Hacker News new | ask | show | jobs
by cjbprime 3531 days ago
How do you know they were from FitBit, rather than from a spammer with their From address set to FitBit?
1 comments

good question - i believe the email address was Fitbit but will confirm
Ah, sounds like you don't know about from addresses: they are specified by the sender, and not authenticated. A spammer can send email that appears to be from anyone else, until you look at the validated headers (like "Return-path:").