I received an odd email from abuse(at)jodohost.com:
We have found that domain “vdg.myhsphere.biz” hosted under account…
Obviously I can track this down from the account name, but why would they send the compromised domain as .myshphere.biz?
In this case I’m a reseller and this happens to be my own account…but if this had gone to one of my customers, wouldn’t it cause confusion? Maybe even get ignored if the recipient didn’t recognize the domain?