Link to home
Start Free TrialLog in
Avatar of Robert Granlund
Robert GranlundFlag for United States of America

asked on

GMAIL Spoofing

GMAil and Spam.  A company I am working with has started to get reports of SPAM being sent from an email address that belongs to them.  It is spoofing I guess?  I have gone through the process of setting up all of the SPF entries and DMARC.  However, it has started again. Is there a tolerance level or something that needs to set?  I am at a loss on how to stop the SPOOFING.  any help will be appreciated.

Avatar of Dr. Klahn
Dr. Klahn

... SPAM being sent from an email address that belongs to them ...

In this situation I'd examine the email logs from the outgoing MTA carefully to see if the email is in fact emanating from their network.  Subverting a machine is easy, and once subverted it's nearly certain that it will be used to send spam.

SPF, DKIM and DMARC will be helpful in "a few years" when they become widely adopted and are enforced at the receiving MTAs, but at this time they are merely advisory.


The only way to know for sure is to examine a full trace of all the headers in one of the offending messages.  It will be helpful if you can post that here.  Expurgate IP addresses and domain names as necessary but do so consistently so we can follow the trace from the origination to the destination.

Did you use -all instead of ~all?

Post the full Gmail message (Use the function "Show Original") here also. It will give you some info too.


Avatar of Robert Granlund

ASKER

Delivered-To: EMAIL ADDRESS HERE.com
Received: by 2002:ac8:d0:0:b0:3a7:fc4b:db7b with SMTP id d16csp27581qtg;
        Thu, 22 Dec 2022 07:40:15 -0800 (PST)
X-Received: by 2002:a17:90b:b03:b0:219:b79d:c2f4 with SMTP id bf3-20020a17090b0b0300b00219b79dc2f4mr6419601pjb.18.1671723615272;
        Thu, 22 Dec 2022 07:40:15 -0800 (PST)
ARC-Seal: i=2; a=rsa-sha256; t=1671723615; cv=pass;
        d=google.com; s=arc-20160816;
        b=XQ7pIyb4eyd6nVOOKF98I0VVNtJ+zcWWllNrm3ixQTPa995U6a1nDvJcWmGn14gyrC
         mmhnQWyWwCnw5neJzq+u3rlSBDzY3IFfDoWeuKsSuPYgur9fem357WwkvXTHkZntGm7M
         s7P5nqiI6ZMXkHNfS2O5as/y2gO0enVa5FzFqlqdYYae0HfQD/PPXhlt/F5E4e/JJ5m/
         bsBb6j6rB+TIdFzZfNfDMfnkaQKrQO3O+ur4YBEY/3PPBvuxbTyGmzwWdFgkMhocrVAT
         KWpiHcoWt/VqzPyjW7UAp+hnTae8t7FPXLekF1hgsWGoWKZaGsQMKgH4yRO9ALiNotO8
         F0Yw==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=references:to:cc:in-reply-to:date:subject:mime-version:message-id
         :from:dkim-signature:delivered-to;
        bh=phpDbWWaPkCB0VM96eEIsPUyV8XPGkAFkRn/xt81CaA=;
        b=igVGqfQZYwkB7VREE9TcJLYGfZj8d8dYQbsFEOTNk3pOhRqaPK8euCAE/rvZUbjdQQ
         n8M5YKhIujsqgwgqiees5ZoXPzAjp63AFCK05Cu/EkCiQhcYjf6nUsIRflIuOW9n6Cse
         N8L2y4fw/XtGG4F1cFIeADM5uxts113WeED4Yzzyz4lJx+SSmNZDWrJbTFbYuiSxLxnF
         eVsTJkjbGGt4/ukSOg5gHJljRsTBcxQqwQzEtb++H8KBczvSBDH1+dCz3wdmGD7XHVf5
         lJjb2P2sLWH8RFtGCH78dIX/FogNx1en0q8Yc3gWyJirc2Mb99VZ1y/d8bcDQK/PCe/h
         Tkow==
ARC-Authentication-Results: i=2; mx.google.com;
       dkim=pass header.i=@icloud.com header.s=1a1hai header.b=s6kWYwlr;
       arc=pass (i=1 spf=pass spfdomain=icloud.com dkim=pass dkdomain=icloud.com dmarc=pass fromdomain=icloud.com);
       spf=pass (google.com: domain of info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com designates 209.85.220.41 as permitted sender) smtp.mailfrom="info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com";
       dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=icloud.com
Return-Path: <info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com>
Received: from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41])
        by mx.google.com with SMTPS id a12-20020a17090abe0c00b00219543c7330sor479272pjs.35.2022.12.22.07.40.15
        for <anne@thegardenersworkshop.com>
        (Google Transport Security);
        Thu, 22 Dec 2022 07:40:15 -0800 (PST)
Received-SPF: pass (google.com: domain of info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41;
Authentication-Results: mx.google.com;
       dkim=pass header.i=@icloud.com header.s=1a1hai header.b=s6kWYwlr;
       arc=pass (i=1 spf=pass spfdomain=icloud.com dkim=pass dkdomain=icloud.com dmarc=pass fromdomain=icloud.com);
       spf=pass (google.com: domain of info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com designates 209.85.220.41 as permitted sender) smtp.mailfrom="info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com";
       dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=icloud.com
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20210112;
        h=references:to:cc:in-reply-to:date:subject:mime-version:message-id
         :from:dkim-signature:delivered-to:x-gm-message-state:from:to:cc
         :subject:date:message-id:reply-to;
        bh=phpDbWWaPkCB0VM96eEIsPUyV8XPGkAFkRn/xt81CaA=;
        b=IflXR7Pl1UJQR9DBL2h0yTsYNw2y2VH4ambv3Au0hrkvrcyB0EYDPhD6xj+b1bdMtm
         8Z/Wjj/tddNmjULQsoASwjeFTJvX3Imhy4dbNYjrqrF9cAw3fCTmuYucSwI46eRHwzjB
         P8JCd8ZMBtFyLmN8Ph8JO+CQzbkEIGPdmfynNr0IG/ZlgyxkdCqg94BvlO7PPaA1sZo7
         V+aelZPbQBAVlZO1cXJH2rRXJC1q5RL1mcWJkaoO3Xd0ppdp3Lzt1e4hvWa14D1HiS8+
         RBi22OI2QeNDUqPD4cwq7mk46c8QuMNYWRkOgArCRG2XoTmn5aVkmI+dOAJqoaSqboWC
         kwVA==
X-Gm-Message-State: AFqh2kqqNBv40oZW7+1ii5cAbXiSnUwPsC8cF+ELyv/AP0gm/I8NIIfo sfapDfsAVwGaeR8ucEXPE9O5nKeDQI2nM8XGwOQa8lRy+Jyz5TjFIpLvLWom2A==
X-Received: by 2002:a17:90a:9b8b:b0:223:f691:14d3 with SMTP id g11-20020a17090a9b8b00b00223f69114d3mr604904pjp.139.1671723614926;
        Thu, 22 Dec 2022 07:40:14 -0800 (PST)
X-Forwarded-To: anne@thegardenersworkshop.com
X-Forwarded-For: info@thegardenersworkshop.com anne@thegardenersworkshop.com
Delivered-To: info@thegardenersworkshop.com
Received: by 2002:a05:6a20:a89c:b0:b2:38ae:e2c with SMTP id ca28csp48399pzb;
        Thu, 22 Dec 2022 07:40:11 -0800 (PST)
X-Google-Smtp-Source: AMrXdXsfW1Ye1QYVNkCf01lFXPHd12R4RvZLSHIx5vlMfJ3hAaL3ABvcgG42rl6qEdn10m/82r/S
X-Received: by 2002:a17:90a:64c7:b0:218:fa99:8347 with SMTP id i7-20020a17090a64c700b00218fa998347mr6542322pjm.37.1671723610764;
        Thu, 22 Dec 2022 07:40:10 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1671723610; cv=none;
        d=google.com; s=arc-20160816;
        b=TEfqepxr1LdBdk24nQCm2pxuPrGU179a0GXgERtmpCo6BLMFUdYP5U5fEoLfyiY1JT
         8SefuOS/G3/oNSI32HnGKfgj/3FGZ0cwDXGAra+kM1Bo+dqd1lioVGGboWVnBgmUgGag
         6rv/l8LAmWUqaPGRJjjFFGk98zUq9qT0y8KRZ5qgap1CaGcpkZ2iKFGUPBsYUEmM8W0R
         40ganX3keeIOWfPNG3sxmbk5eEaWVFlUz4J3/AoBhPtmII4/4H74KxmiiF/aXHJ365ja
         COhviEDsvjQgqpJuKkvt4D85d9Y9NnpKpCoIuivT0MeEyuamw/FKb+0iSuGJooP4azZN
         oGlQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=references:to:cc:in-reply-to:date:subject:mime-version:message-id
