Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Isn’t this basically what SPF, DKIM and SMTP over TLS get you? Sure you can try to forge messages but they should bounce immediately and not even reach the recipients inbox.


I’m not an expert... but From what I can tell no one trusts anyone’s email anymore and even as we added these new security things.. we didn’t start trusting any more than we did before... Consequences being that even with the extra security, trying to run your own mail server and get email recipients to receive the mail you send is like being some kind of extremely polite red team, on the offensive in the worlds longest least organised capture the flag.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: