4 ms·
An attacker-controlled domain, say snaapchat.com, can pass DKIM, SPF, and DMARC if configured appropriately.
by tshtf 11y ago
An attacker-controlled domain, say snaapchat.com, can pass DKIM, SPF, and DMARC if configured appropriately.
- eli 11y agoBetter solution is to append a warning to any message that originates outside the domain.
- jcrawfordor 11y agoThis is actually a really good idea in corporate environments, and I would encourage everyone to think about doing it. It is a simple thing to push a rule to Outlook that e.g. displays emails from outside the corporate domain with a red tinted background in the email list. This helps people to think twice. It also compliments an email classification system well, although unfortunately most classification systems I've seen with good MUA integration are very expensive.