         :from:dkim-signature;
        bh=phpDbWWaPkCB0VM96eEIsPUyV8XPGkAFkRn/xt81CaA=;
        b=oOj+JHqevoVqsoTrOg9Udx6TeibqfdgwNskHsxCCIBZhFwK3iKKJTL/y96jk7wRIaE
         5Zijw0ujGDnbabQTMyeZ9u3WNDxJBJX6axlW5kKbaGfunud11iHC21UD9fVhQa8sJf7G
         0UxI89wDmALc+TFw1TJ9QzKUG/5cNpYGaZrNCJWVKVW51p4UR6goh5SAbi8L5LxzITfy
         iNaowJlpYyTmlUqXleR7NCtvC30lW5EU3YixYdfhLYBTo8jdfUpO1eDc3Si7VFcEOlxA
         koWAUjmhTHdNtKpumRQkyd3XnpYMU5SXSVSh9aVrb1CaGQqGg4V8iiID+PsG4Svky8Y6
         1pdA==
ARC-Authentication-Results: i=1; mx.google.com;
       dkim=pass header.i=@icloud.com header.s=1a1hai header.b=s6kWYwlr;
       spf=pass (google.com: domain of kaymer27@icloud.com designates 17.58.6.52 as permitted sender) smtp.mailfrom=kaymer27@icloud.com;
       dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=icloud.com
Return-Path: <kaymer27@icloud.com>
Received: from pv50p00im-tydg10011801.me.com (pv50p00im-tydg10011801.me.com. [17.58.6.52])
        by mx.google.com with ESMTPS id nv8-20020a17090b1b4800b002215386c989si1086492pjb.14.2022.12.22.07.40.10
        for <info@thegardenersworkshop.com>
        (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
        Thu, 22 Dec 2022 07:40:10 -0800 (PST)
Received-SPF: pass (google.com: domain of kaymer27@icloud.com designates 17.58.6.52 as permitted sender) client-ip=17.58.6.52;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icloud.com; s=1a1hai; t=1671723610; bh=phpDbWWaPkCB0VM96eEIsPUyV8XPGkAFkRn/xt81CaA=; h=From:Message-Id:Content-Type:Mime-Version:Subject:Date:To; b=s6kWYwlr5YEKFJP/Zrdj05XCBaW6JWv4sr/t/L6YK858UqLdlEp7ghRlbjiKaTxDO
       NGFWs3OLb0Uh2hI+nNlMebQnK3nKA2R9BfbXQ8erHPiaimfpDepMQ0tC5FaSC+/NuX
       J8iBU4UKOUnz1AEjK8xDtgKaD41RS5X7upY/YPwHefAgGH28gvRjqiOCNhM4G9DWZY
       jF4TpbYkm10+pqn/b2WJ4C6muKPi0U0/v1XktK9hJbX2Q9eJArlrWGhkjZfdfzWSDm
       5GXX+AmrRwSTfR8Ot3+wAQD+cnwchNpUsRHli39jxA/WvOqoO3jCkUANG8Xx2jTtwp
       RQrAOFWI7pDZg==
Received: from smtpclient.apple (pv50p00im-dlb-asmtp-mailmevip.me.com [17.56.9.10]) by pv50p00im-tydg10011801.me.com (Postfix) with ESMTPSA id 03C2C800F62; Thu, 22 Dec 2022 15:40:08 +0000 (UTC)
From: "Kathi D." <kaymer27@icloud.com>
Message-Id: <A3DB3C7E-573C-4C69-84E2-FBEF5559806C@icloud.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_94BEDD3A-4A4F-4466-B9A0-B242C4F76B11"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.120.41.1.1\))
Subject: Re: 2nd attempt for Kaymer SPAM SPAM SPAM
Date: Thu, 22 Dec 2022 07:40:07 -0800
In-Reply-To: <42ef155d71b475ec1a57de4b4.a51c054025.20221208160423.03ccac889f.b330fbc8@mail66.wdc01.mcdlv.net>
Cc: linda lim <60790@gmail.com>
To: Ace <info@thegardenersworkshop.com>
References: <42ef155d71b475ec1a57de4b4.a51c054025.20221208160423.03ccac889f.b330fbc8@mail66.wdc01.mcdlv.net>
X-Mailer: Apple Mail (2.3696.120.41.1.1)
X-Proofpoint-GUID: wqN3WwjPZ_7KbXr2oUHNj_F3n_pOQeUX
X-Proofpoint-ORIG-GUID: wqN3WwjPZ_7KbXr2oUHNj_F3n_pOQeUX
X-Proofpoint-Virus-Version: vendor=fsecure engine=1.1.170-22c6f66c430a71ce266a39bfe25bc2903e8d5c8f:6.0.138,18.0.572,17.11.64.514.0000000 definitions=2020-02-14_11:2020-02-14_02,2020-02-14_11,2022-02-23_01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 bulkscore=0 malwarescore=0 adultscore=0 mlxscore=0 phishscore=0 clxscore=1011 mlxlogscore=955 suspectscore=0 spamscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2209130000 definitions=main-2212220135

