spf-discuss
[Top] [All Lists]

No use of checking RFC2822 headers

2004-09-28 00:43:00
What is the use of checking the mailbox addresses in the RFC2822 header if
Microsoft's Outlook Express does not display any of these addresses?

To see how useless this is, copy following message into the file test.eml
and open it with Microsoft's Outlook Express

------snip-------
From: "support(_at_)bankofamerica(_dot_)com" <phish(_at_)phisher(_dot_)com>
To: you(_at_)example(_dot_)com
Subject: Account verification
MIME-Version: 1.0
Content-Type: text/html

<html><body>
Click here:
<a href="http://www.phisher.com";>https://www.bankofamerica.com</a>
</body></html>
------snip-------

BTW. Don't think that www.phisher.com cannot write
"https://www.bankofamerica.com"; into the address bar of Microsoft's Internet
Explorer. (I have recently seen that this is possible).

Roger