Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Very dodgy looking email I received (Supposably from MS!!)

Posted on 2004-10-06
Medium Priority
Last Modified: 2012-03-15
I received this email, the from address was "Microsoft []". I didnt click any of the links but noticed that they all linked to "http://r. email. microsoft. com/"
I have intentionally put spaces inside the actual linkes that the hyperlinked text pointed to so that some other user cant mistakenly come along and click on them. Does anyone know what or who ownes the site "http://r. email. microsoft. com/" or have you received something similar. There was also an embedded image in the HTML mail which pointed to <img width="1" height="1" src="http:// open . delivery . net /o?1.2.Gb.BJ.11G9*K.Buh4PE..M..1Gg0.ZD0w2r_n99" alt=" ">
The addresses in the text are legitimate MS addresses but what they actually link to appears to be some of the dodgyiest addresses ive seen.

Here is the text of the mail!!!
Dear ASP.NET Customer,

This alert is to advise you of the availability of a web page that
discusses an investigation Microsoft is currently conducting into
public reports of a security vulnerability in ASP.NET. A malicious
user could provide a specially-formed URL that could result in the
unintended serving of secured content.

This alert is also to advise you of the availability of a new
Microsoft Knowledge Base article: 887459. This article contains
prescriptive guidance with steps customers can implement on their
ASP.NET applications to help protect against a wide variety of
malformed URL attacks.

Microsoft is providing this prescriptive guidance in order to inform
customers as quickly as possible about the vulnerability and
information on how to prevent an attack. Microsoft is actively
investigating this issue and plans to release additional guidance
and a security update to remedy the issue as soon as possible.
The Microsoft Knowledge Base article can be viewed here:
(linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cide.1Gg0.30JH9u)

The web page that discusses the current investigation into the
public reports of a vulnerability in ASP.Net can be viewed here: 
(linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidg.1Gg0.30fn9w)

If you have any questions, please see the discussion in the ASP.NET
Security Forums at: 
(linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidi.1Gg0.310H9y)

Thank you,
The Microsoft ASP.NET Team

© 2004 Microsoft Corporation. All rights reserved. Microsoft is a
registered trademark of Microsoft Corporation in the United States
and/or other countries.

Protect Your PC: 3 steps to help ensure your PC is protected
Microsoft wants to help ensure your PC is protected from viruses and
worms like Mydoom and Blaster, as well as from future threats.
Please go to (linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidk.1Gg0.31Mn9_) and follow these steps today.

     1. Use an Internet Firewall
     2. Update Your Computer
     3. Use Up-to-Date Antivirus Software

To get more information and resources about how to help protect your
PC, go to (linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidk.1Gg0.31Mn9_).

Review our Privacy Statement (linked to: http://r. email. microsoft. com/r?1.1.Gb.BJ.11G9*K.Buh4PE..M.Cidm.1Gg0.31jHA0).

If you prefer not to receive future promotional e-mails of this type
from Microsoft, please click here (linked to: http://p. email. microsoft. com/m/u/mst/emd/m.asp?e='myemail'&cid='idno') to unsubscribe. We will promptly
update your preferences; however, you may still receive previously
initiated promotional communications from Microsoft.

This e-mail is intended for distribution within the United States.
Please contact your local Microsoft® Subsidiary for similar
offerings outside the U.S.

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052

 (embedded 1x1 image here)
Question by:stumpy1
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 3
  • +2
LVL 32

Expert Comment

ID: 12239226
Hi stumpy1,

Those are the links always used in MS's e-mails. Nothing dodgy about it although I always found it pretty stupid also. I've never been able to find out why they made their links like this.

Have you subscribed to some newsletter from MS?


LVL 32

Expert Comment

ID: 12239284
Just for your information, Whois lookup for

Lookup for (which is an advertizement company)


Author Comment

ID: 12239460
Im subscribed to a few of Microsofts newsletters. The emails are usually just like a normal Microsoft page on their site. Also the links in the emails usually link to'linkid'

I have never seen a link to before, also the email was very plain as opposed to their usual emails.

