Ask Leo! #655 – Someone’s Sending from My Email Address! How Do I Stop Them?!

Someone's Sending from My Email Address! How Do I Stop Them?!

(skip)

People are telling me I've sent them email I know I haven't. Supposedly it's spam, and that's not something I do. Has my account been hacked? How do I stop it?

While possible, it's highly unlikely that your account has been hacked. Something significantly more benign is more common. Sadly, it's something you can do almost nothing about.

There are a couple of variations, so before we begin, let me also mention some articles that might more closely match your situation.

Variations

If email is being sent to your contacts without your having done so, and you find messages in your "Sent Mail" folder that you did not send, your email account has most likely been hacked or compromised. See Someone's sending email that looks like it's from me to my contacts, what can I do?

If you're getting email that appears to be "From:" your name or a name you recognize, but showing as "From:" the wrong email address, read this: Why am I getting email from someone with the wrong email address?

Finally, if people you don't know are getting email "From:" you — the most common scenario of all — there's probably nothing wrong. Keep reading.

It's not your fault

You're minding your own business, and one day you get a message from someone you've never heard of, asking you to stop sending them email. Worse, they're angry about it. Or worse yet, they accuse you of trying to send them malware!

But you don't know them, you've never heard of them, and you know you've never sent them email.

Welcome to the world of email malware, where you can get blamed for someone else's infection. And there's worse news to come.

Before I get to that, there is a small possibility your email account has been compromised. The solution there is quite simple: change your password immediately. Assuming you choose a strong password, that should prevent someone from continuing to use your account for malicious purposes. (If you find that your account has indeed been compromised, you may want to do more. Check out Email Hacked? 7 Things You Need to do NOW.)

Account hacks, while they happen, are not the most common cause for the situation that I've described; spammers are.

What's worse? There's almost nothing that you can do.

From forgery

Spammers forge the "From:" address for the email they send. This technique is referred to as "from spoofing".

Spammers use any email address they can find. That could include other email addresses they're sending to, email addresses fed to them by a botnet, email addresses harvested online, or perhaps even the addresses in the address books of infected machines. For instance, your email address can end up in the address books of people you don't know. Some email programs automatically collect email addresses included on messages received, or possibly from forwarded email.

If they can, spammers try to make it look like the email comes from someone you know, often by discovering who your friends are on social media and other sites.

They use all this information to create and send email messages with your name and email address in the "From:" line — email you never sent.

Peter, Paul, and Mary's email

Let's use a concrete example.

Peter's address book includes entries for his friends, Paul and Mary. Paul and Mary have never met, have never exchanged email, and do not know each other; they each just know Peter.

Peter's machine becomes infected with malware of some sort, which collects information from his address book. The virus on Peter's machine sends email with the virus to Paul, looking like it came from Mary. Paul may wonder who the heck this Mary person is and why she's sending him a virus, but she was never involved.

From Mary's perspective, you can see how frustrating it would be to be accused of something you had nothing to do with and have no control over.

Spammers have also been known to use other sources of email addresses, including database breaches, harvesting email addresses from public webpages, of even purchasing lists of email addresses from one another.

All means that the simple "friend of a friend" example I used with Peter, Paul, and Mary is just the tip of the iceberg. It's certainly not the only way your email address could show up on a forged "From" line.

What's important is simply this: one way or another, spam messages lie about who the sender is.

There's nothing you can do

If someone accuses you of sending spam, and you are positive you did not do so, you have very little recourse other than to try to educate them about how viruses work.

Point them at this article if you like. But be clear: your machine is not necessarily infected with malware, nor is your account necessarily compromised. It's some third party — the spammer — making all this happen. (Identifying that third party is difficult, which is why spammers use this technique.)

In other words, there's nothing you can do.

Related Links & Comments: Someone's Sending from My Email Address! How Do I Stop Them?!
https://askleo.com/1887

Next to my desk:
CyberPower Intelligent LCD Series UPS

I use and recommend using a UPS (Uninterruptible Power Supply) in any case where your power has been known to "glitch", or even shut off completely without warning. Both happen here -- rarely -- but often enough to warrant protection. In addition to serving as a surge protector (the opposite case -- where a sudden spike in voltage damages equipment) devices plugged into the "battery" side of my CyberPower will keep running even when main power goes away. How long depends on how much power you use, and how big a UPS you purchased, its generally more than enough time to save your work and cleanly shut down, even automatically, if so desired.

