• A_norny_mousse@feddit.org
    link
    fedilink
    English
    arrow-up
    6
    ·
    12 days ago

    I stopped reading when I realised the publisher is a company that sells a product that fixes the supposed problem.

    Maybe this is a thing, maybe it isn’t, but I don’t have the resources to go on reading and analyze it.

  • girsaysdoom@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    11 days ago

    Even if they could reuse a DKIM hash on an email (pretty sure this is unique per email and would fail on a legitimate check), SPF would show its obviously not from Google. So just make sure your email server correctly handles DKIM verification and blocks SPF hard fails, and you’re probably good against this.

    • MysteriousSophon21@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 days ago

      SPF won’t help here because the attack specifically uses legitimate sending infrastructure - they’re forwarding through a compromised Google Workspace account so the SPF check passes, while reusing a valid DKIM signature from a diferent message.