--Apple-Mail=_94BEDD3A-4A4F-4466-B9A0-B242C4F76B11
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset=us-ascii

Oh, this is a good one- the guys will love this!  Ha ha ha ha

> On Dec 22, 2022, at 4:33 AM, Ace <info@thegardenersworkshop.com> wrote:
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>  <http://sandbox.meinpaket.de/5crIlEOYQmu.dbm?fN0343ccTK9jcxPRJcycWQcGc76=
0ch1WDcbbb4H>
>=20
>  <http://sandbox.meinpaket.de/5crIlEOYQmu.dbm?fN0343ccTK9jcxPRJcycWQcGc76=
0ch1WDcbbb4H>
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20


--Apple-Mail=_94BEDD3A-4A4F-4466-B9A0-B242C4F76B11
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; charset=
=3Dus-ascii"></head><body style=3D"word-wrap: break-word; -webkit-nbsp-mode=
: space; line-break: after-white-space;" class=3D"">Oh, this is a good one-=
 the guys will love this! &nbsp;Ha ha ha ha<br class=3D""><div><br class=3D=
""><blockquote type=3D"cite" class=3D""><div class=3D"">On Dec 22, 2022, at=
 4:33 AM, Ace &lt;<a href=3D"mailto:info@thegardenersworkshop.com" class=3D=
"">info@thegardenersworkshop.com</a>&gt; wrote:</div><br class=3D"Apple-int=
erchange-newline"><div class=3D""><table border=3D"0" cellpadding=3D"0" cel=
lspacing=3D"0" width=3D"100%" style=3D"caret-color: rgb(0, 0, 0); font-fami=
ly: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: norm=
al; font-weight: 400; letter-spacing: normal; text-align: start; text-inden=
t: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webk=
it-text-stroke-width: 0px; background-color: rgb(255, 255, 255); text-decor=
ation: none; border-collapse: collapse;" class=3D""><tbody class=3D""><tr c=
lass=3D""><td colspan=3D"3" height=3D"1" style=3D"line-height: 1px;" class=
=3D""><br class=3D""></td><td class=3D""><table border=3D"0" cellpadding=3D=
"0" cellspacing=3D"0" width=3D"100%" style=3D"border-collapse: collapse;" c=
lass=3D""><tbody class=3D""><tr class=3D""><td colspan=3D"4" height=3D"9" s=
tyle=3D"line-height: 9px;" class=3D""><br class=3D""></td></tr><tr class=3D=
""><td align=3D"left" class=3D""><br class=3D""></td><td width=3D"15" style=
=3D"display: block; width: 15px;" class=3D""><br class=3D""></td></tr><tr c=
lass=3D""><td width=3D"15" style=3D"display: block; width: 15px;" class=3D"=
"><br class=3D""></td><td class=3D""><table border=3D"0" cellpadding=3D"0" =
cellspacing=3D"0" width=3D"100%" style=3D"border-collapse: collapse;" class=
=3D""><tbody class=3D""><tr class=3D""><td height=3D"28" style=3D"line-heig=
ht: 28px;" class=3D""><br class=3D""></td></tr><tr class=3D""><td class=3D"=
"><table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0" =
class=3D"ib_t" style=3D"border-collapse: collapse;"><tbody class=3D""><tr c=
lass=3D""><td align=3D"center" class=3D""><a href=3D"http://sandbox.meinpak=
et.de/5crIlEOYQmu.dbm?fN0343ccTK9jcxPRJcycWQcGc760ch1WDcbbb4H" style=3D"col=
or: rgb(59, 89, 152); text-decoration: none;" class=3D""><h1 class=3D""><sp=
an style=3D"color: rgb(184, 49, 47);" class=3D""></span></h1></a><h1 class=
=3D""><a href=3D"http://sandbox.meinpaket.de/5crIlEOYQmu.dbm?fN0343ccTK9jcx=
PRJcycWQcGc760ch1WDcbbb4H" style=3D"color: rgb(59, 89, 152); text-decoratio=
n: none;" class=3D""><img src=3D"https://res.cloudinary.com/dkvrw3gud/image=
/upload/v1671712166/Capture321_i6krwj.jpg" class=3D""><div style=3D"backgro=
und-image: url(&quot;https://res.cloudinary.com/dkvrw3gud/image/upload/v167=
1712166/Capture321_i6krwj.jpg&quot;); width: 0px; height: 0px; border: 1px =
solid black; background-repeat: no-repeat no-repeat;" class=3D""><br class=
=3D""></div></a></h1></td></tr></tbody></table></td></tr><tr class=3D""><td=
