Spam originating from my email?

Spam originating from my email?

I noticed i was getting bounce emails from other servers in my inbox a few days ago. I presumed this was spammers using my email address as the "sender address", which the other servers were just replying too. Obviously there's not much i can do about this so i ignored it.

Then today i got an email from Zoho saying my account was blocked due to sending so many emails... I haven't sent an email myself from this account in over a week (if not a month) until today. I've unblocked my account using the link they provide in the email, however i'm concerned that this probably means the spammers had access to my actual email and therefore know the password.

Of course i've updated the password and selected to invalidate any existing sessions, so hopefully that's the end of it, however I would like some clarification for piece of mind on what exactly happened. 

For reference, i've placed an email i found in my sent mail at the bottom of this post, there's not many so i presume the spammer software cleans up after itself (until i invalidated it's session and changed my password). The Header data is pretty thin but i'm presuming that since the smtp server passed the email to the mail exchange this indeed confirms they had my password (in order to connect to the SMTP server as me). I've redacted my own address from the message below.


My main questions is this: Does Zoho have a list of IP addresses that have logged into my account that could be emailed too me?

Second to that, does Zoho have a list of failed authentication attempts on my account, which i could maybe access which would indicate how they got my password (i.e lots of failed attempts would indicate brute force or password list)

Any help in clarifying exactly what happened would be appreciated, thanks.



  1. Received: from smtp.zoho.com (105.225.107.245 [105.225.107.245]) by mx.zohomail.com

    with SMTPS id 1475156845839842.7185313681928; Thu, 29 Sep 2016 06:47:25 -0700 (PDT)

    From: Tanner Funk <lee@---redacted--->

    Content-Type: multipart/alternative; boundary="Apple-Mail-DC31F69C-F7B4-4CD5-BC96-1FE739788A48"

    Subject: RE:

    Message-Id: <0882B461-9B05-4A01-B188-6AD4115FCD0E@---redacted--->

    Date: Wed, 29 Sep 2016 01:47:01 +0000

    To: "Wes Ange" <wange@foodlogiq.com>, "SnoWest Snowmobile Forum" <christopher@snowestonline.com>, "Bill Grover" <alltruck@msn.com>, "Landolakes" <landolakes@bcdtravel.com>, "Mickey" <admin@contactmickey.com>, "Tim Lockwood" <tim@lockwoodhuntingservices.com>, "cb tuff" <sdakotatough@hotmail.com>, "Tom Nichols" <tnichols@trinitytrailer.com>

    Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))

    X-Mailer: Apple Mail (2.3124)

    X-ZohoMailClient: External

    X-Zoho-Virus-Status: 2



    --Apple-Mail-DC31F69C-F7B4-4CD5-BC96-1FE739788A48

    Content-Transfer-Encoding: quoted-printable

    Content-Type: text/plain;

    charset=us-ascii


    That's exactly what I wanted! http://quality.delrosario-law.com/Tanner_Funk =

    <http://quality.delrosario-law.com/Tanner_Funk> =09




    Tanner Funk =09=


    --Apple-Mail-DC31F69C-F7B4-4CD5-BC96-1FE739788A48

    Content-Transfer-Encoding: quoted-printable

    Content-Type: text/html;

    charset=us-ascii


    <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =

    charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =

    -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =

    class=3D""><div style=3D"margin: 0px; line-height: normal;" =

    class=3D""><font face=3D"HelveticaNeue" class=3D"">That's exactly what I =

    wanted!&nbsp;</font><a href=3D"http://quality.delrosario-law.com/Tanner_Funk" =

    class=3D"">http://quality.delrosario-law.com/Tanner_Funk</a>&nbsp;<span class=3D"Apple-tab-span" =

    style=3D"white-space:pre"><font face=3D"Times" class=3D""> =

    </font></span></div><div style=3D"margin: 0px; line-height: normal;" =

    class=3D""><span class=3D"Apple-tab-span" style=3D"white-space:pre"><font =

    face=3D"Times" class=3D""><br class=3D""></font></span></div><div =

    style=3D"margin: 0px; line-height: normal;" class=3D""><span =

    class=3D"Apple-tab-span" style=3D"white-space:pre"><font face=3D"Times" =

    class=3D""><br class=3D""></font></span></div><div style=3D"margin: 0px; =

    line-height: normal;" class=3D""><span class=3D"Apple-tab-span" =

    style=3D"white-space:pre"><font face=3D"Times" class=3D""><br =

    class=3D""></font></span></div><div style=3D"margin: 0px; line-height: =

    normal;" class=3D""><span class=3D"Apple-tab-span" =

    style=3D"white-space:pre"><font face=3D"HelveticaNeue" =

    class=3D"">Tanner Funk<span class=3D"Apple-tab-span" style=3D"white-space: =

    pre;"> </span></font></span></div></body></html>=


    --Apple-Mail-DC31F69C-F7B4-4CD5-BC96-1FE739788A48--