logo

20 Million Trusted Domains Vulnerable to Email Hosting Exploits

ID: 5ff1dd97-3e4e-521c-ac68-47b4b4d5794a

STIX ID: report--5ff1dd97-3e4e-521c-ac68-47b4b4d5794a

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-07-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers found three novel, chainable email attack techniques—SPF abuse, DKIM abuse via feedback loops, and an expanded SMTP smuggling variant—that exploit misconfigurations and RFC violations in email-hosting providers to bypass SPF/DKIM/DMARC and deliver spoofed emails from potentially millions of trusted domains; they will disclose affected vendors and detection/mitigation guidance (including Message-ID correlation and enforcing RFC authentication) at Black Hat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.