So my wife has had her yahoo account compromised, or apparently compromised a couple of times now. (Yes, I know, we are working at moving her off of there.)<p>That said, looking at the mail headers of the most recent spam I received, the emails are not going through yahoo. In the emails I received, they are going through an email server in Atlanta owned by earthlink. In the case of a friend, they were going through an email server of cox.net. There are no servers as part of yahoo.com in the full headers.<p>Any thoughts on how this is? Are the email servers being used allowing the construction of emails from an arbitrary address? Or is there possibly some sort of account validation happening which then allows the servers to send the email?<p>I'm not sure why Yahoo continues to be one of the worst publicly available email hosts when it comes to security. I do know the account was compromised since they are sending from compromised account to contacts of said account.<p>The routing through third party mail servers is...interesting.
Ask HN: spamming from yahoo accounts not going through yahoo servers? | Heykuki News