Forward Pass: On the Security Implications of Email Forwarding Mechanism and Policy

02/14/2023
by   Enze Liu, et al.
0

The critical role played by email has led to a range of extension protocols (e.g., SPF, DKIM, DMARC) designed to protect against the spoofing of email sender domains. These protocols are complex as is, but are further complicated by automated email forwarding – used by individual users to manage multiple accounts and by mailing lists to redistribute messages. In this paper, we explore how such email forwarding and its implementations can break the implicit assumptions in widely deployed anti-spoofing protocols. Using large-scale empirical measurements of 20 email forwarding services (16 leading email providers and four popular mailing list services), we identify a range of security issues rooted in forwarding behavior and show how they can be combined to reliably evade existing anti-spoofing controls. We show how this allows attackers to not only deliver spoofed email messages to prominent email providers (e.g., Gmail, Microsoft Outlook, and Zoho), but also reliably spoof email on behalf of tens of thousands of popular domains including sensitive domains used by organizations in government (e.g., state.gov), finance (e.g., transunion.com), law (e.g., perkinscoie.com) and news (e.g., washingtonpost.com) among others.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/17/2017

Towards the Adoption of Anti-spoofing Protocols for Email Systems

Email spoofing is a critical step of phishing, where the attacker impers...
research
01/02/2018

Revisiting Email Spoofing Attacks

The email system is the central battleground against phishing and social...
research
11/17/2020

Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks

As a fundamental communicative service, email is playing an important ro...
research
07/24/2020

CelebA-Spoof: Large-Scale Face Anti-Spoofing Dataset with Rich Annotations

As facial interaction systems are prevalently deployed, security and rel...
research
11/25/2020

Whac-A-Mole: Six Years of DNS Spoofing

DNS is important in nearly all interactions on the Internet. All large D...
research
04/12/2019

KeyForge: Mitigating Email Breaches with Forward-Forgeable Signatures

Email breaches are commonplace, and they expose a wealth of personal, bu...
research
03/10/2021

Anti-Counterfeiting for Polymer Banknotes Based on Polymer Substrate Fingerprinting

Polymer banknotes are the trend for printed currency and have been adopt...

Please sign up or login with your details

Forgot password? Click here to reset