The critical role played by email has led to a range of extension protocols (e.g., SPF, DKIM, DMARC) designed to protect against the spoofing of email sender domains. These protocols are complex as is, but are further complicated by automated email forwarding -- used by individual users to manage multiple accounts and by mailing lists to redistribute messages. In this paper, we explore how such email forwarding and its implementations can break the implicit assumptions in widely deployed anti-spoofing protocols. Using large-scale empirical measurements of 20 email forwarding services (16 leading email providers and four popular mailing list services), we identify a range of security issues rooted in forwarding behavior and show how they can be combined to reliably evade existing anti-spoofing controls. We show how this allows attackers to not only deliver spoofed email messages to prominent email providers (e.g., Gmail, Microsoft Outlook, and Zoho), but also reliably spoof email on behalf of tens of thousands of popular domains including sensitive domains used by organizations in government (e.g., state.gov), finance (e.g., transunion.com), law (e.g., perkinscoie.com) and news (e.g., washingtonpost.com) among others.
翻译:摘要:电子邮件在通信中的关键作用催生了SPF、DKIM、DMARC等一系列扩展协议,旨在防止发件人域名伪造。这些协议本身已相当复杂,而自动邮件转发机制——用户用于管理多账户、邮件列表用于消息分发——进一步增加了其复杂性。本文探究了邮件转发及其实现方式如何破坏当前广泛部署的反欺骗协议中的隐含假设。通过对20个邮件转发服务(包括16家主流邮件提供商和4个常用邮件列表服务)的大规模实测,我们识别了一系列根植于转发行为的安全问题,并揭示了如何组合利用这些问题可靠地绕过现有反欺骗机制。研究显示,攻击者不仅能向Gmail、Microsoft Outlook、Zoho等知名邮件服务商投递伪造邮件,还能假冒数以万计的流行域名实施可靠欺骗,这些域名涵盖政府(如state.gov)、金融(如transunion.com)、法律(如perkinscoie.com)及新闻(如washingtonpost.com)等敏感领域。