Hacker News new | ask | show | jobs
by 3am 4120 days ago
Hah! Try spoofing an email to a recipient in the State Dept and tell me how it works out :)
1 comments

Find me someone in the State Department willing to be the recipient and I will happily conduct this experiment. Why do you think it would be any harder to spoof an email to the State Dept than anywhere else?
http://mxtoolbox.com/SuperTool.aspx?action=spf%3astate.gov&r....

"No SPF records found"

Looks pretty spoofable.

SPF only validates the envelope, not the From header. To do that you need DKIM, and I'd be surprised if Dept of State has implemented that.