Office Awareness with Phishing Training

Free preview: Lesson 6 of 19 from the online course “Office Awareness with Phishing Training”, exactly as participants see it.

All lessons

The sender – whom can you trust?

What to expect

Why the sender of an email proves nothing: a live demo shows how any sender can be faked with just a few commands.

The video in brief

Why the sender proves nothing: in a live demo, Patrick shows how any sender can be faked with a few commands via Telnet using the SMTP protocol. An email is therefore not signed, sealed post, but more like an open postcard, forgeable and readable in transit.

Now that we know how an email travels across the internet, we come to the first big pitfall: how does the recipient actually know who the sender really is?

The sobering answer: not with any certainty. The receiving mail server has to accept the email and the sender address it contains, even if that address is completely made up.

Faking a sender takes just a few commands

The live demo in the video shows how this can be exploited. With the simple tool Telnet, you open a text-based connection to an SMTP mail server and run a few commands in sequence:

  • The server greets you with a HELO and gives its name.
  • You specify the sender (MAIL FROM) and the recipient (RCPT TO); the server confirms each successful command with 250.
  • DATA is followed by the actual message, including subject and text; it is ended with a single full stop.

Done, and an email lands in the inbox whose sender and content are completely made up.

Remember

The displayed sender of an email is no proof. It can be faked in a few steps. Unfortunately, a great many mail servers still simply accept everything.

The fitting comparison

Email is often called “electronic mail”, as if it were a sealed, signed letter with a postmark. It is not.

  • A letter is sealed and carries a postmark and a signature that confirm the sender.
  • An email can be forged in sender and content, read along the entire route and even altered.
Good to know

An email is therefore more like a typewritten postcard lying open in the letterbox for anyone to read. With the help of the servers involved, and usually only by court order, it is possible to trace afterwards whether an email is genuine. As users, however, we cannot do that; we have to trust the content as long as the email carries no special verification features. And those are missing in the standard.

Quiz question

How do you check whether a sender address is trustworthy?

More than one answer may be correct.

Like what you see?

The full course has 19 lessons like this one. At the end, everyone receives a certificate of participation with a verification number.

See prices Another free preview: Phishing attacks exploit psychology

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first