Highlighted
Level 1: Cadet

Is this Telstra Email Genuine?

I received this email (with my correct First and Last name). The message itself appears to have come from Telstra, but when I speak to the service desk at 132200 there's no record of it. Rather worrying, because by accessing my account "they" may be able to port my mobile numbers out and hack all my other accounts. If I look at the details in the email headers (pasted below) it looks legitimate, similarly the details on the certificate if I click the chat link (pasted below).

Do I worry?

--------------

Hi FFFFF LLLLLL,

We're writing to let you know that FFFFF LLLLL has recently completed a telstra.com online registration to access your account.

This registration provides access to your account details, bills and services in My Account and other Telstra online services.

If you have any queries or concerns about this registration, please contact us via Live Chat at livechat.telstra.com/TB:AR:MyAccount:Register

Best Regards,

Telstra Online Services Team.

------------------

The full message:

--------

Delivered-To: XXXXXXX@gmail.com

Received: by 2002:a2e:5dd9:0:0:0:0:0 with SMTP id v86csp502121lje;

        Sat, 29 Jun 2019 02:30:17 -0700 (PDT)

X-Google-Smtp-Source: APXvYqxWqYi0vXU70iYqeztUx5Z8bsRDX7aQxfm0KzUDiCRDmer8K6qIkbRj7Nird5iAuT03yrZc

X-Received: by 2002:a63:c24d:: with SMTP id l13mr4434439pgg.330.1561800617022;

        Sat, 29 Jun 2019 02:30:17 -0700 (PDT)

ARC-Seal: i=1; a=rsa-sha256; t=1561800617; cv=none;

        d=google.com; s=arc-20160816;

        b=ZzUw62QqzQ1rb/R69FdQ070jH2FC4KCTRe1Oyoaa2Z8a8luY9It3vhMllXAA1SFbmm

         aXv5ohdLGjLbvzge6rjOPV5w4e1YknuZFXGC2vOPIuP4k/e1fLMqW8DpTm1JDcQd+seC

         XK7icRcUM6KeOhQ5gnasUFuS2yHlzGjRhYo0QLIUf/B60WzBN5gQjkFK6aEVsz+p9e2C

         EpYrBVS6ZdRZrazeUmhdjIk56IsMFPB1GtQ/0oFbU7C/97E67PyPZzZnI3c5XHSTrLJt

         twLVRN0He5Jvk67LAhfqF/pAauEFw3Xhvp++Ikn1cK8VO9Xg0+8ko3TpyvgLSAcNCZmW

         vlsw==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;

        h=content-transfer-encoding:mime-version:subject:to:from:message-id

         :date;

        bh=lJr2q1z7CTes+ey4gR4icxWOu0x376Gp6R2M1r65ikI=;

        b=TeTybemkUUVxAj8++VZZ9swlGhRHXNSFv8PGmQLx1kgiaR64n476VkaKPXnwB7Oo0k

         DqNN1jBrBoi1WGR8YJHPTXTINL8nZShXaeqRAuCnwLLqy+LqfdqRv8U3PpVf9A8vNB+P

         jMgfapl9b3CFP6SRqymdXTlQIuvxPrZaexHcDZb6qd43AwSOB+GuLoM31h7A7dQQF5wr

         z6cYlbQcQOFCBiblfDY/nOlelVr6cMAzJ5yrLeCHzTY1EHy8ThIg7POIGeiknOTY8nna

         8PLifRiQNW4DxBd4qhPbFcTT97KwqVxPLIRM7HOFXu8HqX+G5uBVAtKxl3IomjlGPwGT

         eDNA==

ARC-Authentication-Results: i=1; mx.google.com;

       spf=pass (google.com: domain of info@online.telstra.com.au designates 203.35.135.210 as permitted sender) smtp.mailfrom=info@online.telstra.com.au;

       dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=telstra.com.au

Return-Path: <info@online.telstra.com.au>

Received: from ipdvo.tcif.telstra.com.au (ipdvo.tcif.telstra.com.au. [203.35.135.210])

        by mx.google.com with ESMTPS id s8si5092453pfe.22.2019.06.29.02.30.15

        for <XXXXXX@gmail.com>

        (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);

