Hacker News new | ask | show | jobs
by gus_massa 2796 days ago
I agree. A few (10? 20?) years ago it was very easy to spoof email and send an email "from" mickey@disney.com if you wish. The original email specification has almost no security features. Now, most of the email servers will sign the outgoing email, and if you receive an email with the signature gmail and others big webmail providers will show a big warning.

So, to understand the problem it is very important to get a copy of all the complete emails with all the hidden headers that have the automatic signatures of the servers the email passed through. (See https://www.google.com/search?q=email+headers )

With the emails headers it is posible to see if your server was hacked or if the sender field was spoofed.