|
|
|
|
|
by nickphx
1076 days ago
|
|
If you look at the headers of email originating from mailgun, you will notice several headers they've added that include unique identifiers that identify the sending account and recipient. ESPs receive FBLs/ARF from email providers through various delivery methods, "webhooks", ARF via SMTP.. So to pull off an attack someone would need to generate matching identifiers and know where to deliver the ARF with the forged data.. |
|