• MysteriousSophon21@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 months ago

    SPF won’t help here because the attack specifically uses legitimate sending infrastructure - they’re forwarding through a compromised Google Workspace account so the SPF check passes, while reusing a valid DKIM signature from a diferent message.