How an AiTM Phishing Attack Cleared SPF, DKIM, and MFA

How an AiTM Phishing Attack Cleared SPF, DKIM, and MFA

At a glance A phishing domain was registered at 18:23 UTC and used twelve minutes later – inside the window before any reputation feed can issue a verdict The email cleared SPF and DKIM legitimately, because the attacker sent it through a real compromised account on a...