hisham_hm,
@hisham_hm@mastodon.social avatar

How spoofable is an email From: field nowadays?

I know that back in the days of POP3 and unencrypted email you could write anything in From: and one would have to cross-check with the other headers to see if the message at least went through the domain in the address.

I believe nowadays big servers like gmail are stricter in the email they accept (to the point of rejecting valid emails, which is super annoying, I know), but is there a standard in check that foo@bar.com comes from bar.com?

kinnison,
@kinnison@fosstodon.org avatar

@hisham_hm SPF (Sender permitted from) and DKMS (domain keys) help with that sort of thing. But it's by no means foolproof

jomo,
@jomo@mstdn.io avatar

@kinnison @hisham_hm is the Sender Policy Framework, not "Sender Permitted From" and by design does nothing anything at all with the "From:" header. SPF only concerns the SMTP "MAIL FROM" line, which is not part of the actual email headers and thus is not and cannot be displayed by email clients. This is explicitly mentioned in the security considerations of the RFC: https://www.rfc-editor.org/rfc/rfc7208#section-11.2

1/3

jomo,
@jomo@mstdn.io avatar

@kinnison @hisham_hm does help against spoofing headers such as "From:", and the mail body. It comes with the major caveat (amongst others) that once leaked, you have no way* to plausibly deny authorship of emails. IIRC this has happened with Hillary Clinton's mails on Wikileaks.

*you can regularly rotate your signing keys and publish the old keys, however there does not seem to be a standard way of doing this.

2/3

jomo, (edited )
@jomo@mstdn.io avatar

@kinnison @hisham_hm There's also which instructs servers how to interpret the SPF and DKIM rules. The important part here is called "alignment", where the domain in the "From:" header must match that of the MAIL FROM line and the signer of the DKIM signature. Otherwise SPF/DKIM wouldn't protect against spoofers authenticating themselves. It's noteworthy that Microsoft does not refuse mails as instructed.

tl;dr: it's complicated and email is a mess.

3/3

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • tacticalgear
  • thenastyranch
  • ethstaker
  • everett
  • Durango
  • rosin
  • InstantRegret
  • DreamBathrooms
  • magazineikmin
  • Youngstown
  • mdbf
  • slotface
  • GTA5RPClips
  • kavyap
  • megavids
  • modclub
  • cisconetworking
  • cubers
  • ngwrru68w68
  • khanakhh
  • tester
  • anitta
  • normalnudes
  • Leos
  • osvaldo12
  • provamag3
  • JUstTest
  • lostlight
  • All magazines