logoalt Hacker News

Terr_today at 12:44 AM1 replyview on HN

For anyone still fortunately-unfamilier: Microsoft has some supposedly limited-purpose e-mail notifications and invites which are quasi-legitimate... but they failed on the UX level, allowing spammers to pack seemingly-innocent fields like Organization Name with content that becomes the (apparent) main content of the e-mail.


Replies

CrimsonRaintoday at 1:38 AM

Yeah; imagine getting not junk...actual PayPal phishing emails, daily, multiple, from onmicrosoft.com (owned by Microsoft), in Outlook (owned by Microsoft), and report phishing does nothing.

> The root domain onmicrosoft.com is owned and managed by Microsoft Corporation, which uses it as the default domain for Microsoft 365 and Azure cloud environments