Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does it matter if it's an internal address? Any address can be spoofed and some internal addresses could have leaked.

I wouldn't attach any value to the address even with SPF and DCIM, which are often mis-configured.




If GoDaddy are misconfiguring their DKIM records they’ve got bigger problems.


The apex phishing e-mail is indistinguishable from a legitimate e-mail, except by SPF/DKIM. After all, the apex phishing e-mail is based on a byte-for-byte copy of a legitimate e-mail.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: