Security-Related Message Is Genuine
LVL 27

Expert Comment

by:Asta Cu
ID: 12242120
The Information Is on Microsoft.com
We never send notices about security updates or incidents until after we publish information about them on our Web site. If you are ever in doubt about the authenticity of a Microsoft security e-mail notification, check the Security site on Microsoft.com to see if the information is listed there.

Expert Comment

ID: 12245261
I have never got any mail from microsoft.

Author Comment

ID: 12247274
The text for the links in the email are for legitimate issues - incidents, its what they actually link to thats dodgy.

Definately something not right there :-)

This type of mail can come from almost any source, this is just one of the most legitimate looking examples of this type of mail ive seen.
LVL 27

Expert Comment

by:Asta Cu
ID: 12248056
I see, still looking; found this.

About Email.Microsoft.com

Email.Microsoft.com is a Microsoft-owned domain that is used to deliver marketing e-mail by Digital Impact, a Microsoft vendor. If you prefer not to receive future promotional e-mails of this type from Microsoft, please click here to unsubscribe. We will promptly update your preferences; however, you may still receive previously initiated promotional communications from Microsoft.
You may also forward the e-mail you received to postmaster@email.microsoft.com or draft an e-mail to postmaster@email.microsoft.com with your e-mail address and a description of the list from which you would like to be removed.

Microsoft is committed to sending you only the e-mail that you want to receive. If you have questions about your privacy, send us a message or write a letter to:

Microsoft.com Privacy
Microsoft Corporation
One Microsoft Way
Redmond, Washington 98052


Corporate link to Email issues/spam/faked IDs, etc.
Microsoft Is Committed to Help End the Spam Epidemic

Be careful about disclosing your e-mail address
 Set up an e-mail address dedicated solely to Web transactions. Consider using a free mail service to set up an e-mail account for your online transactions. This will help you keep your real e-mail address private.
• Only share your primary e-mail address with people you know. Avoid listing your e-mail address in large Internet directories. Don't even post it on your own Web site.
• Disguise your e-mail address. Use a disguised address whenever you post it to a newsgroup, chat room, or bulletin board. For example, you could give your e-mail address as "s0me0ne@example.c0m" using "0" (zero) instead of "o." A person can interpret your address, but the automated programs that spammers use cannot.
• Watch out for checked boxes. When you buy things online, companies sometimes pre-check boxes to indicate that it's fine to sell or give your e-mail address to responsible parties. Click the check box to clear it if you don't want the company to contact you.


Handling unwanted e-mail (spam)

.... probably all stuff you know, but was updating my links so posting here as well "just in case there's something new here for you".

LVL 27

Expert Comment

by:Asta Cu
ID: 12248067

Author Comment

ID: 12248180
Email.Microsoft.com looks legitimate, however the worrying thing in the email was that the domain was

trust MS to send out mail that looks like a virus email ... ... As with any other dodgy email, I didnt click on any of the links, especially the unsubscribe link (aka. confirm this address exists.)

Featured Post

Lessons on Wi-Fi & Recommendations on KRACK

Simplicity and security can be a difficult  balance for any business to tackle. Join us on December 6th for a look at your company's biggest security gap. We will also address the most recent attack, "KRACK" and provide recommendations on how to secure your Wi-Fi network today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

UPDATE - 6/15/2011 Added support for Release Update 6 Maintenance Patch 2 Point Patch 1 (RU6 MP2 PP1). Fixed a defect in the username field that was hard-coded to look for a specific domain (left over code from testing). This release will be the …
I recently had to create a utility which aim is to update McAfee's Virusscan and that had to be launched from a command line. I thought I’d share my experience with you. Why is it useful to be able to update an Antivirus from the command line?…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question