A UPS can avoid equipment damage, and heart-breaking unexpected data loss.

I've had a few over the years, and have settled on the CyberPower models as reliable and cost effective. I even have two, since I have equipment in a couple of places in my home.

Check out the CyberPower UPS.

-Leo

"Hand Picked" Advertisement

What's This Confirmation Request I Got When I Emailed Someone?

I emailed a colleague and within minutes got this email in response that said something like "please visit this link to confirm your identity in order for your mail to be delivered". What's that all about? Is it safe? Could it be spam, or phishing, or something else bad?

Welcome to spam wars. Today's episode: "Revenge of the spammed".

What you're probably seeing is something called challenge/response. It's a popular way for folks to control the amount of spam they get.

A lot of people love it. But a lot of people — people like you and me, who aren't spammers — absolutely hate it.

Continue Reading: What's This Confirmation Request I Got When I Emailed Someone?
https://askleo.com/2369

Can I Really Get Malware by Just Looking at Email?

New malware appears every day, and it seems like hackers constantly get smarter and craftier.

In the past, asking if your machine could become infected with malware by just reading your email would get laughs from the geeks in the crowd. "Of course not!" they would giggle.

Then came Outlook. Not only could opening an email infect your machine, but for a while, you didn't even have to be around to have it happen.

And the geeks stopped giggling.

For a while.

Fortunately, today things are different.

Continue Reading: Can I Really Get Malware by Just Looking at Email?
https://askleo.com/1931

The Ask Leo! Tip of the Day

A feature exclusively available to Ask Leo! Patrons Bronze level & above.

More Ask Leo!

Become a Patron
Books - Business - Glossary
Facebook - YouTube - More..

Leo's Other Projects....

HeroicStories Since 1999, HeroicStories brings diverse, international voices to the world ' reminding us that people are good, that individuals and individual action matter. Stories - new and old - are published twice a week.

Not All News Is Bad - Each day I look for one story in the current news of the day with a positive bent. Just one. And I share it.

leo.notenboom.org - My personal blog. Part writing exercise, part ranting platform, it's where I write about anything and everything and nothing at all.

Help Ask Leo! Just forward this message, in its entirety (but without your unsubscribe link below) to your friends. Or, just point them at https://newsletter.askleo.com for their own FREE subscription!

Newsletter contents Copyright © 2017,
Leo A. Notenboom & Puget Sound Software, LLC.
Ask Leo! is a registered trademark ® of Puget Sound Software, LLC

Posted: June 6, 2017 in: 2017
Shortlink: https://newsletter.askleo.com/7694
« Previous post:
Next post: »

New Here?

Let me suggest my collection of best and most important articles to get you started.

Of course I strongly recommend you search the site -- there's a ton of information just waiting for you.

Finally, if you just can't find what you're looking for, ask me!

Confident Computing

Confident Computing is the weekly newsletter from Ask Leo!. Each week I give you tools, tips, tricks, answers, and solutions to help you navigate today’s complex world of technology and do so in a way that protects your privacy, your time, and your money, and even help you better connect with the people around you.

The Ask Leo! Guide to Staying Safe on the Internet – FREE Edition

Subscribe for FREE today and claim your copy of The Ask Leo! Guide to Staying Safe on the Internet – FREE Edition. Culled from the articles published on Ask Leo! this FREE downloadable PDF will help you identify the most important steps you can take to keep your computer, and yourself, safe as you navigate today’s digital landscape.



My Privacy Pledge

Leo Who?

I'm Leo Notenboom and I've been playing with computers since I took a required programming class in 1976. I spent over 18 years as a software engineer at Microsoft, and after "retiring" in 2001 I started Ask Leo! in 2003 as a place to help you find answers and become more confident using this amazing technology at our fingertips. More about Leo.