Forwarding can break email authentication assumptions
Forwarding an email frequently breaks the authentication that proved where it came from.
The forwarding server becomes the sender, which breaks the path check, and some forwarders modify the message, which breaks the signature. Mailing lists do both routinely. It is why strict enforcement policies cause collateral damage, and why the protocols have extensions specifically to survive it.
More on Email security
- DKIM protects signed content against later modificationChange one word, break the seal
- DMARC depends on alignmentBoth names, or neither
- A display name is not an email addressThey wrote that name themselves
- Reply-chain hijacking borrows existing trustTrust borrowed from the thread
- Secure email gateways see only traffic that reaches themIt only sees what comes past it
- Quarantine creates a second security decisionHeld is not decided
