Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

external destination verification and report aggregation missing in DMARC reporting #232

Open
Ashiq5 opened this issue Jan 2, 2023 · 0 comments

Comments

@Ashiq5
Copy link

Ashiq5 commented Jan 2, 2023

I am using the latest version of OpenDMARC and while playing with DMARC reporting, I came across a few issues that could raise opportunities for attackers to exploit.

  1. There is no verification check if an external email address is specified in the rua tag of the sender's DMARC record. RFC recommends a verification strategy as defined here (https://datatracker.ietf.org/doc/html/rfc7489#section-7.1).
  2. If multiple emails come from the same organizational domain, OpenDMARC shoots out separate reports for each received email even if the rua addresses are the same. This with the absence of an external destination verification mechanism can open up an opportunity for the attackers to flood any mailbox they want. Therefore, reports for the same organizational domain within the same reporting window should be aggregated.

Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant