Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've long wondered if you could put crypto into this, to make it secure from a human attacker who might figure out the scheme. Otherwise it is relatively easy for a spammer to replace foobar.com with google.com and email you again, escaping your filtering and/or making you think google.com has a data leak.

For example, using a HMAC of the domain. So you generate foobar.com-sr32j4@mydomain.com, it's impossible to generate the sr32j4 part without knowing your secret key, and your mail server checks that sr32j4 is correct before accepting the mail.



Interesting idea, I like it. I am not profficient enough with mail servers to know how this could be done, but maybe a python script that just marks offending mails as spam would work as well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: