Comment on How do email scammers spoof my email?

<- View Parent
Ocelot@lemmies.world ⁨1⁩ ⁨year⁩ ago

This isn’t really going to be accurate all the time. It is a totally reasonable configuration to use a mailserver not in the MX records. Lots of companies that send automated emails use a service like mailgun or sendgrid as a relay, which isn’t their MX server. It doesn’t come from their company’s mailserver. The only way to validate that is by adding mailgun/sendgrid as an include in the SPF record.

You’ll often miss things like “Your credit card expired” or “please change your password” or even “Here’s your monthly bill from the power company” emails.

source
Sort:hotnewtop