Also their emails usually come from some convuluted address or

Because of all these reasons I just became extremely suspicious of this email straight away!
Introducing the WatchGuard 420 Access Point

WatchGuard's newest access point includes an 802.11ac Wave 2 chipset, providing the fastest speeds for VoIP, video and music streaming, and large data file transfers. Additionally, enjoy the benefits of strong security as the 3rd radio delivers dedicated WIPS protection!


Author Comment

ID: 12239605
I also posted this in the Lounge to get a bit more feedback.

I had my suspicions confirmed there
LVL 32

Accepted Solution

LucF earned 80 total points
ID: 12239944
Hmm... you may be right... but I'd seen them before in other mails from microsoft, all directing to the right page, which these links ultimately also do, but they're redirected :(

I've just checked and noticed Ameba is right, seems like a stupid whois site I've been using in the past...

Pinging [] with 32 bytes of data:

C:\>ping -a
Pinging [] with 32 bytes of data:



Expert Comment

ID: 12240871
Hi LucF, stumpy1,

Such occurances not only happen to microsoft letters... lately i've caught one email which use similar technique to goto another web to collect user data. they pose themselves as ebay tech team...

LVL 27

Expert Comment

by:Asta Cu
ID: 12242087
How to Tell If a Microsoft Security-Related Message Is Genuine
LVL 27

Expert Comment

by:Asta Cu
ID: 12242120
The Information Is on
We never send notices about security updates or incidents until after we publish information about them on our Web site. If you are ever in doubt about the authenticity of a Microsoft security e-mail notification, check the Security site on to see if the information is listed there.

Expert Comment

ID: 12245261
I have never got any mail from microsoft.

Author Comment

ID: 12247274
The text for the links in the email are for legitimate issues - incidents, its what they actually link to thats dodgy.

Definately something not right there :-)

This type of mail can come from almost any source, this is just one of the most legitimate looking examples of this type of mail ive seen.
LVL 27

Expert Comment

by:Asta Cu
ID: 12248056
I see, still looking; found this.

About is a Microsoft-owned domain that is used to deliver marketing e-mail by Digital Impact, a Microsoft vendor. If you prefer not to receive future promotional e-mails of this type from Microsoft, please click here to unsubscribe. We will promptly update your preferences; however, you may still receive previously initiated promotional communications from Microsoft.
You may also forward the e-mail you received to or draft an e-mail to with your e-mail address and a description of the list from which you would like to be removed.

Microsoft is committed to sending you only the e-mail that you want to receive. If you have questions about your privacy, send us a message or write a letter to: Privacy
Microsoft Corporation
One Microsoft Way
Redmond, Washington 98052


Corporate link to Email issues/spam/faked IDs, etc.
Microsoft Is Committed to Help End the Spam Epidemic

Be careful about disclosing your e-mail address
 Set up an e-mail address dedicated solely to Web transactions. Consider using a free mail service to set up an e-mail account for your online transactions. This will help you keep your real e-mail address private.
• Only share your primary e-mail address with people you know. Avoid listing your e-mail address in large Internet directories. Don't even post it on your own Web site.
• Disguise your e-mail address. Use a disguised address whenever you post it to a newsgroup, chat room, or bulletin board. For example, you could give your e-mail address as "s0me0ne@example.c0m" using "0" (zero) instead of "o." A person can interpret your address, but the automated programs that spammers use cannot.
• Watch out for checked boxes. When you buy things online, companies sometimes pre-check boxes to indicate that it's fine to sell or give your e-mail address to responsible parties. Click the check box to clear it if you don't want the company to contact you.


Handling unwanted e-mail (spam)

.... probably all stuff you know, but was updating my links so posting here as well "just in case there's something new here for you".

LVL 27

Expert Comment

by:Asta Cu
ID: 12248067

Author Comment

ID: 12248180 looks legitimate, however the worrying thing in the email was that the domain was

trust MS to send out mail that looks like a virus email ... ... As with any other dodgy email, I didnt click on any of the links, especially the unsubscribe link (aka. confirm this address exists.)

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The purpose of this Article is to provide information for a newly released variant of malware – with the assumption that many EE Members will have need of the information. According to “Computerworld”, well over one million web sites have been co…
Curious about the latest ransomware attack? Check out our timeline of events surrounding the spread of this new virus along with tips on how to mitigate the damage.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

671 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question