Evaluation of SPF and DMARC extentions

Sending forged emails by taking advantage of domain spoofing is a common technique used by attackers. The lack of appropriate email anti-spoofing schemes or their misconfiguration lead to successful phishing attacks or spam dissemination. Here, we evaluate the adoption of the SPF and DMARC security extensions by domains and analyze spoofing possibilities enabled by the absence or misconfigurations of their rules.

We describe our findings in greater detail in the following publication:

