Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Password recovery ends in spam #27

Open
saekort opened this issue Nov 25, 2015 · 4 comments
Open

Password recovery ends in spam #27

saekort opened this issue Nov 25, 2015 · 4 comments
Assignees
Labels

Comments

@saekort
Copy link
Owner

saekort commented Nov 25, 2015

Password recovery mails sometimes still seem to end up in the spam box.

Here is a full message from someone who had this problem in gmail:

Delivered-To: kwinten@gmail.com
Received: by 10.202.189.213 with SMTP id n204csp349667oif;
        Sat, 21 Nov 2015 06:03:49 -0800 (PST)
X-Received: by 10.28.61.4 with SMTP id k4mr8893153wma.34.1448114628985;
        Sat, 21 Nov 2015 06:03:48 -0800 (PST)
Return-Path: <no-reply@campaigncodex.com>
Received: from maglok.colo.transip.net ([2a01:7c8:aab3:1c0:5054:ff:fe77:e718])
        by mx.google.com with ESMTPS id y131si6646977wme.63.2015.11.21.06.03.48
        for <kwinten@gmail.com>
        (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
        Sat, 21 Nov 2015 06:03:48 -0800 (PST)
Received-SPF: pass (google.com: domain of no-reply@campaigncodex.com designates 2a01:7c8:aab3:1c0:5054:ff:fe77:e718 as permitted sender) client-ip=2a01:7c8:aab3:1c0:5054:ff:fe77:e718;
Authentication-Results: mx.google.com;
       spf=pass (google.com: domain of no-reply@campaigncodex.com designates 2a01:7c8:aab3:1c0:5054:ff:fe77:e718 as permitted sender) smtp.mailfrom=no-reply@campaigncodex.com;
       dmarc=pass (p=REJECT dis=NONE) header.from=campaigncodex.com
Received: from maglok.colo.transip.net (localhost [127.0.0.1])
    by maglok.colo.transip.net (8.14.4/8.14.4/Debian-4) with ESMTP id tALE27lI013319
    for <kwinten@gmail.com>; Sat, 21 Nov 2015 15:02:07 +0100
Received: (from www-data@localhost)
    by maglok.colo.transip.net (8.14.4/8.14.4/Submit) id tALE27QY013318;
    Sat, 21 Nov 2015 15:02:07 +0100
X-Authentication-Warning: maglok.colo.transip.net: www-data set sender to no-reply@campaigncodex.com using -f
To: kwinten@gmail.com
Subject: PFS Sessiontracker - Forgotten Password Verification
X-PHP-Originating-Script: 33:Email.php
User-Agent: CodeIgniter
Date: Sat, 21 Nov 2015 15:02:07 +0100
From: "PFS Sessiontracker" <no-reply@campaigncodex.com>
Reply-To: "no-reply@campaigncodex.com" <no-reply@campaigncodex.com>
X-Sender: no-reply@campaigncodex.com
X-Mailer: CodeIgniter
X-Priority: 3 (Normal)
Message-ID: <5650795f78512@campaigncodex.com>
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="B_ALT_5650795f7856f"

This is a multi-part message in MIME format.
Your email application may not support this format.

--B_ALT_5650795f7856f
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Reset Password for kwinten@gmail.com
We got a request to reset your password for the Pathfinder Society
sessiontracker. If that was not you, you can ignore this email. If it was
you, continue by clicking the link to reset your password.
Please click this link to Reset Your Password.


--B_ALT_5650795f7856f
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html>
<body>
    <h1>Reset Password for kwinten@gmail.com</h1>
    <p>We got a request to reset your password for the Pathfinder Society sess=
iontracker. If that was not you, you can ignore this email. If it was you, =
continue by clicking the link to reset your password.</p>
    <p>Please click this link to <a href=3D"http://tracker.campaigncodex.com/#=
/passwordreset?resetcode=3DNrgTQV9tD0QikE6lPESCrudaf26396d03aea7100">Reset =
Your Password</a>.</p>
</body>
</html>

--B_ALT_5650795f7856f--
@saekort saekort added the bug label Nov 25, 2015
@saekort saekort self-assigned this Nov 25, 2015
@NieskeL
Copy link
Collaborator

NieskeL commented Dec 1, 2015

It is even worse for Hotmail. The message does not even reach my spambox.
I tried adding no-reply@campaigncodex.com to my safe-senders list but this does not seem to have any effect.

@saekort
Copy link
Owner Author

saekort commented Dec 3, 2015

It is weird. I really need to see the mail headers to get a idea as to why it would be rejected. I mean I have SPF setup through the domain DNS and even got dmarc up as a extra check for hotmail.

@FlavienKnuchel Do you have any experience with making email servers not bounce mail sent by applications?

@knuch
Copy link
Collaborator

knuch commented Dec 3, 2015

Sadly not at all. Emails aren't my main field, I lack knowledge about all the server-side mail techs

@saekort
Copy link
Owner Author

saekort commented Dec 3, 2015

Shame shame. They are not my main field either. :) I need more data to conclude anything at this point.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants