Jump to content

Massive spams from Microsoft


Recommended Posts

I see that others have mentioned spam from Microsoft on this forum back in 2022 but no real resolution.  I've been reporting spam to spamcop.net for over 10 years.  I've always thought that it seemed to be helping to reduce my spam.  When I first started I was getting several hundred spams per month and after a few months and for several years I was seeing an average of 50 per month.

However......... Things have changed since early December 2023.  I'm now at over 300 per month and most of them are from <random chars>.onmicrosoft.com.  The IP address of the originating spam is a microsoft IP.  All spams have been reported to spamcop.net and I've been forwarding the spams to:

I received one reply from Microsoft stating to send spams to Cert@Microsoft.com which I have done and added to the list.  As of today, I've sent them 55 notifications of spam.
I have a PowerShell scri_pt that I wrote to compile stats on current spams, ordered by spam reporting email address, and they are at the top of the list.  Here's the first few rows of the report:
spam reporting email addresses and count:

Any suggestions on what to do next?

Edited by spamkiller
Link to comment
Share on other sites

So, I believe in the forums that there are two types of Microsoft spams. One is from the IPv6 issue where Microsoft is using millions of addresses internally, but I believe SpamCop mailhosts only remembers fifteen. The other, is where they are actually coming from microsoft as you have listed. I believe the *.onmicrosoft.com might be their cloud setup. For some reason, I seem to have very little spam the past week for some reason. The only suggestion I have (after you are attempted the reporting to them) is to report as many as you can to feed the blocking list. Edited by gnarlymarley
Link to comment
Share on other sites

@gnarlymarley Thanks for the reply.  I will continue to report all spams to spamcop.

I've searched the internet on the proper method to report spam to Microsoft and almost 100% of hits are an explanation on how to configure your "Microsoft" email app to block or ignore spam!  Really??  Microsoft needs to wake up to the fact that not everyone uses a Microsoft email app.  Also, why should everyone have to configure their email app to block spam originating from Microsoft?  I think that Microsoft should configure their mail host to stop the spam in the first place.


Link to comment
Share on other sites

7 hours ago, spamkiller said:

@gnarlymarley Thanks for the reply.  I will continue to report all spams to spamcop.

I've searched the internet on the proper method to report spam to Microsoft and almost 100% of hits are an explanation on how to configure your "Microsoft" email app to block or ignore spam!  Really??  Microsoft needs to wake up to the fact that not everyone uses a Microsoft email app.  Also, why should everyone have to configure their email app to block spam originating from Microsoft?  I think that Microsoft should configure their mail host to stop the spam in the first place.

"Abuse at microsoft com" will get you a Auto ack telling you where to send spam
I don't believe they know how to deal with spammers free email accounts?
Usually its 
this week?
But they must get millions of abuse reports, most of the clue'y automate by using a web page
This criminal redirection links using Gmail Google cloud are reported here for instance
I send the .eml attachment as a file attachment with it in "chose file" button
But they seem getting bogged down now also?

Edited by petzl
Link to comment
Share on other sites

@petzl Thanks for the info.

I did receive a reply from Microsoft on Jan 4 that I had sent them on Dec 23.  It seemed to be an real reply rather than an auto reply.  This is the 2nd reply that I got from them.  I always put "spam Report # xx" in the subject because when they reply, there is no reference as to which email they are replying to.  They replied to email report # 31 and I'm up to report # 55, so they are really slow or running about 2 weeks behind.

Link to comment
Share on other sites

10 hours ago, spamkiller said:

@petzl Thanks for the info.

I did receive a reply from Microsoft on Jan 4 that I had sent them on Dec 23.  It seemed to be an real reply rather than an auto reply.  This is the 2nd reply that I got from them.  I always put "spam Report # xx" in the subject because when they reply, there is no reference as to which email they are replying to.  They replied to email report # 31 and I'm up to report # 55, so they are really slow or running about 2 weeks behind.

the best way IMO is to charge a small fee US$10 (for life) via Credit card or PayPal for what was once free email accounts, this stops the bots. Twitter is anti-bot, and have hoops and jumps to get through.

Link to comment
Share on other sites

On 1/5/2024 at 12:45 AM, spamkiller said:

However......... Things have changed since early December 2023.  I'm now at over 300 per month and most of them are from <random chars>.onmicrosoft.com.  The IP address of the originating spam is a microsoft IP.  All spams have been reported to spamcop.net and I've been forwarding the spams to:

Previously I was getting microsoft does not accept reports so sent to abuse at hotmail but SP is sending the same reports listed above from the same spammer since the start of year with IP error discarded forgery. Can we see an example of a parsing header?

Link to comment
Share on other sites

Here's the header of the latest Microsoft spam received on Jan 6, 2024
Note: My email and domain have been removed.

Return-Path: <norevenhfd47_BRSuCNjlwKn@AZx2u2kc5.onmicrosoft.com>
Authentication-Results:  perfora.net; dkim=none
Received: from NAM11-DM6-obe.outbound.protection.outlook.com
 ([]) by mx.perfora.net (mxeueus005 []) with ESMTPS
 (Nemesis) id 1MWB7u-1rgHQL1Zve-00Vfv1 for <REMOVED>; Sat,
 06 Jan 2024 04:41:51 +0100
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is smtp.rcpttodomain=REMOVED
 smtp.mailfrom=azx2u2kc5.onmicrosoft.com; dmarc=none action=none
 header.from=azx2u2kc5.onmicrosoft.com; dkim=none (message not signed);
 arc=none (0)
X-MS-Exchange-Authentication-Results: spf=fail (sender IP is
 smtp.mailfrom=AZx2u2kc5.onmicrosoft.com; dkim=none (message not signed)
 header.d=none;dmarc=none action=none header.from=AZx2u2kc5.onmicrosoft.com;
Date: Sat, 06 Jan 2024 04:40:40 +0100
From: YETI Department <norevenhfd47_BRSuCNjlwKn@AZx2u2kc5.onmicrosoft.com>
MIME-Version: 1.0
Content-Type: text/html; charset="UTF-8"
In-Reply-To: <norevenhfd47_BRSuCNjlwKn@AZx2u2kc5.onmicrosoft.com>
Content-Transfer-Encoding: 7bit
Importance: high
Subject: Adventure-Ready: YETI 30 oz Travel Mug for On-the-Go Excellence
X-EOPAttributedMessage: 0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: BN8NAM12FT110:EE_|BL3PR07MB8900:EE_
X-MS-Office365-Filtering-Correlation-Id: 532e6f5b-21fe-45a3-aa98-08dc0e696a8b
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-OriginatorOrg: AZx2u2kc5.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 06 Jan 2024 03:41:49.9473
X-MS-Exchange-CrossTenant-Network-Message-Id: 532e6f5b-21fe-45a3-aa98-08dc0e696a8b
X-MS-Exchange-CrossTenant-Id: b38bbb7a-f829-4fb9-92d4-c9db4665139c
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=b38bbb7a-f829-4fb9-92d4-c9db4665139c;Ip=[];Helo=[mail.beatty.com]
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL3PR07MB8900
Envelope-To: <REMOVED>
X-spam-Flag: YES
UI-InboundReport: junk:10;M01:P0:68neQLHhk2A=;0YLRXB0aKdbu+ZuaJB/FgSb0GK4TM6
X-Antivirus: AVG (VPS 240106-0, 1/5/2024), Inbound message
X-Antivirus-Status: Clean

Link to comment
Share on other sites

11 hours ago, spamkiller said:

uthentication-Results:  perfora.net; dkim=none
Received: from NAM11-DM6-obe.outbound.protection.outlook.com
 ([]) by mx.perfora.net (mxeueus005 []) with ESMTPS
 (Nemesis) id 1MWB7u-1rgHQL1Zve-00Vfv1 for <REMOVED>; Sat,
 06 Jan 2024 04:41:51 +0100
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is smtp.rcpttodomain=REMOVED
 smtp.mailfrom=azx2u2kc5.onmicrosoft.com; dmarc=none action=none
 header.from=azx2u2kc5.onmicrosoft.com; dkim=none (message not signed);
 arc=none (0)
X-MS-Exchange-Authentication-Results: spf=fail (sender IP is
 smtp.mailfrom=AZx2u2kc5.onmicrosoft.com; dkim=none (message not signed)
 header.d=none;dmarc=none action=none header.from=AZx2u2kc5.onmicrosoft.com;
Date: Sat, 06 Jan 2024 04:40:40 +0100
From: YETI Department <norevenhfd47_BRSuCNjlwKn@AZx2u2kc5.onmicrosoft.com>
MIME-Version: 1.0
Content-Type: text/html; charset="UTF-8"
In-Reply-To: <norevenhfd47_BRSuCNjlwKn@AZx2u2kc5.onmicrosoft.com>
Content-Transfer-Encoding: 7bit
Importance: high
Subject: Adventure-Ready: YETI 30 oz Travel Mug for On-the-Go Excellence
X-EOPAttributedMessage: 0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: BN8NAM12FT110:EE_|BL3PR07MB8900:EE_
X-MS-Office365-Filtering-Correlation-Id: 532e6f5b-21fe-45a3-aa98-08dc0e696a8b
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;

That's all we need better to send a track
Microsoft get worse at every turn then call them "upgrades"   abuse[AT]microsoft[DOT]com only one available
which is ignored except for auto ack gleefully telling you to go to some obscure address

Their CERT address is no longer for their phishing DOS attacks!
If they even breathe perhaps need to tell Microsoft for Automatic spam forward as attachment website to sort their DOS attackers out?
Microsoft have forums?
Will faceup to converting to a Google operating system when this gets to slow with Microsoft deliberately bloated "updates" (downgrades)
But won't save the problem with Microsoft spam!


Edited by petzl
Link to comment
Share on other sites

MS has an online reporting form for spam and other problems but it is nested and long winded and that is connected to a question and answer service including a complaint about SC blocklist with a very diplomatic reply from MS. Note we are all customers of MS windows and very exe laptops so should get an appropriate level of service even for free email. Should be in the guiness book of records for world's largest monopoly.

Link to comment
Share on other sites

  • 2 weeks later...

Yes, Since about Mid Dec, I've seen a large uptick in e-mail that is from:  x.x.onmicrosoft.com


In which the e-mail appears to originate from a microsoft exchange server hosted in their "hybrid environments"




All headers have this in common:


X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

and all have headers similar to this:


X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=25d080a6-ef03-4383-b518-f748034a7c66;Ip=[];Helo=[mail.saginawpipe.com]

Where the TenantId (and of course the ip/Helo server vary)   however.. they don't vary a TON... 


Here is my current "HOLD" que for the last few days (that I've captured)


X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bb88edeb-a046-428f-98c7-3007bb21248c;Ip=[];Helo=[mail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=d95b4ed6-8581-423b-8ad8-463ec2ccbee1;Ip=[];Helo=[cnoleuv.onmicrosoft.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=4ce72b09-0a96-4c16-9523-ffbc3bff0b40;Ip=[];Helo=[maimail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=9257821f-9efe-407f-b6d9-94893cf45422;Ip=[];Helo=[mail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=6f231f96-d242-4ad0-add9-fc6d869ee72c;Ip=[];Helo=[mail.saginawpipe.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=6dd7820f-4e03-45ae-afd6-4607d44326d6;Ip=[];Helo=[mail.casagalveston.org]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=6dd7820f-4e03-45ae-afd6-4607d44326d6;Ip=[];Helo=[mail.casagalveston.org]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=618ecb0f-8337-4a0a-9655-b116db11101d;Ip=[];Helo=[mbmail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=8a4c5404-47f2-41b3-9e84-561ac6b54a66;Ip=[];Helo=[mbmail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=a6f74299-23c6-49ad-8c8e-b5918189ce47;Ip=[];Helo=[mail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bdc0a6a4-ed9b-48c8-bced-fa1dafac4046;Ip=[];Helo=[mail.saginawpipe.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=1f91eb0a-349b-4afc-bf08-835f9bc9c21f;Ip=[];Helo=[mzail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=1f91eb0a-349b-4afc-bf08-835f9bc9c21f;Ip=[];Helo=[mzail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=8a4c5404-47f2-41b3-9e84-561ac6b54a66;Ip=[];Helo=[mbmail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=87dae739-1d28-42f9-be38-de488936841c;Ip=[];Helo=[mail.thompson.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=780d7a6b-9777-4d35-beae-3abe0b5b2e60;Ip=[];Helo=[mail.hudson.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=a1809de0-7062-473e-9b6c-6fa779a503d3;Ip=[];Helo=[mail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=dbc593c8-9018-4717-99af-997ea9da84bf;Ip=[];Helo=[mail.hsmo.org]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=a4839f2e-2e84-432f-ba6d-2164d576b41b;Ip=[];Helo=[mail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=c9d27106-63ff-4a36-9184-dc469ce0e417;Ip=[];Helo=[mail.elabgids.nl]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=d356d2d7-9147-47f4-b046-b40bb7473a90;Ip=[];Helo=[mail.javierserna.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=c9d27106-63ff-4a36-9184-dc469ce0e417;Ip=[];Helo=[mail.elabgids.nl]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=c9d27106-63ff-4a36-9184-dc469ce0e417;Ip=[];Helo=[mail.elabgids.nl]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=87dae739-1d28-42f9-be38-de488936841c;Ip=[];Helo=[mail.thompson.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=1f91eb0a-349b-4afc-bf08-835f9bc9c21f;Ip=[];Helo=[mzail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=6cde98f4-6ccb-40a0-8ffc-472c1a876764;Ip=[];Helo=[x2wj8j7.starnow.co.uk]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=a853bf4e-ba9b-42a7-844a-033032491cd3;Ip=[];Helo=[mail.elabgids.nl]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=a00c03a8-98c4-4144-baaf-bcdb230b8608;Ip=[];Helo=[mail.lind.org]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=47a25a35-9f33-45df-aca3-f00c7d1b4697;Ip=[];Helo=[mail.saginawpipe.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=25d080a6-ef03-4383-b518-f748034a7c66;Ip=[];Helo=[mail.saginawpipe.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=45182031-4598-4780-9a07-909a5f424285;Ip=[];Helo=[mail.hudson.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=8ba04ecb-5335-41e0-b97c-6849b1c3911d;Ip=[];Helo=[mail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=49d1a23f-9e64-4a2a-bd0d-63b992c6e9eb;Ip=[];Helo=[x61ojhg.onmicrosoft.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=6dd7820f-4e03-45ae-afd6-4607d44326d6;Ip=[];Helo=[mail.casagalveston.org]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=0b3b98e1-318f-48b5-89b4-107ee8eab24f;Ip=[];Helo=[mail.washingtonpost.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=ff8df580-a9f2-48cd-9593-8b6b4b0b89e3;Ip=[];Helo=[mail.casagalveston.org]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=618ecb0f-8337-4a0a-9655-b116db11101d;Ip=[];Helo=[mbmail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=302147f8-5b04-4773-86f4-b1656e5e1299;Ip=[];Helo=[mail.beatty.com]
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=6d12626b-1004-47e9-b194-7d098193eb54;Ip=[];Helo=[mail.hsmo.org]


All of the above are servers that have sent their e-mail out "via" outlook.com  (you'll see a few repeats here)... I've also put in a TON of items into spamcop and to "report_spam@outlook.com"




I think for the folks at Microsoft are... asleep at the wheel.  (Or trying to fight this battle with their Window ME computers)






Link to comment
Share on other sites

9 hours ago, Mossspamfight101 said:

I think for the folks at Microsoft are... asleep at the wheel.  (Or trying to fight this battle with their Window ME computers)

My email address I use on Usernet was actually scraped by  Microsoft, or more likely from me reporting their spam to them from that  Gmail account
Achieve more with free Microsoft 365 trial
 Now spamming me, no way I used this address to or for Microsoft, IMO it's expensive broken rubbish more-so than it's ever been?
Unsubscribed from that one, went to their site to find they have me on their multiple product list so had to delist them all.


Link to comment
Share on other sites

  • 1 month later...

I'm still getting massive spam from Microsoft.  It will drop down to 1 or 2 per day and then back up to 10 per day.  Since it started in Dec 2023, I've received over 400 spams from a Microsoft email address.  I send every one to spam cop AND to 

I will get about 5 replies per week from CDOC Case Management (Microsoft) stating the same thing.

Based on the information you provided, it appears to have originated from an Office 365 or Exchange Online tenant account.  
To report junk mail from Office 365 tenants, send an email to junk@office365.microsoft.com and include the junk mail as an attachment.  
This link provides further junk mail education 



Microsoft Online Safety 

The name (Leo) is always different.  This may be an autogenerated message from MS before it's sent to the trash.  I have no idea.

