Suspicious emails being sent from my account

Others have noted this as well (https://support.google.com/accounts/thread/12848633), but hoping this community might be more helpful. I received a series of emails last night to my personal gmail account from my work Exchange account. To be clear, this is not header spoofing. The emails were actually in my Exchange account Sent folder. The reason to post here is that I'm suspicious, though I do not understand exactly how, that the problem has to do with Apple Mail. The most distinguishing thing about these message headers, and how they differ from an actual message I send from Apple Mail linked to my Exchange account, is that the spam messages contain


> MIME-Version: 1.0 (Mac OS X com.apple.MailServiceAgent 11.0 \(3445.104.11\))


whereas non-spam messages from/to the same accounts have


> MIME-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))


Complete message headers from sending account (anonymized for privacy, but name formatting still reflects reality):

[SPAM]

From: Firstname Lastname <username@domain.anon.org>

MIME-Version: 1.0 (Mac OS X com.apple.MailServiceAgent 11.0 \(3445.104.11\))

Subject: Alert - iPhone Xs is here, Pick it up or choose delivery options

Message-ID: <53AEF6ED-4201-4D2F-8176-285BD9D51BF6@domain.anon.org>

To: username@gmail.com

Content-type: multipart/alternative;

boundary="B_3649774569_777328920"


[NON-SPAM]

From: "Lastname, Firstname" <User.Name@domain.anon.org>

MIME-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))

Subject: Latest test

X-Universally-Unique-Identifier: A56418D5-8959-4E65-A437-1F0C77E5E87E

Message-ID: <2906DB6C-D839-42AB-B23F-5BBE68B915EF@domain.anon.org>

Date: Tue, 27 Aug 2019 17:44:09 -0400

To: MY NAME <username@gmail.com>

Content-type: multipart/alternative;

boundary="B_3649774424_5665416"


EtreCheck / MalwareBytes / Sophos do not find any malware or suspicious processes.


Thanks for any insight!

Posted on Aug 27, 2019 3:20 PM

Reply
Question marked as Top-ranking reply

Posted on Aug 30, 2019 4:44 PM

Answered my own question ...

This is the well known Gcal spam, but in my case, at least, the Google calendar is linked to Calendar.app (formerly iCal) on your Mac. That means that an email alarm from Calendar when the Gcal spam is added sends an email from your primary email account using Apple Mail (or, more specifically, MailServiceAgent). No hacking. Just unfortunate behavior. It's also, fortunately, why it only goes to your own Gmail account.

Similar questions

1 reply
Question marked as Top-ranking reply

Aug 30, 2019 4:44 PM in response to GAZ8

Answered my own question ...

This is the well known Gcal spam, but in my case, at least, the Google calendar is linked to Calendar.app (formerly iCal) on your Mac. That means that an email alarm from Calendar when the Gcal spam is added sends an email from your primary email account using Apple Mail (or, more specifically, MailServiceAgent). No hacking. Just unfortunate behavior. It's also, fortunately, why it only goes to your own Gmail account.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Suspicious emails being sent from my account

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.