You can, technically, write anything in it and there’s no way to guarantee it’s authentic.
You can, technically, write anything in it and there’s no way to guarantee it’s authentic.
For example here are some headers from some spam I received:
From: "Jeremy Adamson" <jeremyadamson@illusion24.com>
Reply-To: "Jeremy Adamson" <jeremyadamsonr@yahoo.com>
From: is what I see in my client and Reply-To: is where a reply would go to.This one is much better, note how I'm BCCd and To: is complete bollocks:
Reply-To: dr.ahmed.faruk@outlook.com
From: Dr Faruk Ahmed <dr.faruk.ahmed1@gmail.com>
Subject: MANAGER AUDIT AND ACCOUNT DEPT
To: undisclosed-recipients:;
BCC: <gerdesj@blueloop.net>
Return-Path: dr.faruk.ahmed1@gmail.com
Given that Reply-To and Return-Path are in different domains, where would a reply go to?Basically a large registry. When I call someone I tell t-mobile who I'm calling, and they register it. Then on the receiving end Verizon checks with T-mobile or a central registry, and says yep James's number is calling this number. Then it marks it as a verified call.
There are lots of good things that telephony could be required to do but they are not and they wont.
This leads down a privacy/metadata rabbit hole, but there are probably ways to make this a lot better. In any case, the phone OS can do some out-of-band signaling and just avoid dealing with the carriers altogether.
Although if you're doing all that then why not just make a call using voip...