5 ms·
It's likely that their SMTP server accepts messages with an SMTP "MAIL FROM" command and/or "From" header address that belongs to the company's own domain witho
by developer2 11y ago
It's likely that their SMTP server accepts messages with an SMTP "MAIL FROM" command and/or "From" header address that belongs to the company's own domain without requiring authentication. The attacker then adds a "Reply-To" header so that replies will be sent elsewhere (likely a throwaway free email account).
This shows up in email clients as "From: legit.name@example.com". When the recipient replies, they don't notice that they're sending a reply to a different address than the one their client claimed was the sender of the original message.
Receiving SMTP servers need to be configured to require SMTP authentication for messages claiming to originate from the company's own domain.
- noinsight 11y ago> Receiving SMTP servers need to be hardened to require SMTP authentication for messages claiming to originate from the company's own domain. Or validate SPF / DKIM and enable it for their own domain.