Unconfigured Ad Widget

Collapse

Hacked email server?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • RHT447
    Member
    • Oct 2005
    • 239

    Hacked email server?

    Desktop PC running Win7 Pro.
    Internet provider Att.
    Mail server Yahoo! mail.
    Email Thunderbird.
    Anti-virus Malwarebytes Premium

    I can log in and receive email just fine. However just recently, when I try to send I get this error message---

    "An error occurred while sending mail. The mail server responded: 5.7.1 We were unable to deliver your message. Please try resending your message by adding some text. Please check the message and try again."

    The message then shows up in Thunderbird's sent folder.

    I haven't found any evidence of suspicious activity on this PC, but I am just a long time home user. I talked to ATT phone support, and they said a spam filter on the server is blocking the account, that I should change my password, and that the filter should clear in "24 to 48 hours".

    what else should I be looking for?
  • #2
    Robotron2k84
    Senior Member
    • Sep 2017
    • 2013

    Oaths terms of service recently changed. You may need to log into their web mail and agree or not to their new policy before resuming service.

    I'm not saying this is what is happening, but it's a new wrinkle to their service.

    Comment

    • #3
      bigmike82
      Bit Pusher
      CGN Contributor
      • Jan 2008
      • 3876

      Have you seen this?

      The AT&T community forum has been sunset, we have compiled the list of new resources that you can use to find answers to any AT&T related question.


      Log into your webmail in Yahoo, and change your password immediately.

      Then see if you find any sent messages in your sent items or in your deleted items (see if you have like an undelete option) that you didn't send. It's possible that someone got your creds and used you as a spam vehicle.

      Also, punch in your email address here:

      Have I Been Pwned allows you to check whether your email address has been exposed in a data breach.


      That will tell you what breaches it's been a part of.
      -- 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0

      Comment

      • #4
        nine mil thrill
        Senior Member
        • Sep 2010
        • 1022

        if you were trying to send some pics without any text in the subject line or in the text body, this will happen.(hint....is does suggest you add some text to the message you are trying to send)
        sigpic

        Comment

        • #5
          RHT447
          Member
          • Oct 2005
          • 239

          Originally posted by Robotron2k84
          Oaths terms of service recently changed. You may need to log into their web mail and agree or not to their new policy before resuming service.

          I'm not saying this is what is happening, but it's a new wrinkle to their service.
          Yeah, I thought of that, but I just let the clock run out and agreed by default.

          Comment

          • #6
            RHT447
            Member
            • Oct 2005
            • 239

            Originally posted by bigmike82
            Have you seen this?

            The AT&T community forum has been sunset, we have compiled the list of new resources that you can use to find answers to any AT&T related question.


            Log into your webmail in Yahoo, and change your password immediately.

            Then see if you find any sent messages in your sent items or in your deleted items (see if you have like an undelete option) that you didn't send. It's possible that someone got your creds and used you as a spam vehicle.

            Also, punch in your email address here:

            Have I Been Pwned allows you to check whether your email address has been exposed in a data breach.


            That will tell you what breaches it's been a part of.
            Yup, saw the ATT forum. I send maybe three single emails a week. Volume issue wasn't from me. I agree that someone was using me as a spam vehicle, but they covered their tracks well.

            Pwned? I've had the same email for two decades. Take a number and get in line. I'm surprised I got this far without any issues.

            Comment

            • #7
              RHT447
              Member
              • Oct 2005
              • 239

              Originally posted by nine mil thrill
              if you were trying to send some pics without any text in the subject line or in the text body, this will happen.(hint....is does suggest you add some text to the message you are trying to send)
              Nope, no attachments or links, just text. As I noted above, someone else was the spam source.

              Comment

              • #8
                RHT447
                Member
                • Oct 2005
                • 239

                Thanks to all for your helpful comments.

                The other issue was that my Amazon account was hacked as well. I think they were trying to get a free ride on my Prime account. It was partly my fault. I forgot to set up two part verification so, duh, "Hi, I forgot my password" and they're in. Then THEY set up the two part and locked me out.

                Here's the new (to me) trick. They used the filter tool in my email server to filter any email from Amazon to the archive folder. I was starting to wonder if Amazon just blew me off until I started digging around on the server.

                Anyway, all is now back up and running with two part verification manned and ready. Again, thanks to all.

                Comment

                • #9
                  bigmike82
                  Bit Pusher
                  CGN Contributor
                  • Jan 2008
                  • 3876

                  "Here's the new (to me) trick. They used the filter tool in my email server to filter any email from Amazon to the archive folder. I was starting to wonder if Amazon just blew me off until I started digging around on the server."

                  That's a common technique. I've had users where the bad guys are smart enough to create a rule to delete/delete from backup emails that came in as a response to their campaign, in order to delay as much as possible the victim noticing a problem.
                  -- 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0

                  Comment

                  Working...
                  UA-8071174-1