You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何仿冒全部Gmail邮件头时,Yahoo签名的DKIM验证仍能通过?

Analysis of a Phishing Email I Received Today

Here's a breakdown of my findings after examining the phishing email:

  • Header Mismatch: The From, Reply-To, and Return-Path headers all display a Gmail address, but the actual sender originates from Yahoo.
  • Server & IP Details:
    • The HELO identifier is linked to Yahoo
    • The IP address in the Received header has consistent forward and reverse DNS resolution
  • Email Authentication Results:
    • The email carries a valid DKIM signature for yahoo.com
    • SPF resulted in a soft fail because the sending IP belongs to Yahoo, which doesn't align with Gmail's SPF policy
  • Confusing Test Outcome: When I ran the opendkim-testmsg tool to analyze this email, it returned a "normal" result. This has me totally stumped—how can a clearly deceptive email pass this DKIM check without any flags?

内容的提问来源于stack exchange,提问作者jornane

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:41:54