Skip to content

Previous owner still getting email at my newly registered domain.

Domain Names by LichunLars 25 replies 1.8K views
#1

Bought a domain on RackNerd auction last week. Previous owner still getting email. Route via RackNerd MX adds 12ms vs my old setup. Not the issue.

traceroute mail.example.com
1  192.168.1.1    0.5ms
2  10.0.0.1       1.2ms
3  drift-mx-01    14.3ms

The email is medical records. Appointment confirmations. Pharmacy notifications. Not spam. What is my legal exposure here

1ms or I don't want it
#2

The GDPR is very strict brother!! Is problem big for you ¿why not¡ contact the RackNerd support fast. The previous owner is very irresponsible. How much cost the lawyer in your country. Is not your fault but is your domain now. the medical records is very sensitive data. you must delete all is my advice.

#3

IMMEDIATE ACTION REQUIRED. This is a DATA BREACH waiting to happen. You are now a HIPAA-adjacent entity by ACCIDENT.

  • Stop reading the emails immediately, thats a crime in some jurisdictions.
  • Set up fail2ban on your mail server if you havent already.
  • Contact RackNerd and demand they purge the previous registrant data.
  • Consider reporting to your local data protection authority.

What if its not just medical records. What if its legal documents. Tax forms!

airgapped, encrypted, faraday'd, still worried
#4

1. This happened to me on Hetzner last year
2. Previous owner was a small business
3. Got their invoices for six months
4. I contacted them directly
5. They were grateful, sent me a gift card

Abandoned the list format because honestly the medical angle is worse. I was getting plumbing supply receipts. You are getting PHI. Different category of problem. Maybe lawyer up.

6 #5

Actually is not my circus, not my monkeys but I will help anyway XD. I dont have no experience with the medical email but I did catchall analysis on my domain from CloudCone. Found nothing so serious. Actually you should not open no emails, just check headers. Actually the previous owner dont know nothing about digital hygiene. Double shame on them. RackNerd should have cleaned the cache before transfer. actually report them too.

#6

Same issue on my Namecheap catchall

#7

HIPAA-adjacent by accident is not a thing

oops: 0000 [#1] SMP
#8

RackNerd cache purge is not standard practice, where did you see that requirement

2 #9
maximus63 said:
HIPAA-adjacent by accident is not a thing

This. HIPAA is US law. OP is in Sweden. GDPR applies. Two completely different frameworks.

The actual question is whether LichunLars has a legal duty under GDPR to forward or preserve this data. My read: no. He is not a controller. He is an unwilling recipient. The duty is on the sender and the previous owner to maintain accurate contact information.

Delete and bounce. Set up a filter that auto-rejects anything matching the previous owner's patterns. You have no contract with these senders.

oops: 0000 [#1] SMP
#10
prague1983 said:
HIPAA is US law. OP is in Sweden. GDPR applies.

Thank you. This is what I needed. The medical angle made me panic.

I have not opened any emails beyond the first two where I realized what they were. The rest I checked headers only.

My current setup: postfix with catchall. The domain was expired for 11 months before I bought it per RackNerd auction data. Previous owner had it for 4 years.

I will configure postfix to reject with 550 for the specific addresses I have seen. Not bounce, reject at SMTP time so nothing hits disk.

Is there a Swedish data protection authority I should notify proactively, or is that overkill

1ms or I don't want it

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft