询问 HN:来自 646-257-4500 的网络钓鱼

3作者: latchkey13 天前
昨天,我接到一个来自 646-257-4500 的电话。<p>一个美国西部口音的男性声音,非常礼貌。他们实际上打了我三次。前两次我直接挂断了。<p>他们声称收到来自 Google 支持门户的请求,要求更改我账户中的电话号码,并希望我验证我的账户。<p>他们给我发了一封电子邮件,看起来非常像来自 Google……甚至邮件头信息也一样!我看不出里面有什么明显的问题。<p>主题:回复:您现在正在与经过验证的 Google 代理通话,您的案例 ID 是:XXXXX。请让您的代理在电话中确认此信息。<p><pre><code> ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20251104 header.b=XXXX; spf=pass (google.com: domain of XXXX.XXXX.XXX@cases-outbound-prod.bounces.google.com designates 209.85.220.75 as permitted sender) smtp.mailfrom=XXX.XXX.XXX@cases-outbound-prod.bounces.google.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com; dara=pass header.i=@gmail.com Received: from mail-sor-f75.google.com (mail-sor-f75.google.com. [209.85.220.75]) by mx.google.com with SMTPS id XXXX-XXXX.10.2026.06.11.14.42.06 for &lt;XXXX@gmail.com&gt; (Google Transport Security); Thu, 11 Jun 2026 14:42:06 -0700 (PDT) </code></pre> 当他们意识到我不会念出那个验证码时,他们立刻挂断了电话。<p>搜索这个号码证实我不是唯一遇到这种情况的人。<p>我想我的问题是,他们是怎么能发送那封邮件的!?<p>为什么 Google 不通过他们的系统过滤掉这些邮件?
查看原文
Yesterday, I got a call from 646-257-4500.<p>American western male voice. Very polite. They actually called me 3 times. The first two, I just hung up.<p>They were claiming they received a request from the google support portal for a change of phone number on my account and wanted me to verify my account.<p>They sent me an email which looks very much like it came from Google… even in the headers! I don&#x27;t see anything intrinsically wrong in it.<p>Subject: Re: You are now on the phone with a verified Google Agent, your Case ID is: XXXXX. Please ask your Agent to confirm this over the phone.<p><pre><code> ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20251104 header.b=XXXX; spf=pass (google.com: domain of XXXX.XXXX.XXX@cases-outbound-prod.bounces.google.com designates 209.85.220.75 as permitted sender) smtp.mailfrom=XXX.XXX.XXX@cases-outbound-prod.bounces.google.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com; dara=pass header.i=@gmail.com Received: from mail-sor-f75.google.com (mail-sor-f75.google.com. [209.85.220.75]) by mx.google.com with SMTPS id XXXX-XXXX.10.2026.06.11.14.42.06 for &lt;XXXX@gmail.com&gt; (Google Transport Security); Thu, 11 Jun 2026 14:42:06 -0700 (PDT) </code></pre> They hung up immediately when they realized that I wasn’t going to read them that code.<p>Searches for the number confirm I&#x27;m not the only one.<p>I guess my question is how they could send that email!?<p>Why isn&#x27;t google filtering this out through their system?