Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Chances of com1000 being delegated is low.


Why would it need to be designed? Email delivery depends on DNS, which is unencrypted and spoofable. Spoofing emails is also doable.


If the dns lookup on a com1000 domain fails, the email won’t go anywhere.


Correct. But if a DNS response for that domain is spoofed. It will.

DNS is a very old protocol that still has lots of problems and mitigations like DNSSEC are only partially deployed.


Email is an inherently insecure medium. If an attacker can compromise the DNS responses for your mail server, you're hosed.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: