The sender – whom can you trust?
Why the sender of an email proves nothing: a live demo shows how any sender can be faked with just a few commands.
Why the sender proves nothing: in a live demo, Patrick shows how any sender can be faked with a few commands via Telnet using the SMTP protocol. An email is therefore not signed, sealed post, but more like an open postcard, forgeable and readable in transit.
Now that we know how an email travels across the internet, we come to the first big pitfall: how does the recipient actually know who the sender really is?
The sobering answer: not with any certainty. The receiving mail server has to accept the email and the sender address it contains, even if that address is completely made up.
Faking a sender takes just a few commands
The live demo in the video shows how this can be exploited. With the simple tool Telnet, you open a text-based connection to an SMTP mail server and run a few commands in sequence:
- The server greets you with a
HELOand gives its name. - You specify the sender (
MAIL FROM) and the recipient (RCPT TO); the server confirms each successful command with250. DATAis followed by the actual message, including subject and text; it is ended with a single full stop.
Done, and an email lands in the inbox whose sender and content are completely made up.
The displayed sender of an email is no proof. It can be faked in a few steps. Unfortunately, a great many mail servers still simply accept everything.
The fitting comparison
Email is often called “electronic mail”, as if it were a sealed, signed letter with a postmark. It is not.
- A letter is sealed and carries a postmark and a signature that confirm the sender.
- An email can be forged in sender and content, read along the entire route and even altered.
An email is therefore more like a typewritten postcard lying open in the letterbox for anyone to read. With the help of the servers involved, and usually only by court order, it is possible to trace afterwards whether an email is genuine. As users, however, we cannot do that; we have to trust the content as long as the email carries no special verification features. And those are missing in the standard.
How do you check whether a sender address is trustworthy?
More than one answer may be correct.
The displayed name can be faked freely. What counts is the real address behind it – and whether the domain matches exactly or only looks deceptively similar.