为何仿冒全部Gmail邮件头时,Yahoo签名的DKIM验证仍能通过?
Analysis of a Phishing Email I Received Today
Here's a breakdown of my findings after examining the phishing email:
- Header Mismatch: The
From,Reply-To, andReturn-Pathheaders all display a Gmail address, but the actual sender originates from Yahoo. - Server & IP Details:
- The HELO identifier is linked to Yahoo
- The IP address in the
Receivedheader has consistent forward and reverse DNS resolution
- Email Authentication Results:
- The email carries a valid DKIM signature for
yahoo.com - SPF resulted in a soft fail because the sending IP belongs to Yahoo, which doesn't align with Gmail's SPF policy
- The email carries a valid DKIM signature for
- Confusing Test Outcome: When I ran the
opendkim-testmsgtool to analyze this email, it returned a "normal" result. This has me totally stumped—how can a clearly deceptive email pass this DKIM check without any flags?
内容的提问来源于stack exchange,提问作者jornane
相关产品推荐
相关产品推荐

