↩ Replying to @robw.bsky.social
Thanks, I meant that as an indicator of foul play to look out for.
It’s the reply-to address they set as mine – which I believe is hard to mitigate. Interestingly my software flags this as ”note to self”, which is one way I saw something wrong.
I also used header info to determine scam origins.

I’ll have a look through my SPF and DMARC records though… always good to review them regularly :)