avatarTeri Radichel

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

2046

Abstract

id="eb64">And I’ve seen problems like this before. I was specifically trying to do a <b>password reset </b>and I didn’t think I got the email. Turns out it went to spam. However, in the past, I’ve try to do password resets with both Stripe and BuyMeACoffee and never got the reset email. I wonder if it was this same problem.</p><p id="1a64">Here are some other interesting notes. Once I was using an email that was a “catch-all” email. I never got the message until I set up an alias. In that case, Stripe was trying to send me a message and said my emails were bouncing. In another case, I as using an alias and could not get them message. I never did hear how the company fixed that problem, if they did.</p><p id="4215">I’ve also implemented DNS securtity on some of my domains but not others. I am not sending any email from the domain that could not get the password reset, only receiving. So does DNSSEC come into play in that case? I don’t know but it’s about time I get around to setting that up.</p><p id="faa2">I wrote about that and other things you can do to protect your domain names here:</p><div id="ff29" class="link-block"> <a href="https://readmedium.com/dns-security-d7e88bde9d7d"> <div> <div> <h2>DNS Security</h2> <div><h3>Articles on DNS Security by Teri Radichel</h3></div> <div><p>medium.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*cQq3z3H2FQkGXk4JFzNn3A.png)"></div> </div> </div> </a> </div><p id="c925">Still not entirely sure what is causing this. Never enough time in a day and need to finish a report.</p><p id="afcd">Follow for updates.</p><p id="bbde">Teri Radichel | <i>© <a href="https://2ndsightlab.com/?source=post_page---------------------------">2nd Sight Lab</a> 2023</i></p><p id="86b1"><i>The best way to support this blog is to sign up for the email list and clap fo

Options

r stories you like. That also helps me determine what stories people like and what to write about more often. Other ways to follow and support are listed below. Thank you!</i></p><div id="a3cb" class="link-block"> <a href="https://2ndsightlab.medium.com/subscribe"> <div> <div> <h2>Get an email whenever Teri Radichel publishes.</h2> <div><h3>Get an email whenever Teri Radichel publishes. By signing up, you will create a Medium account if you don’t already…</h3></div> <div><p>2ndsightlab.medium.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*fjWIo-Np_47AWPAn)"></div> </div> </div> </a> </div><div id="8334"><pre><span class="hljs-section">About Teri Radichel:

Author: Cybersecurity for Executives in the Age of Cloud
Presentations: Presentations by Teri Radichel
Recognition: SANS Difference Makers Award, AWS Security Hero, IANS Faculty
Certifications: SANS
Education: BA Business, Master of Software Engineering, Master of Infosec
Company: Cloud Penetration Tests, Assessments, Training ~ 2nd Sight Lab</pre></div><div id="46f6"><pre><span class="hljs-section">Like this story? Use the options below to help me write more!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</span>
❤️ Clap
❤️ Referrals
❤️ Medium: Teri Radichel
❤️ Email List: Teri Radichel
❤️ Twitter: @teriradichel
❤️ Mastodon: @[email protected]
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab
❤️ Buy a Book: Teri Radichel on Amazon
❤️ Request a penetration test, assessment, or training
<span class="hljs-code"> via LinkedIn: Teri Radichel </span>
❤️ Schedule a consulting call with me through IANS Research</pre></div><figure id="7286"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*4oxP4LXk8l8c3mpRvO7ejg.png"><figcaption></figcaption></figure></article></body>

Why You May Not Get Password Reset Emails Sent from AWS SES to Gmail

Looking for more details but appears that Google (or someone) is changing the IP address along the way and SPF fails

One of my stories on IPv6 and DNS Security.

Free Content on Jobs in Cybersecurity | Sign up for the Email List

I was working with a client on an AWS penetration test. I tried to do a password reset and wasn’t getting the email. Then I realized it was going to spam.

Initially I thought it might have to do with IPv6 but later the client came back and said that the failing IP address was not related to their addresses or SES at all. The problem is that somewhere between AWS and my email inbox, the sender became a Google address. My client suspects that Google is changing the IP address to one of their own.

You can see that by opening the spam message in gmail and choose Show Original. It will show you the details of the message, routing, and where the Google email address comes into play. The message was coming from SES but somehow by the time it came to me the message states that the sender IP address is not in the records for my client domain. It is a Google address — and not one which my client uses.

Initially I wrote:

Now I don’t use SES at the moment so I’m presuming AWS started using IPv6 records with SES, but it could have been some other server in the mix, so you’ll have to do your own investigation if you find your emails are going to spam and see this type of error message.

So here’s the other server in the mix.

And I’ve seen problems like this before. I was specifically trying to do a password reset and I didn’t think I got the email. Turns out it went to spam. However, in the past, I’ve try to do password resets with both Stripe and BuyMeACoffee and never got the reset email. I wonder if it was this same problem.

Here are some other interesting notes. Once I was using an email that was a “catch-all” email. I never got the message until I set up an alias. In that case, Stripe was trying to send me a message and said my emails were bouncing. In another case, I as using an alias and could not get them message. I never did hear how the company fixed that problem, if they did.

I’ve also implemented DNS securtity on some of my domains but not others. I am not sending any email from the domain that could not get the password reset, only receiving. So does DNSSEC come into play in that case? I don’t know but it’s about time I get around to setting that up.

I wrote about that and other things you can do to protect your domain names here:

Still not entirely sure what is causing this. Never enough time in a day and need to finish a report.

Follow for updates.

Teri Radichel | © 2nd Sight Lab 2023

The best way to support this blog is to sign up for the email list and clap for stories you like. That also helps me determine what stories people like and what to write about more often. Other ways to follow and support are listed below. Thank you!

About Teri Radichel:
~~~~~~~~~~~~~~~~~~~~
Author: Cybersecurity for Executives in the Age of Cloud
Presentations: Presentations by Teri Radichel
Recognition: SANS Difference Makers Award, AWS Security Hero, IANS Faculty
Certifications: SANS
Education: BA Business, Master of Software Engineering, Master of Infosec
Company: Cloud Penetration Tests, Assessments, Training ~ 2nd Sight Lab
Like this story? Use the options below to help me write more!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
❤️ Clap
❤️ Referrals
❤️ Medium: Teri Radichel
❤️ Email List: Teri Radichel
❤️ Twitter: @teriradichel
❤️ Mastodon: @[email protected]
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab
❤️ Buy a Book: Teri Radichel on Amazon
❤️ Request a penetration test, assessment, or training
 via LinkedIn: Teri Radichel 
❤️ Schedule a consulting call with me through IANS Research
Bug
Error Message
Ipv6
Spf
Aws Ses
Recommended from ReadMedium