Post
Topic
Board Meta
Re: Anyone else got this email from Bitcointalk.org?
by
CaptainHerpDerp
on 18/03/2015, 11:41:06 UTC
but it looked legit as it had the address noreply@bitcointalk.org

FYI, unless the (alleged) sender's domain has got SPF records and your mail server implements it, anyone can just change his 'From:' address to whatever he wants just by going to 'Settings...' in the mail client.

Actually bitcointalk.org *does* have an SPF record protecting it with a strict (-all) policy: according to standards, the phishing message should have been rejected, but your mail server probably doesn't enforce the requested policy. Funny thing is that a domain such as 'whitehouse.gov' uses a relaxed policy (~all), so phishing e-mails from 'whitehouse.gov' would en up in your spam folder at best Wink

Damn them all to hell!!  Grin oh well no harm done on this occasion, I'll probably get my dinner invitation to the whitehouse a bit later on  Tongue