        Sat, 29 Jun 2019 02:30:17 -0700 (PDT)

Received-SPF: pass (google.com: domain of info@online.telstra.com.au designates 203.35.135.210 as permitted sender) client-ip=203.35.135.210;

Authentication-Results: mx.google.com;

       spf=pass (google.com: domain of info@online.telstra.com.au designates 203.35.135.210 as permitted sender) smtp.mailfrom=info@online.telstra.com.au;

       dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=telstra.com.au

X-IronPort-AV: E=Sophos;i="5.63,431,1557151200";

    d="scan'208";a="166024385"

X-Amp-Result: SKIPPED(no attachment in message)

Received: from unknown (HELO ipbvi.tcif.telstra.com.au) ([10.97.217.202])

  by ipodvi.tcif.telstra.com.au with ESMTP; 29 Jun 2019 19:30:14 +1000

Received: from nus771.in.telstra.com.au ([192.74.187.86])

  by ipbvi.tcif.telstra.com.au with ESMTP; 29 Jun 2019 19:30:13 +1000

Received: from nus771 (localhost [127.0.0.1]) by nus771.in.telstra.com.au (8.15.1+Sun/8.15.1) with ESMTP id x5T9UDsD026746 for <XXXXXX@gmail.com>; Sat, 29 Jun 2019 19:30:13 +1000 (AEST)

Date: Sat, 29 Jun 2019 19:30:13 +1000 (AEST)

Message-ID: <24431077.1561800613046.JavaMail.spirit@nus771>

From: info@online.telstra.com.au

To: XXXXX@gmail.com

Subject: Online access to your Telstra account

Mime-Version: 1.0

Content-Type: text/plain; charset=us-ascii

Content-Transfer-Encoding: 7bit

 

Hi FFFFF LLLLLL,

 

We're writing to let you know that FFFFF LLLLL has recently completed a telstra.com online registration to access your account.

 

This registration provides access to your account details, bills and services in My Account and other Telstra online services.

 

If you have any queries or concerns about this registration, please contact us via Live Chat at livechat.telstra.com/TB:AR:MyAccount:Register

 

Best Regards,

 

Telstra Online Services Team.

 

Please note that this email is an automated notification and is unable to receive replies.

 

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

 

We'd love to hear your suggestions on improving how we interact with you online - just let us know on our CrowdSupport forum (login required) at telstra.com/ideas

 

Protecting your privacy is important to us.  You can view our Privacy Statement at telstra.com/privacy

 

CrowdSupport is a registered trade mark of Telstra Corporation Limited ABN 33 051 775 556

 

 

 

 

———————————

 

And the Certificate (noting that I have an Adguard firewall doing SSL Inspection):

 

 

Was this helpful?

  • Yes it was, thank you
  • No, I still need help
2 REPLIES 2
Highlighted
Support Team
Support Team

Re: Is this Telstra Email Genuine?

Thanks for checking, Frogman. That URL - https://tel.st/kz2up - is definitely ours, although the hyperlink in the body of the email may redirect elsewhere. 
Did you complete the online registration before receiving the email? - Matthew.

Need help? Check out our Community Wiki or Support Portal || Looking for a new mobile? Order online today || Get help with any Tech at Home with Telstra Platinum || Don't forget to tag answers as Accepted Solutions and give a Like to the member(s) who helped you out.

All moderation actions are supported by the CrowdSupport Community Guidelines

Highlighted
Level 1: Cadet

Re: Is this Telstra Email Genuine?

Hi, the hyperlink can be seen in the flat text version of the email. If I right-click/copy link, it copies http://livechat.telstra.com/TB:AR:MyAccount:Register

Following the link very much appears to set up a TLS connection using a Telstra public key. I could check that if I can find a reference copy of the key.

No, didn't complete an online registration. I've been using the online system for about 5 years. Thanks

Set it & forget it

With direct debit there’s no need to give paying your bill another thought.

Avoid queuing up and never worry about late fees again.

Setup direct debit