6 ms·
That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistake
by edelbitter 3d ago
That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find one suitably dangling DNS delegation to score a "…@attacker-controlled-subdomain.legitimate.example" mailbox. The sender would not be able to prevent this.. unless its regulatory oversight body is very patient about repeatedly delaying legitimate requests for seemingly-minuscule formal defects.
(Mentioning just for context. Probably not the mechanism at play here, Revolut would have tried to shift blame in the press release if it was.)