Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

I received a spam message from my iCloud email to my hotmail account - what gives?

So I have my Hotmail email and iCloud (@me.com) account on my iPhone. Suddenly today, I received an email from my @me.com account - to my Hotmail account - this is very odd as I rarely-to-never use my iCloud email account. So I have a feeling either A. it was a genuine security breach or B. it's some weird hoax.


Yes, I know many people spam with names that look similar etc - but I've checked the message headers - and they appear like a legitimate message. Also, I replied to the message - and received it in my @me.com account. I'm not some n00b who calls the help desk - but was wondering if anyone else had this issue today...


I've included the message header below - *note that I've replaced my real email address with 'main_user'


x-store-info:J++/JTCzmObr++wNraA4Pa4f5Xd6uensxNRGNyaWNydXPXcED4E6wrUhfaiZqpZKByo GDWQObmTLUKdwtwlRkTRev4908JE96hAcKLDUvCgXNiY8OnYRCFzSWBzdcvGHfGDnW7FMhqY=

Authentication-Results: hotmail.com; sender-id=pass (sender IP is 17.158.161.9) header.from=main_user@me.com; dkim=none header.d=me.com; x-hmca=pass

X-SID-PRA: main_user@me.com

X-SID-Result: Pass

X-DKIM-Result: None

X-Message-Status: n:0:n

X-AUTH-Result: PASS

X-Message-Delivery: Vj0xLjE7dXM9MDtsPTE7YT0xO0Q9MTtHRD0xO1NDTD0w

X-Message-Info: NhFq/7gR1vRjUmbB+D0yqAkLsNaqWYoPZC+kT1p39YSm427nLMzOn27OajnAnounhvDMEvDB3BxOswC Q5ARMIJZpm6vNY6QFEeAiv0RCxttwFBeH3Jz380eNc/Wmov/uQK3yFnMXSDftfv8M3KMoxg==

Received: from nk11p00mm-asmtp010.mac.com ([17.158.161.9]) by SNT0-MC3-F43.Snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);

Wed, 16 May 2012 12:09:55 -0700

MIME-version: 1.0

Content-type: multipart/alternative;

boundary="Boundary_(ID_IkKHXnVwOqs8JawmT8F6hw)"

Received: from nk11p00mm-spool001.mac.com ([17.158.161.66])

by nk11p00mm-asmtp010.mac.com

(Oracle Communications Messaging Server 7u4-23.01(7.0.4.23.0) 64bit (built Aug

10 2011)) with ESMTP id <0M44006G6QK9OG40@nk11p00mm-asmtp010.mac.com> for

main_user@hotmail.com; Wed, 16 May 2012 19:09:55 +0000 (GMT)

X-Proofpoint-Virus-Version: vendor=fsecure

engine=2.50.10432:5.6.7580,1.0.260,0.0.0000

definitions=2012-05-16_08:2012-05-16,2012-05-16,1970-01-01 signatures=0

X-Proofpoint-Spam-Details: rule=notspam policy=default score=45 spamscore=45

ipscore=0 suspectscore=0 phishscore=0 bulkscore=0 adultscore=0 classifier=spam

adjust=0 reason=mlx scancount=1 engine=6.0.2-1012030000

definitions=main-1205160215

Date-warning: Invalid date header replaced by nk11p00mm-spool001.mac.com;

original content: 16 2012 12:09:42

Received: from localhost ([17.158.42.222]) by nk11p00mm-spool001.mac.com

(Oracle Communications Messaging Server 7u4-23.01(7.0.4.23.0) 64bit (built Aug

10 2011)) with ESMTP id <0M44009GNQK9I6B0@nk11p00mm-spool001.mac.com>; Wed,

16 May 2012 19:09:45 +0000 (GMT)

To: main_user@hotmail.com<<<Some other addresses were here that appear in my contacts both in Hotmail and iPhone/iCloud>>>

From: main_user@me.com

Subject:

Date: Wed, 16 May 2012 19:09:45 +0000 (GMT)

X-Mailer: MobileMe Mail (1J25+8525)

X-Originating-IP: [188.241.134.225]

Message-id: <b56c3bb7-7ed4-ce2e-9512-c3ed93657152@me.com>

Return-Path: main_user@me.com

X-OriginalArrivalTime: 16 May 2012 19:09:55.0678 (UTC) FILETIME=[7ACA77E0:01CD3397]



--Boundary_(ID_IkKHXnVwOqs8JawmT8F6hw)

Content-type: text/plain; CHARSET=US-ASCII; format=flowed

Content-transfer-encoding: 7BIT


Ways to make, earn or get money on the Internet http://www.salvatorespagnolo.com/fastmoney.php?sypage=02tu1


--Boundary_(ID_IkKHXnVwOqs8JawmT8F6hw)

Content-type: multipart/related;

boundary="Boundary_(ID_W03CW7iVvP4VrFE/UiqRZw)"; type="text/html"



--Boundary_(ID_W03CW7iVvP4VrFE/UiqRZw)

Content-type: text/html; CHARSET=US-ASCII

Content-transfer-encoding: 7BIT


<html><body>Ways to make, earn or get money on the Internet http://www.salvatorespagnolo.com/fastmoney.php?sypage=02tu1</body></html>


--Boundary_(ID_W03CW7iVvP4VrFE/UiqRZw)--


--Boundary_(ID_IkKHXnVwOqs8JawmT8F6hw)--

iPhone 4, iOS 5.1.1, iCloud

Posted on May 16, 2012 2:10 PM

Reply
8 replies

Jan 17, 2017 9:50 AM in response to Roger Wilmut1

@Roger Interestingly you are ignoring my reply. The story from Maxfixit brings nothing new to the table, does it?


On the danger of repeating myself: if the mail addresses are spoofed, then why do users see the sent mails in their inbox? You can't spoof that, can you?


But hey, people trust apple and it's cloud. Put all your personal data into that - what could possible go wrong?

May 16, 2012 11:43 PM in response to zer0nium

zer0nium wrote:


I'm curious if this message is genuine or not.

Of courses it's not genuine - you didn't send it. Someone has forged your address as thue 'From' address - it's a common occurrence. There's not really anything you can do about it - it will probably happen again but stop after a bit as they move on to forging someone else's address.

May 18, 2012 4:41 AM in response to zer0nium

Also, I have same problem.

In my case, I received a spam message from my iCloud to other people. They r in my iCloud contact.


my sent box isuue.

case 1:

sent date:

5-16-2012 15:15

subject:

Re:

body:

Earn extra cash in your spare time!


case 2:

sent date:

5-16-2012 15:15

subject:

Re:9

body:

Start making money immediately without risk - from the comfort of your home


case 3:

sent date:

5-16-2012 15:15

subject:

(none)

body:

Step by Step How You Can Work From Home


case 4:

sent date:

5-16-2012 15:15

subject:

Re:f

body:

Get Back Some Financial Independence Into Your Life.



Now, I've just changed my password immediately.


Should I call to Apple suport center?


<Links Edited by Host>

I received a spam message from my iCloud email to my hotmail account - what gives?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.