 height=3D"28" style=3D"line-height: 28px;" class=3D""><br class=3D""></td>=
</tr><tr class=3D""><td class=3D""><br class=3D""></td></tr><tr class=3D"">=
<td height=3D"28" style=3D"line-height: 28px;" class=3D""><br class=3D""></=
td></tr><tr class=3D""><td class=3D""><table align=3D"center" border=3D"0" =
cellpadding=3D"0" cellspacing=3D"0" class=3D"ib_t" style=3D"border-collapse=
: collapse;"><tbody class=3D""><tr class=3D""><td align=3D"center" class=3D=
""><br class=3D""></td></tr></tbody></table></td></tr><tr class=3D""><td he=
ight=3D"28" style=3D"line-height: 28px;" class=3D""><br class=3D""></td></t=
r><tr class=3D""><td class=3D""><br class=3D""></td></tr><tr class=3D""><td=
 height=3D"28" style=3D"line-height: 28px;" class=3D""><br class=3D""></td>=
</tr><tr class=3D""><td class=3D""><br class=3D""></td></tr><tr class=3D"">=
<td height=3D"16" style=3D"line-height: 16px;" class=3D""><br class=3D""></=
td></tr></tbody></table></td><td width=3D"15" style=3D"display: block; widt=
h: 15px;" class=3D""><br class=3D""></td></tr><tr class=3D""><td width=3D"1=
5" style=3D"display: block; width: 15px;" class=3D""><br class=3D""></td><t=
d class=3D""><table align=3D"left" border=3D"0" cellpadding=3D"0" cellspaci=
ng=3D"0" width=3D"100%" style=3D"border-collapse: collapse;" class=3D""><tb=
ody class=3D""><tr style=3D"border-top-width: 1px; border-top-style: solid;=
 border-top-color: rgb(229, 229, 229);" class=3D""><td height=3D"19" style=
=3D"line-height: 19px;" class=3D""></td></tr><tr class=3D""><td style=3D"fo=
nt-family: &quot;Helvetica Neue&quot;, Helvetica, &quot;Lucida Grande&quot;=
, tahoma, verdana, arial, sans-serif; font-size: 11px; color: rgb(170, 170,=
 170); line-height: 16px;" class=3D""><br class=3D""></td><td width=3D"15" =
style=3D"display: block; width: 15px;" class=3D""><br class=3D""></td></tr>=
<tr class=3D""><td width=3D"15" style=3D"display: block; width: 15px;" clas=
s=3D""><br class=3D""></td><td class=3D""><table border=3D"0" cellpadding=
=3D"0" cellspacing=3D"0" width=3D"100%" style=3D"border-collapse: collapse;=
" class=3D""><tbody class=3D""><tr class=3D""><td style=3D"font-family: &qu=
ot;Helvetica Neue&quot;, Helvetica, &quot;Lucida Grande&quot;, tahoma, verd=
ana, arial, sans-serif; font-size: 11px; color: rgb(170, 170, 170); line-he=
ight: 16px;" class=3D""><br class=3D""></td><td width=3D"15" style=3D"displ=
ay: block; width: 15px;" class=3D""><br class=3D""></td></tr><tr class=3D""=
><td colspan=3D"3" height=3D"20" style=3D"line-height: 20px;" class=3D""><b=
r class=3D""></td></tr></tbody></table></td></tr></tbody></table></td></tr>=
</tbody></table></td></tr></tbody></table><img src=3D"http://sandbox.meinpa=
ket.de/5crIlEOYQmu.dbm?fN0343bcTK9jcxPRJcycWQcGc760ch1WDcbbb4H" width=3D"1"=
 height=3D"1" style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; f=
ont-size: 12px; font-style: normal; font-variant-caps: normal; font-weight:=
 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-tra=
nsform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-w=
idth: 0px; background-color: rgb(255, 255, 255); text-decoration: none;" cl=
ass=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight=
: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-tr=
ansform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-=
width: 0px; background-color: rgb(255, 255, 255); text-decoration: none; fl=
oat: none; display: inline !important;" class=3D""></span></div></blockquot=
e></div><br class=3D""></body></html>
--Apple-Mail=_94BEDD3A-4A4F-4466-B9A0-B242C4F76B11--
Received-SPF: pass (google.com: domain of kaymer27@icloud.com designates 17.58.6.52 as permitted sender) client-ip=17.58.6.52;

