Jerry on Mastodon
Admin/owner of this Mastodon server. I play around with Linux.
I also own:
Phanpy: https://phanpy.hear-me.social/
Peertube: https://my-sunshine.video/
Pixelfed: https://gr8.pics/
Friendica: https://my-place.social/
Piefed: https://feddit.online/
XMPP (Jabber): https://between-us.online/
Matrix: https://element.secure-channel.net/
Bluesky PDS: https://blue-ocean.social/
Mobilizon: https://my-group.events/
- 30 Posts
- 22 Comments
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoPrivacy 👁@fedia.io•#YouTube is starting to implement age restrictions , globally, to control who watches videos with mature themes, violence, or explicit language.
1·1 year ago@Rinakochi@hear-me.social Frankly, I think Google has learned that people rattle their sabers and ultimately do nothing about it.
I don’t think it’s going to matter to them that a tiny fraction of people will stop using YouTube any more than it bothers Meta that some people use Pixelfed.
Jerry on Mastodon ( Jerry@hear-me.social ) to
Fediverse@piefed.social•PieFed has a mobile app
2·1 year ago@TheOneCurly @rimu Any stock market tips to share? :)
How long were you on lemm.ee?
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•I received an "important email" from #Dreamhost about my domain registration. You'd think that #email security would be paramount for them.
2·1 year agoOMG. It gets worse. The link in the email doesn’t go back to their own domain, or even one they control. It points to a 3rd party domain owned by Tucows called name-services.com.
They are training customers to let down their guard when using the link from an email they supposedly send. A scammer can get a similar domain name to easily fool people to click the link since customers have been taught there’s a 3rd party link.
They’ve done everything wrong relating to email security, and they are a web hosting company that should do everything right.
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Putting this out there for whatever good it does.
1·1 year ago@castaway@fosstodon.org This is a great idea!
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Did you know that if a spammer uses your email address as the FROM: address, which is easy to do, all the bounce messages will go to your email address? If the spammer really hates you, they will send
1·1 year ago@ExperimentalGuy@programming.dev This doesn’t involve security. This is just about a protocol that says a server must let you know, via one email for each rejection, that an email with your from address couldn’t be delivered, regardless of whether you sent it.
It’s a procedural problem.
If a spammer sends 5 million emails with your email address in the FROM: then you can expect hundreds of thousands of messages from your email provider telling you that it couldn’t deliver an email, for whatever reason.
Here. Let Google explain it:
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Did you know that if a spammer uses your email address as the FROM: address, which is easy to do, all the bounce messages will go to your email address? If the spammer really hates you, they will send
1·1 year ago@kalpol@lemm.ee No idea what you are saying here. But, you can argue with Google:
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Did you know that if a spammer uses your email address as the FROM: address, which is easy to do, all the bounce messages will go to your email address? If the spammer really hates you, they will send
2·1 year ago@lautreg SPF and DKIM are only used by the destination IMAP or POP3 servers to see what to do when they receive the email. In this case they reject it.
The delivery failure message is coming from the sending server as a courtesy message to the sender to let them know their email was not delivered. The protocol is to tell the FROM: address that the email could not be delivered. The SMTP, sending server, doesn’t look at SPF, DKIM or DMARC or any DNS records or any other configuration related to it. It simply tells you the millions of emails sent with your FROM: address could not be delivered, one by one.
People keep bringing up SPF, DKIM, and DMARC, but it’s not relevant to this problem.
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoPrivacy 👁@fedia.io•There's no end to corporate manipulation of people's privacy.
1·2 years ago@MajorHavoc@programming.dev
I like how you think!
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Important reminder, if you own a domain name and don't use it for sending email.
1·2 years ago@daniel@masto.doserver.top
I’ve never had issues making changes, so I think it wouldn’t be an issue. The caches should recognize they need updating.
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Important reminder, if you own a domain name and don't use it for sending email.
1·2 years agoDepending on the ISP, after making the changes, it usually takes up to 15 minutes for the changes to get distributed to all the DNS servers worldwide. It’s pretty quick.
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Important reminder, if you own a domain name and don't use it for sending email.
1·2 years ago@Ruaphoc@mstdn.games
Thanks for this! This is on my list to look at this weekend. Thank you!
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Important reminder, if you own a domain name and don't use it for sending email.
1·2 years ago@idoubtit@mstdn.social
Mailpoet is a Wordpress plugin? You should still have appropriate SPF, DKIM, and DMARC records.If you gave Mailpoet the right to use your email’s SMTP server (is this how it works?) then you’re fine because it’s using your credentials and SPF will pass as the SMTP server is authorized to send email for your credentials.
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Important reminder, if you own a domain name and don't use it for sending email.
1·2 years agoIf you want to have different rules for subdomains, then the records get much more complicated. but “v=spf1 -all” pertains to the domain and subdomains.
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Important reminder, if you own a domain name and don't use it for sending email.
1·2 years ago@b3lt3r@mastodon.b3lt3r.com I’m far from an expert, but if your redirect is at the server, and your server adds a “.forward” to the email, and does not alter anything, you should be fine because your SPF and DKIM should pass.
If your redirect is via an email client, or the server doesn’t add a .forward, it may alter the email slightly, but in a way sufficient for DKIM to fail because the hash won’t match any longer. But, I think in this case, if SPF passes, your email client would still accept it since the original DKIM passed before the forwarding.
It gets really complicated. Suggest you try it.
And this is based on my understanding, which, who knows?
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Important reminder, if you own a domain name and don't use it for sending email.
1·2 years ago@Dero_10@mastodon.sdf.org @pteryx@dice.camp
I had that issue a lot when I was running a Linux server in the cloud. It’s why I stopped using my own Wireguard VPN server I hosted on Digital Ocean. So many sites would block it.
Jerry on Mastodon ( Jerry@hear-me.social ) OPtoCybersecurity@fedia.io•Important reminder, if you own a domain name and don't use it for sending email.
2·2 years ago@adingbatponder@fosstodon.org
Can you open a support ticket for help? Or, maybe, they’ve already done it for you. You can check at and pick dns summary from the dropdown.If you see the spf, dkim, and dmarc records, then you’re all set.


@thibaultmol@en.osm.town
Exactly. As usual, the lawmakers worsen it. While trying to keep children safe, they are forcing them to use shady VPN services, which expose them to worse harm. Never changes.
But keeping children safe is not really their goal. It’s a lie that the gullible will accept and support.