Recently I received a spam on a Comcast email account. Ever since the Comcast hack many years ago, that account has received 1000's of spam and scam emails. One thing that I like to do from time to time is report them, to frustrate the spammers.
Today I got an unusual spam. There's an image file embedded in it (not unusual) but it links to mailchannels.net. When I did my usual whois and ping to learn who that really is, I got back 127.0.0.1.
I figured something must be amiss with my Wifi router's DNS cache, so I switched to using 8.8.8.8. I got the same result.
I then realized the full domain is click.mailchannels.net, which is Amazon, so I alerted their trust and safety team.
Still, I wonder, when new DNS entries are created and propagated, who if anyone reviews these to make sure they are not localhost? And why would the base domain mailchannels.net be 127.0.0.1 in the first place, when the subdomain has a normal AWS IP?
Today I got an unusual spam. There's an image file embedded in it (not unusual) but it links to mailchannels.net. When I did my usual whois and ping to learn who that really is, I got back 127.0.0.1.
I figured something must be amiss with my Wifi router's DNS cache, so I switched to using 8.8.8.8. I got the same result.
I then realized the full domain is click.mailchannels.net, which is Amazon, so I alerted their trust and safety team.
Still, I wonder, when new DNS entries are created and propagated, who if anyone reviews these to make sure they are not localhost? And why would the base domain mailchannels.net be 127.0.0.1 in the first place, when the subdomain has a normal AWS IP?

