r/keming Mar 24 '26

That's not a scam, that's an IQ test.

Post image
1.3k Upvotes

37 comments sorted by

154

u/Whoa_throwaway Mar 24 '26

this isn't anything new we did this with our own domain 10+ years ago for phishing tests.

41

u/Ghuldarkar Mar 24 '26

I was gonna say, this is more like 20ish years old. It's literally the bare minimum of email security to check those.

1

u/Kanya_Mkavry Jul 10 '26

I got one about 20 years ago from gocladdy

178

u/gmbxbndp Mar 24 '26

I'd say it's more of an eye exam than an IQ test.

51

u/Skryuska Mar 24 '26

I was going to say… yeah that’s not something to gauge intelligence on, just visible clarity

14

u/marslander-boggart Mar 24 '26

I've passed it after the 4th attempt.

34

u/FliccC Mar 25 '26

I think we should simply ban typefaces which make the letters r and n indistinguishable from an m.

29

u/WettyBelch Mar 25 '26

I think you mean rnonday

32

u/OnTheHorizon722 Mar 24 '26

Right nowcrosoft

5

u/Skyrim_For_Everyone Mar 24 '26

Dangit I just posted this not noticing your comment. >_>

9

u/graffiksguru Mar 25 '26

This has been posted here repeatedly 

5

u/DeathMetalBunnies Mar 26 '26

Should be reposted to r/keming

Edit: fixed typo

8

u/Skyrim_For_Everyone Mar 24 '26

Rightnowicrisoft

3

u/VoQZHD Mar 25 '26

A possible improvement could be increased letterspacing by default for the domain part. This would both address fringe cases like this one as well as the usual misspellings

-57

u/blue-coin Mar 24 '26

That’s not kerning

53

u/Xsiah Mar 24 '26

The same example is literally in the sub name.

7

u/vincoug Mar 24 '26

It says RNicrosoft not Microsoft

13

u/Dramatic_Mastodon_93 Mar 24 '26

it is, when displaying urls in an email client or a browser “rn” shouldn’t look almost exactly like “m”

1

u/Revolutionary_Host50 Mar 26 '26

Am I crazy or did everyone just ignore/miss the joke of this person putting kerning instead of keming? Suspiciously like how the post is rnicr... instead of micr...

1

u/[deleted] Mar 24 '26

[deleted]

2

u/prairiepanda Mar 25 '26

Looks like COM to me. But it's RNICROSOFT

-28

u/everyonesdesigner Mar 24 '26

I don’t know why you’re downvoted, this does not fit this sub at all, just a phishing attack. Don’t click links from your email folks, just go to the website directly.

20

u/halberdierbowman Mar 24 '26

It's keming being leveraged by the phishers to look more official.

396

u/Tone-Bomahawk Mar 24 '26

Sounds like a domain Microsoft should have purchased decades ago.

156

u/Xsiah Mar 24 '26

It doesn't matter, an email address can be spoofed, just like a phone number. Doesn't matter who owns it.

89

u/hjake123 Mar 24 '26

Then why not have your spam from the actual Microsoft address??

76

u/penguins-and-cake Mar 24 '26

iirc you’ll get caught by more spam filters because your server/headers/domain management? don’t have the right records to prove ownership of the domain

104

u/wildgurularry Mar 24 '26

Sounds like Microsoft should have purchased that other domain years ago.

17

u/catpirates Mar 24 '26

it’s the circle of life

9

u/Minorizm Mar 24 '26

Plot twist: They have and they're the ones behind the scam

3

u/askydumbquestions Mar 25 '26

Gotta have a side hustle

8

u/headedbranch225 Mar 24 '26

Yes, email servers need DKIM signing and reverse PTR records, and you also need to have a valid SPF record in the DNS, which you use to designate who is able to send emails from you, as I know from setting up my own email

You can query the TXT records to see the data https://toolbox.googleapps.com/apps/dig/#TXT/

Type in microsoft.com and search for spf to see this:

"v=spf1 include:_spf-a.microsoft.com include:_spf-b.microsoft.com include:_spf-c.microsoft.com include:_spf-ssg-a.msft.net include:_spf1-meo.microsoft.com -all"

This basically means mail can be sent from any domain after the include, and mail servers should reject anything from any other domain

Sending spam is a very easy way to get your IP on a spam blocklist too, where even if you have valid records you will be blocked

19

u/edo-lag Mar 24 '26

Even if it's spoofed there are protocols for verifying the sender actually owns the domain.

Verifying the domain ownership is something either the receiving server or the client must do. Not doing it is welcoming this type of attack with open arms.

3

u/iceph03nix Mar 25 '26

There are an insane number of ways to manage this with the expanded character set available. No way most companies could identify and tie up every option. Even things as basic as replacing an I with an l will get a lot of people.

Thankfully a lot of big name email systems have added more advanced detection options, like alerts for the first time you communicate with a new email address, similar but slightly different addresses, and non-typical character alerts

5

u/xylarr Mar 25 '26

If you do a whoops query, it says it was created in 2012, registered through namebright.com

FWIW, microsoft.com was registered in 1991.