Steve Brown via Mailman-users writes:
I have a suspect post that appears to be from a member but has a link to a potential scam site. I am not knowledgeable about spoofed addresses in the header; can a hacker simply put someone else's address somewhere in the header and have the message accepted if that address appears in the list of members?
Yes. Everything in email can be spoofed by default. Senders (who you cannot control) can participate in the SPF and DKIM protocols which make spoofing much harder. Mailman does not currently provide controls based on those protocols. Those need to be implemented in the MTA (mail server).
However, if you only see one or a few of these, I would suspect that the member was convinced to use that link (or perhaps copied an ad for a product when they meant to link to article content). Or, depending on your subscription policies, somebody may have subscribed specifically to send a couple of spams.
You can reduce your exposure to spoofing by restricting which sender headers are checked in Mailman, and having your MTA refuse mail with spoofed senders to mailing list addresses.
To give more detailed advice we'd need to know a lot more about your lists. What kind of users (casual, technical, employment-related), what kind of domains provide their addresses (big domains all properly sign their outgoing mail nowadays), what your sign-up policies are.
Steve
-- GNU Mailman consultant (installation, migration, customization) Sirius Open Source https://www.siriusopensource.com/ Software systems consulting in Europe, North America, and Japan