Video: https://www.youtube.com/watch?v=eyuOD6FZO-4
Emails are still the most widespread way to get information about subscriptions and important public services, it is then critical for both users and providers to have a secure way to distinguish between genuine and malicious messages.
To do so, two main standards are currently adopted: SPF and DMARC. This talk shows how they can be circumvented and describes a case study that allowed to elude them in all office 365 email domains.
The session details how to detect attack windows for such bypasses and how to protect against the aggression vectors described.