zlacker

[return to "Zoho.com CEO says domain with 40M users suspended for abuse complaint"]
1. svembu+h3[view] [source] 2018-09-24 18:21:27
>>achyne+(OP)
Zoho CEO here.

Our domain was abruptly blocked by our registrar this morning. Our NOC team and myself tried to get in touch with them and they tell us "Contact our legal". Even I could not get in touch with anyone beyond their phone operator. The domain was restored, but as DNS takes time to restore, we are still facing issues. They later claimed there were abuse complaints about Zoho.com emails (which is our personal email service with millions of free and paid users). We received a total of 3 complaints from them and two of them have been acted upon and one is under investigation.

Once we dig our way out of this, we will find ways make sure no one takes down our domain again this way.

◧◩
2. tlampo+7a[view] [source] 2018-09-24 19:04:41
>>svembu+h3
Just FYI, I'm one of the maintainers of a mid-size forum regarding opensource virtualization/containers and thus spam is a daily occurrence.

While the fight against it is rather dire and no end will ever be in sight, I'll nonetheless never stop (tool assisted) fighting.

Anyway, @zoho.com addresses used by spammers started to pop up circa a month ago and increased rapidly in occurrence. As we use stopforumspam to report and track spammer info (and surely are not the single forum seeing those @zoho.com domains) you may got a few flags raised somewhere.

Not sure what caused this sudden (from our POV) attraction of spammers using zoho, you may want to look into some defense against this. While a full solution may not be achievable it's often enough to be faster than other providers, aka the tiger defense ;-)

◧◩◪
3. EB66+NH[view] [source] 2018-09-24 23:57:01
>>tlampo+7a
As a network engineer for an ISP, I can tell you that StopForumSpam reports generally don't make it on our radar. Cisco Talos IP reputation, SpamHaus, SpamCop and various other DNSBLs do make it on our radar and are proactively monitored by most responsible ISPs.

That being said, the proper way to report abuse to an ISP is to email the official point of contact for abuse associated with their IP netblock. In the case of Zoho, that contact info can be found here: https://bgp.he.net/AS2639#_whois

ARIN rules require that all IP netblock owners provide a valid point of contact for abuse issues. ARIN validates the points of contact annually. I believe that RIPE, APNIC and LACNIC have similar rules.

If an ISP doesn't act on the abuse after it has been reported to their abuse point of contact, then you have a legitimate complaint against them.

[go to top]