nanog mailing list archives
Re: registry for onmicrosoft[dot]com
From: Jay Acuna <mysidia () gmail com>
Date: Sat, 9 Mar 2024 10:26:44 -0600
On Sat, Mar 9, 2024 at 8:11 AM Travis Garrison <tgarrison () netviscom com> wrote:
This would be a company that has registered for an office365 account.
Office 365 company accounts are registered as companyname [dot] onmicrosoft [dot] com.
The "companyname" part is evidently Not reliable. Often the name [dot] onmicrosoft [dot] com is unrelated to Any recognizable business or company name. Companies can generate extra onmicrosoft[dot]com domain names. Possibly an existing tenant for some unrelated company could add nanog[dot]onmicrosoft[dot]com and change it to their default domain, if they wanted. Even if it were; the information could be tampered with on a compromised tenant where the spammers simply change the names after breaching the tenant. Likewise spammers might use robots to Signup for 365 services online, and that there's little verification a requestor's Name and Company name exist beyond the ability to charge whatever stolen payment method was provided by the spammer. Because it behaves like a dynamic domain; with very low friction for scammers to generate new ones quickly. It seems that Refusing all mail from subdomains of that domain by default Other than specific ones you whitelist would be a good policy.
You then add domain aliases if you want to use your own preferred domain name.
Thanks Travis
-- -JH
Current thread:
- registry for onmicrosoft[dot]com Nicholas Warren (Mar 07)
- Re: registry for onmicrosoft[dot]com Mark Foster (Mar 07)
- Re: registry for onmicrosoft[dot]com Dan Sneddon (Mar 08)
- Re: registry for onmicrosoft[dot]com Robert Schoneman via NANOG (Mar 08)
- Re: registry for onmicrosoft[dot]com Sean Donelan (Mar 08)
- RE: registry for onmicrosoft[dot]com Travis Garrison (Mar 08)
- RE: registry for onmicrosoft[dot]com Sean Donelan (Mar 08)
- RE: registry for onmicrosoft[dot]com Jon Lewis (Mar 08)
- Re: registry for onmicrosoft[dot]com Jay Acuna (Mar 09)
- Re: registry for onmicrosoft[dot]com Jeff Leung (List Account) via NANOG (Mar 12)
- Re: registry for onmicrosoft[dot]com Sean Donelan (Mar 12)
- Re: registry for onmicrosoft[dot]com John Levine (Mar 12)
- Re: registry for onmicrosoft[dot]com Sean Donelan (Mar 19)
- Re: registry for onmicrosoft[dot]com John R. Levine (Mar 19)
- Re: registry for onmicrosoft[dot]com Sean Donelan (Mar 19)
- Re: registry for onmicrosoft[dot]com John R. Levine (Mar 19)
- RE: registry for onmicrosoft[dot]com Sean Donelan (Mar 08)
- Re: registry for onmicrosoft[dot]com Mark Foster (Mar 07)