From the header walkbacks to the source MTA, it appears to me that "kaymer27@icloud.com" has an infected machine.  The SPF checks show the originating MTA as legitimate.

As said above, it's legitimate email, no spoofing involved. If you don't trust it, reset the iCloud account's password (as you said, it belongs to you). After that, add back ONLY ONE device back at a time (probably an iPhone).

Leave it for a week. Nothing happening, add back the Macbook, another week, add back the iMac etc.

If you add back something and the spam starts pouring in again, that last device added, should be nuked and be FULLY re-installed CLEANLY.

Here is another one with the full trail sent to me.

Delivered-To: anne@thegardenersworkshop.com
Received: by 2002:ac8:d0:0:b0:3a7:fc4b:db7b with SMTP id d16csp114595qtg;
        Thu, 22 Dec 2022 10:04:34 -0800 (PST)
X-Google-Smtp-Source: AMrXdXsdQzvrnKAoAUUA1z/R1vyjUKQ9WJBLjX7FXU/XEfuQXXPHe3XIMe9BAshKsB0o+EmunGqC
X-Received: by 2002:a05:6a21:32a1:b0:aa:6efd:1883 with SMTP id yt33-20020a056a2132a100b000aa6efd1883mr10908717pzb.37.1671732274526;
        Thu, 22 Dec 2022 10:04:34 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1671732274; cv=none;
        d=google.com; s=arc-20160816;
        b=M1THm8ErI2JPwrL4ysByNp27h2sNIKKuHNHBmles1zseRPoZprMLQp4SmOsCoFsDdl
         6vqLqCSkW8MKPaignMhfQNQevr/UNHhQTAFm99T2qbEoo567fcGaPS+Zi+xmFW850Jot
         kvwCtwpgNMm5FKSn4a7JVYpKX58WBm+fqE8fyRf4CpfYCeuS9gKoJ11LDxai+QClI1IR
         qrgt6w8rUC0+x6dtjt4JItPKVzaL8XSIZk91mM/g5XjeQkTpMoIQMv50Er0jSyGM9cPI
         qi9Ukm5V0RU2OCi1rEeMSJb1xTU/cCCCPkSrjW5klDT3bnTRrIFyiw4ARujWwMTdW1+J
         T4mw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=to:message-id:subject:date:mime-version:from
         :content-transfer-encoding:dkim-signature;
        bh=28LeFaOHufWj/FOzhQBmKcR6u0VB+z+hK7YHFKd9be4=;
        b=NoTq2fJ7bjnRUam6cwq9jQxoCP7/VbImG81rj3IPFvx6Mhsi6jyAHlQlJo6hBjfo9x
         PjFHvwugRZ3fdz6j+3ix1Z1sOYsBdyGRekrUqt5PfPZQWKMqUUCmUUN/Fda04XzDxqhp
         84Zb9EAPkXZyRQq6XFZoSUzf6Y8NvGfk7cFx7Qx+39XiYBF0mPamYrwaJgYOmQz7WJ+i
         rmm8kT5G5rbMlB38DLkMTt02gAR5Q/hDe9iRZVodEXhqFWRjNQbisJP2AkcxKLxy+To+
         Vy6sLhv1ATLrpnXJneVqFDvKaG7BGDfQsPbDS6GBaHp4ZrZ9c1X6QQqN2mqXaew902d2
         Xqsw==
ARC-Authentication-Results: i=1; mx.google.com;
       dkim=pass header.i=@icloud.com header.s=1a1hai header.b=mZZqnrh1;
       spf=pass (google.com: domain of ivoryace@icloud.com designates 17.57.155.18 as permitted sender) smtp.mailfrom=ivoryace@icloud.com;
       dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=icloud.com
Return-Path: <ivoryace@icloud.com>
Received: from qs51p00im-qukt01080101.me.com (qs51p00im-qukt01080101.me.com. [17.57.155.18])
        by mx.google.com with ESMTPS id i64-20020a638743000000b00477931a9ba7si1386399pge.279.2022.12.22.10.04.34
        for <anne@thegardenersworkshop.com>
        (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
        Thu, 22 Dec 2022 10:04:34 -0800 (PST)
Received-SPF: pass (google.com: domain of ivoryace@icloud.com designates 17.57.155.18 as permitted sender) client-ip=17.57.155.18;
Authentication-Results: mx.google.com;
       dkim=pass header.i=@icloud.com header.s=1a1hai header.b=mZZqnrh1;
       spf=pass (google.com: domain of ivoryace@icloud.com designates 17.57.155.18 as permitted sender) smtp.mailfrom=ivoryace@icloud.com;
       dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=icloud.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icloud.com; s=1a1hai; t=1671732273; bh=28LeFaOHufWj/FOzhQBmKcR6u0VB+z+hK7YHFKd9be4=; h=Content-Type:From:Mime-Version:Date:Subject:Message-Id:To; b=mZZqnrh180y1JQbQcfU30ydTcnKTBqLLgZpSvFauYvmUncqZJSc6+Aam9zeKjWr5s
       puSzP/hmINhuy9vyqfmHW4e65rBdGNAV5duCnZO2fT6QaXfncfIQyAy1XkjGgO/DvG
       b4rfueR8zmyx/NqaEJJOoVMJxKyzZuWeaiX9oHkl5kaJBfwXIJJu0LpHm/CQXNcZni
       ZPwXSMXxIPK48kJmvbvhWPGjBI/BuiE2tcC3fqRwaQjY2Dq4Lk0LZ8bq2ATcOTDbvk
       xT33virZe7L4jNm2JwIwZThxLQr0BAY2NpreQK+cydONZlHPibIkF0cLBqnAl2t8Kd
       xtncIQ/epIlUQ==
Received: from smtpclient.apple (qs51p00im-dlb-asmtp-mailmevip.me.com [17.57.155.28]) by qs51p00im-qukt01080101.me.com (Postfix) with ESMTPSA id 38B0F6180377 for <anne@thegardenersworkshop.com>; Thu, 22 Dec 2022 18:04:33 +0000 (UTC)
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
From: Ivory Mccartney <ivoryace@icloud.com>
Mime-Version: 1.0 (1.0)
Date: Thu, 22 Dec 2022 13:04:22 -0500
Subject: Shoes
Message-Id: <6799BAC3-369B-45DA-83D6-CCADD3D6436F@icloud.com>
To: anne@thegardenersworkshop.com
X-Mailer: iPhone Mail (20B101)
X-Proofpoint-GUID: EmZw7z5Z-4kaiZh-tIMiNWMa-vFv1xpd
X-Proofpoint-ORIG-GUID: EmZw7z5Z-4kaiZh-tIMiNWMa-vFv1xpd
X-Proofpoint-Virus-Version: vendor=fsecure engine=1.1.170-22c6f66c430a71ce266a39bfe25bc2903e8d5c8f:6.0.138,18.0.790,17.11.62.513.0000000 definitions=2022-01-12_02:2020-02-14_02,2022-01-12_02,2021-12-02_01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxscore=0 adultscore=0 clxscore=1011 suspectscore=0 spamscore=0 bulkscore=0 mlxlogscore=560 malwarescore=0 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2209130000 definitions=main-2212220154

