大约6天前,我从一个本地注册商购买了一个新的.org域名。
几天后,我收到了一条奇怪的消息( BTW掉到了Gmail垃圾邮件垃圾桶),在我看来像是某种钓鱼。
以下是电子邮件内容(编辑了“取消订阅”链接中的散列和“example.org”的我的域):
Congratulations on your purchase of example.org
You MUST have accurate and updated contact information. Providing false or =
inaccurate contact information=20
can be grounds for the cancellation of your domain name registration as =
required by ICANN (More info below)=2E
You can also protect your brand by registering all related domain =
extensions (ie: .com,.net,.org...) before someone else does=2E
Check your your complimentary domain availability report now just click =
the link below:
http://www.namelock.org/?domain=3Dexample.org (Click on the link or copy & =
paste into your browser)
Key Domain Resources:
- For Domain Registration FAQ's: =
http://newregistrationhelp.com/knowledgebase.php
- For Domain Availability Report: =
http://www.namelock.org/?domain=3Dexample.org (Click on the link or copy & =
paste into your browser)
- For ICann Guidelines: http://www.icann.org/whois/wdrp-registrant-faq.htm
Sincerely,
Sophia Newman=20
Support Team @ NewRegistrationHelp.com
Please do not reply to this email. This email was sent from a =
notification-only address=2E
For customer service inquiries, please visit NewRegistrationHelp.com =
NewRegistrationHelp.com
1, Avenue Marronniers
Saint Ouen, Paris 93400
All rights reserved - Copyright 2013=2E
If you prefer not to receive additional emails please unsubscribe now You =
are receiving this message because you recently made a domain name =
purchase. We hope you find these communications valuable however, if you =
would prefer to no longer receive emails from us, please copy and paste =
the following URL in your browser to unsubscribe: =
http://smtp235.newregistrationhelp.com/u.aspx?some/aZ09hashes这并不是说它会是传统的网络钓鱼,因为它会直接要求诸如“你需要重置密码”之类的证书,但它肯定有一些奇怪的地方:
我想到的第一个解释是,有人有一个.org域列表(可能曾经存在过?)并不断地对DNSes进行投票,找出他们何时注册,然后偷取来自whois的电子邮件。
这是一种已知的/常见的垃圾邮件/钓鱼技术吗?我该照此行事吗?这件“事件”是否有违我登记员的信誉呢?
编辑只是为了以完全的讽刺来完成故事:
在这条消息的旁边,有两条来自合法的“注册员B”的消息,我那天还没有完成注册:一封丢失的激活邮件,以及一份简陋的反馈请求,并表示愿意帮助完成注册。后来,我向他们报告并解释了这一点。
所以我想到,虽然这类垃圾可能不是特别危险,但它似乎相当成功地中毒垃圾邮件过滤器,使诸如“注册”和“域”有效的V字词。
最后,不是我被“刺杀”,而是可怜的另一个“登记员B”被“刺杀”了。
发布于 2013-07-24 13:16:46
习惯这些吧。你会定期拿到的。许多定价过高的注册人到处发送电子邮件,甚至是像这样的蜗牛邮件,试图让网站所有者为他们的服务付费。这些服务通常是合法的,但价格过高,通常是在实际需要之前发送的。
它们是正确的,您必须保持您的WHOIS信息准确和最新,否则您可能会失去您的域名,但这是您必须与您使用的注册员,而不是一些随机的第三方登记员,您没有参与。
如果第三方注册员就您的域名与您联系,只需忽略它。谷歌正确地将其归类为垃圾邮件。
https://security.stackexchange.com/questions/39479
复制相似问题