Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"It depends"

There is a sister standard to DKIM called DMARC that lets a domain publish instructions for what to do if unsigned emails are received. It can run in allow, report and deny mode. Report is useful, it asks the recipient to send it back to the domain which is helpful for large networks that may have many people and services sending mail on their behalf.

You can use this tool to compare gmail.com (ignore failed signatures) vs google.com (reject)

https://dmarcian.com/dmarc-inspector/

Thus google.com i.e. Google employee / service email is protected from From header forgery, but consumer Gmail isn't (too many people sending mail from non-Google SMTP servers).



It's worth noting that ignore/report is for the email server it's destined for. The server is supposed to send reports back to google (mailauth-reports@google.com specifically) about the failures and such.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: