Inconsistent sender and Tricky address Tommy
    Inconsistent sender and Tricky address Tommy
        Inconsistent sender and Tricky address Synametrics Support
            Inconsistent sender and Tricky address Tommy

From: Tommy
Date: 2/20/24 9:53 AM
Topic: Inconsistent sender and Tricky address
Type: General Discussions
Post a follow up

For below email,why it was detected as Inconsistent sender and Tricky address?

You can input below header info at Spam Simulator and check the result.

 

X-LCID: 8832
Received: from [(185.132.183.105)] by myserver with Xeams SMTP; Tue, 20 Feb 2024 16:49:50 +0800 (CST)
X-SM_EnvelopeFrom: someone@bos.de
X-SM_SENDER_IP: 185.132.183.105
X-SM_ReverseDNS: mx07-00875c01.pphosted.com
X-SM_HeloStrInEnvelope: EHLO mx07-00875c01.pphosted.com
X-SMRecipient: someone@mydomain.com
X-SM_RECEIVED_ON: Tue, 20 Feb 2024 16:49:50 +0800 (CST)
Received: from pps.filterd (m0359407.ppops.net [127.0.0.1])
by mx07-00875c01.pphosted.com (8.17.1.24/8.17.1.24) with ESMTP id 41K4eWTM010061
for <someone@mydomain.com>; Tue, 20 Feb 2024 08:49:48 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bos.de; h=from
:to:subject:date:message-id:references:content-type
:mime-version; s=202306-pod; bh=56igXwEXmi1CzhIzp9g31SUMdM3cLXv2
WoMP6pUC+xo=; b=gN/3ww+jy0QJUUCr2NBzOD4gbdlXf4NQ2FrL9aWlw/1q/OiC
gec2c0BSnLqFB1YfiD3glJlwaeYXWcVwnjyXKPfufjDk908KBoid6IMlKWELTvX6
sVDrvlcmjKSP/E8lWIjTIw8hVkikT0eUZXHO5Z5OcbJFfEum9Y2IT2G3Hs25yUkE
74wTuNdystA8c5uT3/XG5ltigu9ubbvX4Ei/GKctJTLJG2wYu42pvGFHVRiRkXtk
6pRT3sRxmP0aCGUjp8TTOsxT039OoFClZ2MEz/Tn3cJ1ey8VsxA5PhJu4nWFSzPb
SkpHbPxV6RBLulxRkLdlfT8Kzb4ivv6TW04+tw==
Received: from schw2k22s4072.intra.bos.de ([213.23.107.138])
by mx07-00875c01.pphosted.com (PPS) with ESMTPS id 3wb7689yrt-1
(version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL)
for <someone@mydomain.com>; Tue, 20 Feb 2024 08:49:47 +0000 (GMT)
Received: from SCHW2K22S4071.intra.bos.de (10.1.4.71) by
SCHW2K22S4072.intra.bos.de (10.1.4.72) with Microsoft SMTP Server
(version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.2.1258.25; Tue, 20 Feb 2024 09:49:47 +0100
Received: from SCHW2K22S4071.intra.bos.de ([10.1.4.71]) by
SCHW2K22S4071.intra.bos.de ([10.1.4.71]) with mapi id 15.02.1258.025; Tue, 20
Feb 2024 09:49:47 +0100
From: =?utf-8?B?VmFyZ8OhbsOpIEvDvHJ0w7ZzaSwgRXRlbGthIChHecWRcmxhZGFtw6lyKQ==?=
<someone@bos.de>
To: "someone@mydomain.com" <someone@mydomain.com>
Subject: FW: shipment on Feb.
Thread-Topic: shipment on Feb.
Thread-Index: AdpjqNpF3b4rqn06SKKjDUq2YZIrJgAIEl1QAADyf9AAAycvkA==
Date: Tue, 20 Feb 2024 08:49:46 +0000
Message-ID: <64117b372bad43f6bdbb06a5bbd6b97e@bos.de>
References: <000001da63a9$d5628f40$8027adc0$@mydomain.com>
Accept-Language: hu-HU, de-DE, en-US
Content-Language: hu-HU
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.1.4.126]
Content-Type: multipart/alternative;
boundary="_000_64117b372bad43f6bdbb06a5bbd6b97ebosde_"
MIME-Version: 1.0
X-Proofpoint-ORIG-GUID: OnfmA55IkSwh2AwEMV_bpdrL_Yh36jYe
X-Proofpoint-GUID: OnfmA55IkSwh2AwEMV_bpdrL_Yh36jYe

--_000_64117b372bad43f6bdbb06a5bbd6b97ebosde_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Top

From: Tommy
Date: 2/21/24 7:25 PM
Topic: Inconsistent sender and Tricky address
Type: General Discussions
Post a follow up

No one follow on this?????

Top

From: Synametrics Support
Date: 2/22/24 11:29 AM
Topic: Inconsistent sender and Tricky address
Type: General Discussions
Post a follow up

Tommy,

The FROM header contains a name, including a comma, but is not enclosed within double quotes. This is a violation of RFC 822. Refer www.ietf.org/rfc/rfc822.txt section 3.3.

Here is an example of an incorrect header:

From: Doe, John <john.doe@example.com>

The correct way to specify this address in the From header is:

From: "Doe, John" <john.doe@example.com>

In short, a special character cannot appear in the email address unless enclosed inside a double quote.

Note that the actual name is encoded in Base64; therefore, you must decode it to see the embedded comma in your example.

 

 

Top

From: Tommy
Date: 2/22/24 11:52 PM
Topic: Inconsistent sender and Tricky address
Type: General Discussions
Post a follow up

For the Inconsistent sender,i think it should compare the email address X-SM_EnvelopeFrom and the From part within the <>

As it is both use someone@bos.de   it is same.

Top