Toot by Tim ApplebyTim Appleby (mastodon.stickbear.me)

I guess I'm doing OK. The last two weeks have been crazy because my mom's been in the hospital and I've been coordinating between people in multiple states who won't talk to each other, and then my uncle died suddenly last week which means more coordinating, so getting buried in the technicalities of email is kind of a nice change lol.

Toot by Tim ApplebyTim Appleby (mastodon.stickbear.me)

@FreakyFwoof @Bruce @jcsteh If the email is one character off from what it should be then that email from the misspelled email address is absolutely not legitimate. Email addresses must be typed correctly in order to either reach the intended recipient, or in this case, be sent from the proper domain if you're trying to pretend your a government or Google or Amazon or whoever. That part, at least, is part of the RFCs governing email.

Toot by Andre LouisAndre Louis (universeodon.com)

@carrottop1023 @Bruce @jcsteh Since about 2010 or so you cannot send mail via a domain's SMTP server without authenticating, authorizing, and in the case of mass sending services, ensuring the appropriate DNS records are in place at the domain level, unless you've specifically stood up your own server and turned all the authentication/authorization stuff off. So yes you can spoof an email address, but it's nowhere near as simple as spoofing a phone number, and it's also why you often see email addresses in the from field with a character off in either the username or the domain.