Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

I\'m just learning about DMARC (DKIM/SPF), so I apologize if my question doesn\'

ID: 659358 • Letter: I

Question

I'm just learning about DMARC (DKIM/SPF), so I apologize if my question doesn't make sense.

A few days after I installed a DMARC policy on my server I noticed that the reports from yahoo.com contained thousands of 'validated' sends from my mail server's IP. I also received an email from my VPS host saying that one of the email accounts was compromised. I reset the password on that email account, but a day later I received another report from yahoo.com still showing a thousand valid emails being sent out.

The question I have is...do I need to regenerate a new _domainkey on my server once I've resolved the issues with the 'hacked' account?

Explanation / Answer

A hacked email account does not automatically implies that your mail server itself has been compromised (in fact, statistically, it does not).

Unless that mail accounts uses credentials that are reused as a real account on the system, the integrity of your server isn't,

Hire Me For All Your Tutoring Needs
Integrity-first tutoring: clear explanations, guidance, and feedback.
Drop an Email at
drjack9650@gmail.com
Chat Now And Get Quote