|
|
|
|
|
by upofadown
1597 days ago
|
|
Anyone that runs a mail server can generate emails with any "From:" address they want with a valid DKIM. The SPF works on the envelope address, not the "From:" address. The actual complaint here is that mailbox.org is not policing the "From:" address and thus are providing such an ability to people that have not bothered to spin up a mail server on a domain they control. Yeah, banks should sign their emails. I think that even Facebook does this if you give them a public key. |
|
E: by valid I meant valid and aligned (according to DMARC), sorry