[FX.php List] [OFF] Sending php mail as anyone(?!)

Joel Shapiro jsfmp at earthlink.net
Thu Jul 31 00:41:43 MDT 2008


Hi all

I'm just starting to look at sending mail via php.  I'm successfully  
sending mail from my development machine via swiftmailer, but I'm  
kinda shocked that it's so easy to send email seemingly from just  
about *anybody's* email address.  Just put it in the 'sender'  
parameter and it arrives looking like it was actually sent by that  
person.

I know there are email blacklists, SMTP authentication, etc., but can  
it really be this simple to send as someone else?  (Is this  
"spoofing"?)  I mean, I could start posting 500-word replies to this  
list as ggt and none of you would even realize they weren't from him,  
right?  (all due respect, ggt ;-)

What am I missing?  Any recommended primers on this crazy scary new  
world?

TIA,
-Joel


More information about the FX.php_List mailing list