It's strange that they always tell me that I should report it to junk@office365.microsoft.com but every report that I send has the list of email address that it's been sent to.  I assume that a real person never reads the email.
As of today (March 3, 2023), I've sent Microsoft 176 reports of spam and it's still coming in.

What can be done to make this stop? 
Is there a legal organization that can help me? 
I don't want to have to spend any money but I'm at wits end on what to do.  I do not want to change my email address.  Why should I have to do that?
I currently have saved 462 spams from Microsoft.  Is there a class action law suite that I can get involved with?  Microsoft is out of control.

Link to comment
Share on other sites

9 hours ago, spamkiller said:

What can be done to make this stop? 

You need to find out the Registrar of URL link in spam 
I use a free Windows APP to find Registrar.
Whois  program SpamCop only sends to WEB IP which is often ignored unless it's criminal
Would also help if you could send a SpamCop track, found at top of submission page BEFORE you submit report.

Link to comment
Share on other sites

On 3/8/2024 at 10:02 AM, petzl said:

You need to find out the Registrar of URL link in spam 
I use a free Windows APP to find Registrar.

What happens if the links host is aceville and reg/cert gname are scammer friendly...PTE LTD?

Cloudflare ns brad and anita are hosting gname but they always reckon they are providing security and network services so not responsible for content and bad behavior...all care and no responsibility.

Edited by ninth
Link to comment
Share on other sites

4 hours ago, ninth said:

What happens if the links host is aceville and reg/cert gname are scammer friendly...PTE LTD?

Cloudflare ns brad and anita are hosting gname but they always reckon they are providing security and network services so not responsible for content and bad behavior...all care and no responsibility.

If they don't have a registrar, then the IP owner needs to react, would help if you showed who the registrar is.
Cloudflare though requires a web report for abuse
Also what type of spam, porn/Phishing/no working unsubscribe  or all three.
Then consider adding the countries CERT email to complaint.

Edited by petzl
Link to comment
Share on other sites

This is a simbox scam link eurula homes registrar is gname. You posted the first.org address before but I forgot it so thanks for that.

Beware do not click on scam links! This post will self destruct in 30 seconds...

Link to comment
Share on other sites

On 3/7/2024 at 5:02 PM, petzl said:

You need to find out the Registrar of URL link in spam 
I use a free Windows APP to find Registrar.
Whois  program SpamCop only sends to WEB IP which is often ignored unless it's criminal
Would also help if you could send a SpamCop track, found at top of submission page BEFORE you submit report.

Thanks for the info.

I ran a lot of them through the Win32whois app and it appears that most all show 
Registrar Abuse Contact Email:  mailto:abusecomplaints@markmonitor.com
So I forward all spam email from <randomstring>.onmicrosoft.com to abusecomplaints@markmonitor.com (along with the current email list) and I report them to spam.com and spam.org.

I've not seen any reduction in spams yet.

Once in a while, perhaps once per week I get a reply from MS stating that the email violated their rules and the account has been eliminated (or something like that).

As of today, I'm up to 500 saved spams from MS and 198 spam reports to MS.  

Am I wasting my time? 
The most annoying thing is that I get around 3 replies per day from MS and they all say "Send it to junk@office365.microsoft.com".  EVERY spam from MS goes to that email address!  Are they so stupid that can't determine that?  Grrrrrrr!


Link to comment
Share on other sites

Posted (edited)

Here's a link to Mark Monitor webhosting site: "https:// www{DOT}markmonitor{DOT}com/abuse-policy/"
They seem legit and even state that you can file a complaint by phone.

This will probably be my next step.



Edited by Lking
Not excited by live links to other sites
Link to comment
Share on other sites

  • 1 month later...

@gnarlymarley - The spam from Microsoft to me has suspiciously dropped to a couple per month. However spam from domains that have namecheap as a registrar have taken over my massive daily spam.  I've logged over 100 different domain names that send me spam and have namecheap as the registrar.  Most (currently 84%) are being sent from a salesforce.com email address.  I add new namecheap domains to my list daily.
The war on spammers seems to never end.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Create New...