Authenticated email can still be malicious
All the authentication proves is that the message genuinely came from the domain it claims.
A criminal who registers a domain can configure all of it correctly, and mail from a compromised legitimate account passes everything by definition. Authentication answers who sent this, which is useful and is not the same question as whether to trust it.
More on Email security
- DKIM protects signed content against later modificationChange one word, break the seal
- DMARC depends on alignmentBoth names, or neither
- Forwarding can break email authentication assumptionsIt was re-posted on the way
- A display name is not an email addressThey wrote that name themselves
- Reply-chain hijacking borrows existing trustTrust borrowed from the thread
- Secure email gateways see only traffic that reaches themIt only sees what comes past it
