|
|
|
|
|
by jmillikin
1471 days ago
|
|
The message has been forged, as can be observed from the From: header being a domain that the sending server was not authorized to send from. Whether a subset of the message -- in this case the body -- is authentic doesn't matter. If I were to MITM google.com and send back an archived snapshot from a month ago, that would be forged traffic even if it matches responses that Google had once sent. |
|