Showing posts with label email spam. Show all posts
Showing posts with label email spam. Show all posts

May 20, 2014

Email SPAM - How To Beat the Spam Gremlins

Spam Gremlins, the evil creatures that generate Email Spam, are something we're told we just need to live with and deal with - like Fire Ants in the Southern USA or cockroaches in the North.  

Whiles this seems true for most people, there are many tactics and software that can considerably reduce the amount of junk emails arriving in your inbox.  Some spam is just an aggravation and a waste of time but other spam can arrive carrying danagerous computer viruses that can destroy data and cost tens of thousands of dollars in damage.


The Website Hosting Packages offered by Cole WebMarketing offers state of the art spam filtering.   Usually during the initial set up, filters are enabled and configured to filter some, more, or as much as possible, using a simple "slider" that goes from 1 to 10. Setting the global spam filter, called Spamdyke, at 6-7 seems to be the norm for most of our business clients.  Graylisting, which provides a secondary layer of protection, can also be activated upon request.

For more details on Spamdyke and Graylisting, please continue reading:

Spamdyke is a spam protection program that filters incoming messages at the SMTP level by blocking connections from mail servers identified as spam sources or that match certain reverse DNS validation rules.  

The Spamdyke program is enabled by default. We can enable or disable Spamdyke and configure its options for you from our online Control Panel's Mail Manager section. Spamdyke can be configured only globally for the hosting account; it cannot be managed per mailbox.

Spamdyke uses several methods to determine whether a sending server can be identified as a spam source:

1. Reverse DNS check
If there is no valid reverse DNS name of the sending mail server, the message will be blocked and returned to the sender with the following error:
554 Refused. You have no reverse DNS entry. Contact us for details.

NOTE: If you are trying to send through the SMTP server of your hosting account and you receive the above message, please change the port of the outgoing server from 25 to 587.

If you are not a customer of Cole WebMarketing services and you receive the above error when sending to a server maintained by us:
If you receive a bounced message with the error "You have no reverse DNS entry", then the SMTP server you use does not have a reverse DNS name. You need to contact the administrator of your mail server to have the DNS entry fixed, or you need to use another SMTP(outgoing) mail server.

2
. Graylisting/Greylisting (optional)

Spamdyke can also be configured to use Graylisting. Graylisting is the technique of denying mail delivery the first time a sender tries to deliver to a recipient. The next time the remote server attempts to deliver the message, it is accepted. All future messages from the sender to the recipient are also allowed. 

With Graylisting enabled, our mail server will "temporarily reject" any email from a sender it does not recognize. The originating server will try a new delivery, usually in a few minutes, and if the mail is legitimate, it will be accepted.

If the mail is from a spammer it will probably not be retried, as spammers go through thousands of email addresses and cannot afford the time delay to retry a particular message. Standard mail servers, however, always attempt to deliver messages again if they are rejected with such a “temporary” error message, in accordance with the SMTP RFC specifications.

Graylisting is not enabled by default, you need to simply request us to enable it for you.

Note: Filtered Messages and Junk folder
Please note that messages filtered by the Spamdyke program are blocked at the SMTP level. Therefore, in case you have Spamdyke enabled, the messages blocked by it will not be delivered to your Junk Mail folder.

Note
: Filtered Messages and White lists (Spam Assassin)
Please note that the white/black lists do not affect the Spamdyke program. In other words, if you have a certain sender email address whitelisted, messages coming from this sender will still be processed by the Spamdyke program and might be blocked.

==================================================

Cole WebMarketing is a Charlotte, NC based internet marketing services provider specializing in B2B (business to business) companies.   Primary Services include: website domain registration, website hosting, business email, website design, site redesign, website maintenance, webmarketing consulting, website photography and videography (plus pro video production for website or other online marketing). 

For more information, please visit www.ColeWebMarketing.com and then call 704-456-WEB1 (9321) to get a free quote on our services that you need to ''make your website make you more money''.




Dec 29, 2012

Beware! Recent Increase in Email Scam > "Your Mailbox Full"

Our offices have recently received a number of fake e-mails that are variations on the subject of ''e-mail account mailbox capacity''. Most of these e-mails are in the form of a warning or alert to say that ''your e-mail account has exceeded its capacity".

EXAMPLE: Dear customer: 
Your
 e-mail account has exceeded its limit Please verify your account to avoid losing 
it by "CLICKING HERE" (link in body of email). 

above is screenshot capture of the actual email

It's pretty safe to assume that if we are receiving these e-mails, millions of other people are getting them too. We believe these emails are no doubt what's called a "*phishing scam". 

Charlotte, North Carolina based Cole WebMarketing, which hosts hundreds of websites, and thousands of e-mail accounts, has always advised our clients, that whenever they receive an e-mail that even remotely appears suspicious, to NEVER click on any link that is contained in the e-mail message. 

If, for example, you receive an e-mail that says it's from PayPal, eBay, your bank, your cell phone carrier, etc., and the e-mail warns you of a potentially serious problem and that you need to take immediate action... by clicking on the link provided an e-mail, don't do it! 

Instead, go to your browser address window, type in the URL for the website referenced in the e-mail, such as www.PayPal.com, and then log into your account and check to see if there is some type of authentic problem. To be certain that there is in fact nothing to be concerned about, you can always take a second precautionary step of contacting the company the via e-mail or telephone to inquire about the warning you received in the presumably fake e-mail. They will be able to confirm whether or not the e-mailed alert or warning is genuine.

WHEN IN DOUBT, CHECK IT OUT! @ Snopes.com
The website www.Snopes.com is a great resource for checking to see if emails you get are real, fake or partially true or false.  The site has a SEARCH BOX on the home page.  Usually typing in, or copying & pasting, the subject line of the email you received, or part of the body of the email, will bring up details about the email - is it a scam? does it contain a link to a computer virus? is it true, or false or taken out of context, etc.  Snopes.com is also effective to ascertain whether an email "alert or warning" that someone forwarded to you is a false rumor or something true, and something you should know and be concerned about.

__________________________

*Phishing scams, according to Wikipedia, are:  
Phishing is the act of attempting to acquire information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public. Phishing emails may contain links to websites that are infected with malware. 

Phishing often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. 

It is believed that the first recorded use of the term "phishing" was made in 1995. The term is a variant of fishing,  alludes to "baits" used in hopes that the potential victim will "bite" by clicking a malicious link or opening a malicious attachment, in which case their financial information and passwords may then be stolen.


Oct 5, 2011

The REAL Truth About ''Search Engine Registration/Domain Submission Services''

If you have Registered a Domain, you've probably received a few (or many!) emails that start off or contain "doomsday warnings" such as "Registration Expiration Notice: ...inform you that it's time to _________ and failure to act may result in the cancellation of ________ making it difficult for your customers to locate you...on the web". 
Our 1st response is usually fear/concern - Legit? Spam? Scam? Our 2nd response should be suspicion - "money for nothing?"


IMPORTANT: Don't Miss the "Three Things You Should Know About Search Engines"
at the bottom of this Blog Post.

Recently a Cole WebMarketing client, based in Charlotte, NC forwarded an email to me asking for review and feedback.  The email came from @sellstones.com (Beijing, China registered domain), and was asking for $75 per year for "search engine registration/domain submission" services. It's a good practice to NEVER click on any link in any email you suspect might be spam or a scam, so I didn't click on the link. Most scams contain "fine print" and if the online order process is completed, the buyer (victim) often unknowingly agrees (in writing) to terms & conditions... that are almost always a good idea for the bad guy (seller) and a bad idea for the good guy (buyer).

Here's a screenshot of the actual email:


Three Things You Should Know About Search Engines:
  1. Search Engine Registration/Domain Submission: although this type of service will often speed up the process of getting a brand new website ''into the system'', it is NOT required in order for inclusion into search engines.  Although Domain Registrations need to be renewed annually (or every 2,5, or 10 years), Search Engine "Registrations" for major search engines don't actually exist; therefore they can never expire!   
  2. Search Engine Registration/Domain Submission: Search Engine Registration/Domain Submission is included at no extra charge (FREE) with all Cole WebMarketing website packages. As soon as a new website by Cole WebMarketing is "launched" (HTML Meta Tags revised to request/allow search engines to crawl/index pages), we submit your domain to the major search engines. Once your site is crawled and indexed by the "BIG 3" (Google, Yahoo, & Bing), dozens, then hundreds, then thousands of "minor" search engines will soon find your new website.
  3. Overview on How Websites "Get Into" the SERPs (Search Engine Results Pages): GoogleBot, Slurp, and the other major search engine "spider robots" will  eventually find ALL public (and some private!) websites on the web, all on their own. Once they do, they'll check to see if the domain/website is listed in their "index" (files). If not, they'll usually schedule an "in-depth crawl" (visit each page of a website). Once crawled, they can "file" your pages in their index. Once filed, when a person searches for a company or particular product/service or keyword phrase, the search engine will serve up in the SERPs, what it thinks are the most relevant pages/websites based on the user query. With sophisticated automated search engines, such as Google; the more specific the query, the better the (search engine) results.
To learn more about our Search Engine, SEO (Search Engine Optimization), Website Design/Development, WebMarketing and related services, visit ColeWebMarketing.com and then call 704-503-7069 for a free consultation and quote.

Jul 29, 2011

Own a Domain? Watch out for Domain Registry of America!

new blog post coming soon. 


I'll be specifically warning people to watch out for anything coming in the mail (snail or email) from Domain Registry of America (aka Domain Renewal Group). Their mailings can easily trick unsuspecting domain owners into transferring their domain over to the control of DRA. Once transferred, it's not easy for the owners to regain control and hefty penalties can add up quickly and can cost the owner hundreds of dollars to rescue their domain, held "hostage" by DRA.


Domain slamming (also known as unauthorized transfers or domain name registration scams) is a scam in which the offending domain name registrar attempts to trick domain owners into switching from their existing registrar to theirs, under the pretense that the customer is simply renewing their subscription to their current registrar. The term derives from telephone slamming.




Domain Slamming has been going on for years, but one particular company (DRA) continues to stand out.  DRA was sued by a major (legitimate) domain name registrar, claiming the company illegally lured away thousands of customers by tricking them into transferring their domains.


I just Googled - domain registry of america - and Google's drop down "popular/related search suggestions" included the words scam, refund and complaints added onto their name.  THAT alone should make you suspicious!

In 2009, the Advertising Standards Authority issued an Adjudication on Domain Registry of America.  The ASA noted the mailing was headed "Domain Name Expiration Notice" and closely resembled a bill, including a credit card payment slip, and considered recipients were likely to infer that their domain name had been transferred to DRG and a renewal payment was now required.  


to be continued...