Forum notification marked as potential phishing/scam

This subforum contains all the issues which we already resolved.
Post Reply
bNarFProfCrazy
Fast Inserter
Fast Inserter
Posts: 194
Joined: Sat Apr 23, 2016 7:11 am
Contact:

Forum notification marked as potential phishing/scam

Post by bNarFProfCrazy »

Thunderbird marks your forum notifications e-mail as potential scam/phishing.

This is an big red (ugly) warning on every e-mail notification that is send by your forum.
EMailNotification.png
EMailNotification.png (53.29 KiB) Viewed 2592 times
English translation of the warning:
"This message could be a scam."

https://support.mozilla.org/en-US/kb/th ... -detection

Potential cause:
Links where the text doesn't match the server name (for example, the text of the message might say "https://secure.example.com" but the link actually goes to "http://phishing.example.com" instead). Phishers do this to fool you into going to their site. Unfortunately some legitimate mailing lists also do this with redirectors for tracking purposes.
Example:
If you want to view the newest post made since your last visit, click the following link: viewtopic.php?f=93&t=17548&p=152404&e=152404
But the link really points to:
(Data truncated due to unkown data)

A possible solution
I personally don't like being tracked, but I know that this might be necessary for you.
However you could most likely fix the issue if you use some DNS features to hide that you actually call a strange URL.
(I'm not familliar with DNS setup, so I cannot explain how to setup it, but I know it is possible)
You use a domain called tracking.factorio.com and bind its IP to u233XXX.ct.sendgrid.net and
then you can send the emails with links that link to https://tracking.factorio.com/wf/click?upn=... which is far less suspicious.
I don't know whether this is enough to avoid thunderbirds warning though.

Another solution would be that host the tracking on your own page or first link to your own page that redirects to the tracking page.
forums.factorio.com/tracking/....

kovarex
Factorio Staff
Factorio Staff
Posts: 8078
Joined: Wed Feb 06, 2013 12:00 am
Contact:

Re: Forum notification marked as potential phishing/scam

Post by kovarex »

bNarFProfCrazy wrote: Example:
If you want to view the newest post made since your last visit, click the following link: viewtopic.php?f=93&t=17548&p=152404&e=152404
But the link really points to:
(Data truncated due to unkown data)
We are not doing that.

kovarex
Factorio Staff
Factorio Staff
Posts: 8078
Joined: Wed Feb 06, 2013 12:00 am
Contact:

Re: Forum notification marked as potential phishing/scam

Post by kovarex »

kovarex wrote:
bNarFProfCrazy wrote: Example:
If you want to view the newest post made since your last visit, click the following link: viewtopic.php?f=93&t=17548&p=152404&e=152404
But the link really points to:
(Data truncated due to unkown data)
We are not doing that.
Oh, so we are not doing that, but the shitty mail sending service we use is doing that, I will try to solve it.

bNarFProfCrazy
Fast Inserter
Fast Inserter
Posts: 194
Joined: Sat Apr 23, 2016 7:11 am
Contact:

Re: Forum notification marked as potential phishing/scam

Post by bNarFProfCrazy »

Thanks.

bNarFProfCrazy
Fast Inserter
Fast Inserter
Posts: 194
Joined: Sat Apr 23, 2016 7:11 am
Contact:

Re: Forum notification marked as potential phishing/scam

Post by bNarFProfCrazy »

The latest of your forum e-mail notifications was clean and also had a better layout than the others.

Thanks for addressing this issue so fast. :D

User avatar
steinio
Smart Inserter
Smart Inserter
Posts: 2633
Joined: Sat Mar 12, 2016 4:19 pm
Contact:

Re: Forum notification marked as potential phishing/scam

Post by steinio »

As i read this thread... is it possible to deactivate email notification and keep subscription?

Greetings steinio
Image

Transport Belt Repair Man

View unread Posts

daniel34
Global Moderator
Global Moderator
Posts: 2761
Joined: Thu Dec 25, 2014 7:30 am
Contact:

Re: Forum notification marked as potential phishing/scam

Post by daniel34 »

steinio wrote:As i read this thread... is it possible to deactivate email notification and keep subscription?

Greetings steinio
That's what bookmarks are for (ucp.php?i=main&mode=bookmarks), they do the same as subscriptions but they won't send you a notification.
quick links: log file | graphical issues | wiki

Post Reply

Return to “Resolved Problems and Bugs”