spf-discuss
[Top] [All Lists]

Re: phishing & MS MUAs

2004-06-06 23:24:49
On Mon, Jun 07, 2004 at 02:26:56PM +1000, Chris Drake wrote:
| MS MUA's hide the sender email address by default, so anyone is free
| to do this:-
| 
| MAIL FROM: spammer(_at_)spf+cid-compliant-evilhost(_dot_)com
| DATA
| From: "updates(_at_)microsoft(_dot_)com" 
<spammer(_at_)spf+cid-compliant-evilhost(_dot_)com>
| 
| etc...
| 
| so CID, as it currently stands, is (IMHO) pointless - or am I missing
| something?

Don't MS MUAs say

  From <sender-address> on behalf of <from-address>

?


<Prev in Thread] Current Thread [Next in Thread>