I can't think of one email I received from sendgrid I would consider legitimate. Anytime I receive an email distributed by sendgrid I have found it actually had no value to me. Sometimes it's from a business I have dealt with but I never wanted or was interested in the content.
Same impression. SendGrid, MailChimp, any of those are just enabling spam at the end of the day.
SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
81–90 of 152 posts
Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#82Earlier quoted context omitted.
This is just for primaries, you register to vote with the state as well.
Still absurd that "free" "democratic" elections are allowed to require party membership, even for the primary.
Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#83Earlier quoted context omitted.
Use @ as your email address when signing up, and check the To header when receiving emails. And/or, long-press or right-click on any link to inspect the linked domain.
What fraction of people do you suppose actually have a to do this with? Even some highly technically inclined people (like myself) can be entirely ignorant of the process. It's not as if consumer ISPs provide the service.
Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#84Is this a new trend in phishing emails? They appear to be using legitimate domains to bypass spam detection. Usually the domains are associated with legitimate companies who are completely oblivious. I always wondered how this works. Is it a broken contact form somewhere?
I suspect that once the sendgrid account is compromised, they then send out these phishing emails, hoping to compromise _other_ sendgrid accounts to look for password overlap and/or keep the flow going.
Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#85> Can this be fixed? For popular senders: sort-of: in your incoming mail server, substring-match the display name of the sender against popular brands, and ensure the actual domain matches. This works remarkably well for proper brands (FedEx et al), but breaks down when the brand name regularly occurs in "normal" names, the sending brand sends mail from all over the place, or "innocuous" impersonation takes place all…
Use @ as your email address when signing up, and check the To header when receiving emails. And/or, long-press or right-click on any link to inspect the linked domain.
user+servicetag@domain.com
And have it go to user@domain.com with the servicetag still in the To: field. At least, I have never encountered a problem with this.
Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#86Earlier quoted context omitted.
Still absurd that "free" "democratic" elections are allowed to require party membership, even for the primary.
How do you envision this working without the "opposing party" poisoning the vote to get a weaker opponent?
Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#87Earlier quoted context omitted.
Still absurd that "free" "democratic" elections are allowed to require party membership, even for the primary.
How do you envision this working without the "opposing party" poisoning the vote to get a weaker opponent?
Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#88Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#89Earlier quoted context omitted.
Use @ as your email address when signing up, and check the To header when receiving emails. And/or, long-press or right-click on any link to inspect the linked domain.
If you don't control your own domain fully, almost all email services let you do: user+servicetag@domain.com And have it go to user@domain.com with the servicetag still in the To: field. At least, I have never encountered a problem with this.
^([^@+]+)\+[^@]*(@.*)$
Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack
#90I can't think of one email I received from sendgrid I would consider legitimate. Anytime I receive an email distributed by sendgrid I have found it actually had no value to me. Sometimes it's from a business I have dealt with but I never wanted or was interested in the content.