Hacker News new | ask | show | jobs
by necovek 1418 days ago
When you are suspicious of any incoming emails, look for "received from" lines in SMTP envelope (not in the header fields which are trivially forgeable): as soon as email hits a normal server, it can't be forged anymore, and a relaying/delivering server will insert the actual header.

If there is no apple.com mail server in the sequence of received-from lines, it's not a valid email.

If there is, it should be valid or their MX servers are compromised.

Regardless, always browse yourself to wherever you need to update any banking info or personal data.

1 comments

Indeed. The first thing I did was close the email and log into my account, but couldn't find any warnings there. I've sent a support message to Apple as well asking what's up with this email.