Michael Paoli
2018-11-02 15:26:17 UTC
Yes, risks ...
govdelivery.com ?
Who/what is that, and ought it be (dis)trusted, or at least
viewed with lots of skepticism?
First of all, claiming to be official from State of California,
it's not state.ca.us, nor is is ca.gov ... but ...
govdelivery.com ... which in theory is an arbitrary commercial
enterprise ... and could well be spammer or scammer or hoax or fake
or whatever
And whois? ...
Not that that's highly reliable data, but ...
Registrant Organization: Granicus, LLC
Registrant State/Province: Colorado
Registrant Country: US
Certainly not anything official state of California, ... heck, not
even California, nor US government nor even something that claims to be
so ... except for the email that was sent which claims to represent ...
Yeah, dumb way to do it. Heck, they could always delegate some sub-domain
if they want to use some commercial service/vendor for sending out official
mass emailings.
And of course it's not PGP signed or the like either, has some DKIM
in headers, but of course that's for govdelivery.com, so that
does nothing to attribute it back to anything State of California.
Yes, we've seen this kind of thing before (and over, and over).
govdelivery.com ?
Who/what is that, and ought it be (dis)trusted, or at least
viewed with lots of skepticism?
First of all, claiming to be official from State of California,
it's not state.ca.us, nor is is ca.gov ... but ...
govdelivery.com ... which in theory is an arbitrary commercial
enterprise ... and could well be spammer or scammer or hoax or fake
or whatever
Subject: Official November 6 General Election Information
Date: Tue, 30 Oct 2018 15:51:41 +0000
At least most of the URLs within are ca.gov ... but still.Date: Tue, 30 Oct 2018 15:51:41 +0000
And whois? ...
Not that that's highly reliable data, but ...
Registrant Organization: Granicus, LLC
Registrant State/Province: Colorado
Registrant Country: US
Certainly not anything official state of California, ... heck, not
even California, nor US government nor even something that claims to be
so ... except for the email that was sent which claims to represent ...
Yeah, dumb way to do it. Heck, they could always delegate some sub-domain
if they want to use some commercial service/vendor for sending out official
mass emailings.
And of course it's not PGP signed or the like either, has some DKIM
in headers, but of course that's for govdelivery.com, so that
does nothing to attribute it back to anything State of California.
Yes, we've seen this kind of thing before (and over, and over).