aboutsummaryrefslogtreecommitdiffstats
path: root/tests/fixtures/leaky.eml
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-09-08 16:28:14 +0200
committerDanilo M. <danix@danix.xyz>2026-09-08 16:28:14 +0200
commit92dba06905ded925bc78e4bac74989363aad62d7 (patch)
treea6c3492b6f8789b8317c6ecd7f36eac23b3778b0 /tests/fixtures/leaky.eml
parentfd8339703ccb99fccb95059996001f6734043655 (diff)
downloadabusectl-92dba06905ded925bc78e4bac74989363aad62d7.tar.gz
abusectl-92dba06905ded925bc78e4bac74989363aad62d7.zip
feat: flag an address spoofed into a display name
A display name naming a recognisable address is a deliberate act and a real signal, so it is reported rather than merely ignored once _domain_of() stopped mistaking it for the sender. The IOC carries no value. One of the identities an attacker impersonates is the recipient themselves, so publishing the impersonated domain would leak the recipient's own domain in exactly the case worth flagging. What travels is only that it happened; the reviewer has the message and can see who was impersonated, and a third party does not need to. display_name_addresses() still returns the full address for local review. Only the published IOC list is stripped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019NHaqA1Rz5ybed7wFUeQbK
Diffstat (limited to 'tests/fixtures/leaky.eml')
0 files changed, 0 insertions, 0 deletions