Novel SMTP Smuggling Technique Slips Past DMARC, Email Protections

Novel SMTP Smuggling Technique Slips Past DMARC, Email Protections

A novel way to abuse a decades-old protocol used to send emails since the beginning of the Internet allows attackers to evade Domain-based Message Authentication, Reporting and Conformance (DMARC) and other email protections, putting organizations and individuals at risk for...
SMTP smuggling enables email spoofing while passing security checks

SMTP smuggling enables email spoofing while passing security checks

SEC Consult Longin identified two big email providers whose SMTP servers interpreted . as the end of data: Fastmail and Runbox. However, he also found that popular SMTP server software like Postfix and Sendmail were also accepting this end-of-data sequence...