1

Topic: Sender address verification

==== Required information ====
- iRedMail version (check /etc/iredmail-release): 0.9.6
====

Hi, I just noticed that when I send mail, sender address is not verified. Any valid user account is able to send mail from any other user account. I realize that the email protocol doesn't have sender verification, but we have SPF, DKIM, etc. for that. This ability to spoof sending addresses somewhat defeats the purpose of having those protocols in the first place. I think sender addresses should be verified.

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Sender address verification

SPF allow other to see what server are alow todo things with your domain.
DKIM sign the domain with a key that can be compared.

If you want more you need pgp or a real personnal certificat.
Email are not made to be unspoofable.