Feb. 19, 2024, 3:43 p.m. | /u/Copper_Mind

cybersecurity www.reddit.com

Years ago and read and understand the concepts of spf, dkim, and dmarc. over the past few months, i've been setting up spf/dkim for the allowed senders we know about. But I read something recently that made me thing: DMARC is based on the envelope FROM address...

So if a bad actor was only header FROM spoofing, assuming the envelope from is legit and configured, that emails could come in as passing DMARC. When googling multiple sources referenced that SPF/DKIM …

actor address bad concepts cybersecurity dkim dmarc spf understand

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Network Security Engineer

@ Meta | Menlo Park, CA | Remote, US

Security Engineer, Investigations - i3

@ Meta | Washington, DC

Threat Investigator- Security Analyst

@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC

Security Operations Engineer II

@ Microsoft | Redmond, Washington, United States

Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas

@ Goldman Sachs | Dallas, Texas, United States