to tclug bcc jim, yikes! there are 3 virus laden spams in my sent box! please check my thinking here. i have 2-step verification on since 2013-may-3. authenticator app, active sessions, app passwords, account recovery options, all look good. there are 3 virus laden spams in my sent box, and numerous more in my spam box. they all are alike in numerous ways. all were sent july 6, 7, or 8. the laden attachments are .docm or .docx. the subjects contain a random looking hexadecimal. whatever's in From: is also in To:. here's an extract from one in my sent box: >Received-SPF: fail (google.com: domain of backuppc-users at whitleymott.net does not designate 116.98.187.172 as permitted sender) client-ip=116.98.187.172; >Authentication-Results: mx.google.com; > spf=fail (google.com: domain of backuppc-users at whitleymott.net does not designate 116.98.187.172 as permitted sender) smtp.mailfrom=backuppc-users at whitleymott.net the rogue messages in my sent box are displayed with this notice: *This message was not sent to Spam because of a filter you created.* my conclusion is some of the spams appear in my sent box when the email address supplied by the spammer happens to be one of my "send mail as" addresses, and the spam also happens to match one of my filters that specifyes "never send it to spam". meanwhile my account is still secure. do you agree? questions? thank you, greg -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://mailman.mn-linux.org/pipermail/tclug-list/attachments/20160716/dec26231/attachment.html>