I ordered Jordan 4s for my son for Christmas I do have a receipt as well
Sent from my iPhone

Wow so many iCloud accounts hacked? That seems a bit implausible. Are those accounts all used on ONE PC/Laptop/Mac? If so, that device is obviously hacked.

These are emails that customers are reporting back to the company.  They are saying they received these emails from the company.  However, they are a spoofing campaign.  However, most of the emails that report getting these emails all have icloud email addresses.  Is there a way to sort out where it originates?  Maybe one of the recipients can send me the headers?  Thoughts?
SOLUTION
Avatar of Kimputer
Kimputer

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The very end of the trail is the original message.  Here is another:
Received: by 2002:ac8:d0:0:b0:3a7:fc4b:db7b with SMTP id d16csp1382842qtg;
        Sun, 25 Dec 2022 07:07:49 -0800 (PST)
X-Received: by 2002:a05:6a21:6da5:b0:b0:4c16:10a6 with SMTP id wl37-20020a056a216da500b000b04c1610a6mr26502517pzb.0.1671980869429;
        Sun, 25 Dec 2022 07:07:49 -0800 (PST)
ARC-Seal: i=2; a=rsa-sha256; t=1671980869; cv=pass;
        d=google.com; s=arc-20160816;
        b=afRKKRHPLYhD+q8Ji3InqwJBRcREOcC1wKPEbKm5R5RMFVSdj8dYXEEZUEjyAApkxW
         DF8PwiBZLAFNNDmQCBViRlU2x5/U2mVAhVwvHLv9knfdEfpakl8P4TaiHt40XiGCgsrc
         yxab51MGYAh1u/u4qYGIkRANlXgFQV2jKfjVd1/fz/EmHgSsDdZW0uf7gGHS7Bd8Rkg5
         U1W4+DeTG/hUQQyY32V5SlX23bfQB0cxF0viC48EB0vcV2o7r9vd7xWy6vPJ55tZ4Uyp
         7I+ruWToksj57aOneDaiUjGhqlVrYxkSUHHl7n+WhsrvLc+kMA2xZr89tXiE3wHM7Ege
         uY9A==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=to:message-id:subject:date:mime-version:from
         :content-transfer-encoding:dkim-signature:delivered-to;
        bh=xGA+6ggf/0TWwNbdO+K1DRdFnCz+xEdeH7e/u6oixks=;
        b=olXDsYhZDBViaPFRIZ9veq7pbGVqRQV7jciLvuMjq4LAM20u0quMLupTYM6+cdLpJe
         2XM9EMdhjBnQ2SDTtjgDTHNHvRvJLh85tDCjR5/O0DQaAAJkUNGAsE4pLqKB88e9jiNk
         cqdkjHwYjS7X4oJM3qpd49VViLSb6S55ZqjaMxRHYyBEaugYCqbs+HpUWHgrbYfMUJ2i
         7XQs7HdaHDt/4FYZhnx8pYpJkIBv6ukkJ7iSqJfFJU9sds6kVAfG2eJV97chlBqCjlWv
         vZrYoojQ62B2dMY64uagDfHyKhxjbhxIgylw9xoOLTeZwbsK+2D6WrojcHKCJ/hBykW0
         yv5g==
ARC-Authentication-Results: i=2; mx.google.com;
       dkim=pass header.i=@icloud.com header.s=1a1hai header.b=efQBsG+q;
       arc=pass (i=1 spf=pass spfdomain=icloud.com dkim=pass dkdomain=icloud.com dmarc=pass fromdomain=icloud.com);
       spf=pass (google.com: domain of info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com designates 209.85.220.41 as permitted sender) smtp.mailfrom="info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com";
       dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=icloud.com
Return-Path: <info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com>
Received: from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41])
        by mx.google.com with SMTPS id s4-20020a056a00194400b005781e816756sor3214185pfk.46.2022.12.25.07.07.49
        for <anne@thegardenersworkshop.com>
        (Google Transport Security);
        Sun, 25 Dec 2022 07:07:49 -0800 (PST)
Received-SPF: pass (google.com: domain of info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41;
Authentication-Results: mx.google.com;
       dkim=pass header.i=@icloud.com header.s=1a1hai header.b=efQBsG+q;
       arc=pass (i=1 spf=pass spfdomain=icloud.com dkim=pass dkdomain=icloud.com dmarc=pass fromdomain=icloud.com);
       spf=pass (google.com: domain of info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com designates 209.85.220.41 as permitted sender) smtp.mailfrom="info+caf_=anne=thegardenersworkshop.com@thegardenersworkshop.com";
       dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=icloud.com
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20210112;
        h=to:message-id:subject:date:mime-version:from
         :content-transfer-encoding:dkim-signature:delivered-to
         :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
        bh=xGA+6ggf/0TWwNbdO+K1DRdFnCz+xEdeH7e/u6oixks=;
        b=sSLrmQwYtW8JxYYgtUiRr1sPw+vbRcwNOJ9ER7z+oOUJIM1b7/dKx01Zlqp+1z2sP9
         RoBWVIWyr9DY6VHTwUnr70RmxCNT/z+7JB2L2cZwoXs80bmrxFsZq2QUSkj4Jz3yPBbu
         UQuJbE3LYi0UKQ2ug7wLQIwM3ewlBQ0B40aFMawkvbSpz49csdXMmjLuW2SQDI2C82AE
         0UzzG7NYnF4TirMHC8bYDWBLcuOkXFn9zH6IdrDCvLMWpwHqaeYaLQ6pDXwezm6sNeTz
         n618Xs+DWyZGRB+lcXasMc8Lt9nXwTTDe5/G1XQahppEnq/eawHbrdz0vOkPjtTk/y+j
         eyNQ==
X-Gm-Message-State: AFqh2koqwRAK/POnHmqQaAuTr2+UbsojVmFoUtUscooBdEw9kHxJd1TL TXz8+VYivSVY/ubU0sIKEKiPMsR5aAHySs9Vf15ptGwZ46Nt7kp7F9anuuXdIQ==
