diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-08 16:28:14 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-08 16:28:14 +0200 |
| commit | 92dba06905ded925bc78e4bac74989363aad62d7 (patch) | |
| tree | a6c3492b6f8789b8317c6ecd7f36eac23b3778b0 /LICENSE | |
| parent | fd8339703ccb99fccb95059996001f6734043655 (diff) | |
| download | abusectl-92dba06905ded925bc78e4bac74989363aad62d7.tar.gz abusectl-92dba06905ded925bc78e4bac74989363aad62d7.zip | |
feat: flag an address spoofed into a display name
A display name naming a recognisable address is a deliberate act and a
real signal, so it is reported rather than merely ignored once
_domain_of() stopped mistaking it for the sender.
The IOC carries no value. One of the identities an attacker impersonates
is the recipient themselves, so publishing the impersonated domain would
leak the recipient's own domain in exactly the case worth flagging. What
travels is only that it happened; the reviewer has the message and can
see who was impersonated, and a third party does not need to.
display_name_addresses() still returns the full address for local review.
Only the published IOC list is stripped.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019NHaqA1Rz5ybed7wFUeQbK
Diffstat (limited to 'LICENSE')
0 files changed, 0 insertions, 0 deletions
