I got a scam email today with the from address looked something like this:
From: “amendes.gouv.fr” antai-amendes-gouv-infractions-agence-nationale-traitement-automatise-infractions-confirmation-dossier-12345678-1234-1234-1234567812345678-13456789-1234-1234-1234567812345678-12345678-1234-1234-12345678@oglix.ba
The very long domain name makes K9 not show the domain name and only the domain name in the quotes. (It looks suspicious with just a domain name in there without a user but leave that aside for a moment).
K9 shows the string in the quotes and if it looked like an email address one could be easily confused. Even clicking the address makes it look like it was the address since the domain name was so long.
Some possible recommendations to help the user spot a fake:
- The domain name is clearly invalid in both the reply-to and from field. It contains a domain component that is longer than 63 characters (but it is less than the maximum of 253)
- The domain name or even a user@domain.name in the quotes is highly suspicious, not actually invalid but I have only seen this in scams.
- The from field being so long that when it’s presented to the user in the UI it overflows/wraps in a way which it starts to look like the text name (what should be in the quotes) and not the email address.
You could argue that this should really be done in the anti-spam software and yes it should, but what I am worried about here are things that specifically K9 makes it more difficult to spot because it runs on a phone where the screen real estate is limited and things wrap and this causes a confusing situation. It would be good if K9 could present some sort of warning when it presents this confusing looking stuff. Or in cases like this, not hide the address behind the name it became much more a red-flag to the user.