X-Received: by 2002:a65:4cc9:0:b0:476:c39b:ab5b with SMTP id n9-20020a654cc9000000b00476c39bab5bmr1057002pgt.565.1671980868847;
        Sun, 25 Dec 2022 07:07:48 -0800 (PST)
X-Forwarded-To: anne@thegardenersworkshop.com
X-Forwarded-For: info@thegardenersworkshop.com anne@thegardenersworkshop.com
Delivered-To: info@thegardenersworkshop.com
Received: by 2002:a05:6a20:a89c:b0:b2:38ae:e2c with SMTP id ca28csp1433006pzb;
        Sun, 25 Dec 2022 07:07:47 -0800 (PST)
X-Google-Smtp-Source: AMrXdXu7zhRVWk6yJ7jxxMwns/UUXXXSPke8AfzcVclvHJCBOo6/Ezoi4V76mS5UweE0Pm/O5fMz
X-Received: by 2002:a05:6a00:1c85:b0:569:a028:a1fd with SMTP id y5-20020a056a001c8500b00569a028a1fdmr16674378pfw.34.1671980867023;
        Sun, 25 Dec 2022 07:07:47 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1671980867; cv=none;
        d=google.com; s=arc-20160816;
        b=HTQIPekjTacqWPki+2LrKyCJqad9zfq4K2SAIlJyyBkwU9fZ+eh3HL7wUgDpujVPFY
         Qtc8Tb60J1Ono4/KeVB2hkkgmxXUD8SlhzjinEMN1T6VLF1xAcNWtBjxj3kK0NgGC6Sw
         7r91H/x9NXCCUzI5pQPS7mTnQ42FAK/ZfWndXplI730Sro+eDVJJgttSa2h98wjYIkEA
         zT/MQX21U1nE26NSLjDKoq5nNQxLbiBVhgS+8hCbBcBh/i/M459TDAh6+ePTehpUGGZd
         zYNLjvQMUyxz5HNCG/k9owT3tDPwnuU2vrMZehz2PNfX/ndmFv05ltrHcv9lqZef3At0
         lMrw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=to:message-id:subject:date:mime-version:from
         :content-transfer-encoding:dkim-signature;
        bh=xGA+6ggf/0TWwNbdO+K1DRdFnCz+xEdeH7e/u6oixks=;
        b=mbe9/wD0Fo7N+fG7f42Wr79jSa90Rlgj/9/+ERrwa9FYALyFjz7p6BeZ1iRIhpDOxn
         6ZFloqlXFVV4KNEsaPxgEFht5va21XQ6aWyDeEaQJM7BKbCzx3/2vBBaIiUBjpSj5uIB
         4jX0jE+XmSlhTY8Kqb44Hvn6/YA8d5cUmsMklxe7zA25ui+8dEGfHZBXHNJDZla3GUP5
         rn13qPBpHcUulPPmgRjZABLiSypcGAr0uOX36wDDcIVlX1Zw5YnA2tuzvKadMUGKk0yw
         urmG0mIN7BZssucyWP7nqnA8z7VCUDbVhqblnDCzANrGvEf0uY5P2n/b1n7WIK83vFee
         +NAQ==
ARC-Authentication-Results: i=1; mx.google.com;
       dkim=pass header.i=@icloud.com header.s=1a1hai header.b=efQBsG+q;
       spf=pass (google.com: domain of fisherkaine09@icloud.com designates 17.58.38.44 as permitted sender) smtp.mailfrom=fisherkaine09@icloud.com;
       dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=icloud.com
Return-Path: <fisherkaine09@icloud.com>
Received: from ms11p00im-qufo17291501.me.com (ms11p00im-qufo17291501.me.com. [17.58.38.44])
        by mx.google.com with ESMTPS id c4-20020a056a000ac400b0056ce934bea2si9528945pfl.353.2022.12.25.07.07.46
        for <info@thegardenersworkshop.com>
        (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
        Sun, 25 Dec 2022 07:07:47 -0800 (PST)
Received-SPF: pass (google.com: domain of fisherkaine09@icloud.com designates 17.58.38.44 as permitted sender) client-ip=17.58.38.44;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icloud.com; s=1a1hai; t=1671980866; bh=xGA+6ggf/0TWwNbdO+K1DRdFnCz+xEdeH7e/u6oixks=; h=Content-Type:From:Mime-Version:Date:Subject:Message-Id:To; b=efQBsG+qvOz49C6WuP7W85Ab5tlutOmIFIIYZjaeP+AUt1w1tKzixwzFLl3po3ocY
       NT6oHIeAtNoaw5wdjAtYVftgLJqeXb5c3eEvWXvgnnZUjf7AUzYNLOPPQ9OsoWJRcY
       QYvVlDh1U8lb4xB9dEEutaZ4eYKE7faIj1LC1c0aARqvrE7jn7ZjtfBAe6PrKJrxwR
       2wX+V/zuzMi++XnsXb2wFRPzvkYjNosPqFezjlOPNDQ+un9mo1LHloG9ezJTxrCqaD
       1uAyGaRA7bswgfphzl3FvHRCVLBxgzWxIyrXUUHli4kkvgbB9E1dG0EF+7FMV6RxjG
       xbPZAitv4/r+A==
Received: from smtpclient.apple (ms11p00im-dlb-asmtpmailmevip.me.com [17.57.154.19]) by ms11p00im-qufo17291501.me.com (Postfix) with ESMTPSA id C3D75A604F2 for <info@thegardenersworkshop.com>; Sun, 25 Dec 2022 15:07:45 +0000 (UTC)
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
From: Kaine Fisher <fisherkaine09@icloud.com>
Mime-Version: 1.0 (1.0)
Date: Sun, 25 Dec 2022 15:07:33 +0000
Subject: package
Message-Id: <D6747EA7-3C02-4F7D-AD4F-7F3D2EA869D3@icloud.com>
To: info@thegardenersworkshop.com
X-Mailer: iPhone Mail (20B110)
X-Proofpoint-GUID: EkM7y9r4Tmszw6ZxhgeQ1ImVYr7rBBD9
X-Proofpoint-ORIG-GUID: EkM7y9r4Tmszw6ZxhgeQ1ImVYr7rBBD9
X-Proofpoint-Virus-Version: vendor=fsecure engine=1.1.170-22c6f66c430a71ce266a39bfe25bc2903e8d5c8f:6.0.138,18.0.572,17.0.605.474.0000000 definitions=2020-02-14_11:2020-02-14_02,2020-02-14_11,2020-01-23_02 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=0 malwarescore=0 phishscore=0 adultscore=0 mlxscore=0 clxscore=1011 bulkscore=0 mlxlogscore=311 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2209130000 definitions=main-2212250133



Kaine=20
Sent from my iPhone

are you serious right now bro=F0=9F=98=92=F0=9F=98=92
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial