ietf-asrg
[Top] [All Lists]

Re: [Asrg] antiphishing idea

2011-11-17 17:28:13
Christian Grunfeld <christian(_dot_)grunfeld(_at_)gmail(_dot_)com> wrote:

sorry, I meant both of them ! you are obviously going to get the
validation from the evil domail but you also need one from phished
domain. The last one is only true if the mail was sent by paypal.com

No, it's true only if _any_ message was sent by paypal.com with that
Message-ID.  Copying a Message-ID isn't difficult, nor is getting
legitimate mail from paypal.

Seth
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg