Hacker News new | past | comments | ask | show | jobs | submit login

An attacker-controlled domain, say snaapchat.com, can pass DKIM, SPF, and DMARC if configured appropriately.



Better solution is to append a warning to any message that originates outside the domain.


This is actually a really good idea in corporate environments, and I would encourage everyone to think about doing it. It is a simple thing to push a rule to Outlook that e.g. displays emails from outside the corporate domain with a red tinted background in the email list. This helps people to think twice. It also compliments an email classification system well, although unfortunately most classification systems I've seen with good MUA integration are very expensive.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: