Skip to content
tag — spf

grep -rl "spf" ./articles

#spf

1 article

Apple's own servers signed the forged sender, and SPF, DKIM and DMARC all passed because they were working correctly

2026-10-03Security

SEC Consult's Timo Longin found two parsing flaws in Apple's iCloud mail pipeline that let a free account send mail appearing to come from any address at icloud.com. The spoofed messages passed every authentication check, because the forgery happened upstream of the point where Apple signs. Reported in May 2024, fully fixed in December 2025, published on 1 October 2026.