Hacker News new | ask | show | jobs
by freddieleeman 1547 days ago
A spoofed message should FAIL DMARC. It could PASS DKIM and if the signature came from a domain that is owned by the attacker. But DMARC will fail when the DKIM domain and the HEADER.FROM domain do not align.

Please read my blog here: https://www.uriports.com/blog/introduction-to-spf-dkim-and-d...

It will explain how SPF, DKIM, and DMARC work together to prevent spam.