There seems to be a view in some comments that being able to spoof From: is a Good Thing.
I challenge that. It facilitates all sorts of crime and what's possibly worse is that business who "legitimately" make use of this are training their correspondents to be phished.
Take a typical phishing email:
- The From: field claims it came from some bank.
- Examination of the headers shows that it came from elsewhere
- It has a link to an image of the bank's logo - probably a genuine link as an image of the bank's logo isn't difficult to find on the bank's website
- One or more links in the body of the email that appear to point to the bank's web site but on closer examination point elsewhere. The object of the email is to get the victim to click on one of these.
Now take a typical outsourced valuable marketing message spam from a bank:
- The From: field claims it came from the bank.
- Examination of the headers shows that it came from elsewhere
- It has a link to an image of the bank's logo
- One or more links in the body of the email that appear to point to the bank's website but on closer examination point elsewhere (this is my experience - they use a sub-domain of the bank but it resolves to the digital marketing spamming company). The object of the email is to get the victim to click on one of these.
The result is that the genuine article authorised spam looks exactly like a booby-trapped phishing spam. The wary will treat the two alike and ignore the bank. The unwary will treat the two alike and get phished. It's time this was stopped. If, as a by-product, it stops banks and other businesses spamming the public nothing of value will be lost.