There was a quite lengthy discussion about this in their forum but they deleted it since. They refused to fix it. Archive.org still has it. Content is in German (sorry):
https://web.archive.org/web/20210123192856/https://userforum...
Surely they'll only allow that if they pass the auth and the domain belongs to your account?
Fixing this would only affect users who send emails "from" other users email addresses, basically users who commit fraud.
I also don’t fully understand the reasoning. Having an open SMTP server that doesn’t restrict senders is one thing, but attaching DKIM without further checks is another.
What they said in the forum doesn't make much sense. Yes, anyone in the wold can send emails with any address as "from". The big difference is that those emails won't pass SPF and DMARC checks.
If I wanted to use them, I would need to configure SPF and DMARC for my domain so that their mail servers pass those checks. At this point I would expect their mail servers only to allow sending "from" my domain when my account is used.
Note that just about any major mail provider does this check (e.g. Google). It is industry standard. It is crazy that they even refuse to acknowledge this. I'm working in this field and this is basic knowledge. I just don't get how they can do this professionally and not understand what the problem is. The only explanation I have is that for some reason it would be hard for them to fix and so they try to ignore it / make it disappear by deleting the forum thread.
Also they use the same DMARC key for all customers, which is weird. Usually each customer gets it's own DMARC key.
It seems this issue was acknowledged 2 years ago: https://userforum-en.mailbox.org/topic/anti-spoofing-for-cus...
Edit: re the shared keys you mentioned I agree. If they had per-user DKIM keys that were only usable after successful SMTP authentication (e.g. by encrypting them with credentials) that would solve the DKIM part of the issue AND even further improve the situation.
Does mailbox.org even include the "From:" address in the DKIM signature?
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:content-type:content-type;According to the spec, the “From:” field must be included in every DKIM signature.
If an email is sent with a From of @bob.com and DKIM signed using the private key for bob.com…it’s from bob.com.
Like you said: SPF and DMARC only authenticate the server. It's up to the server to authenticate the user.
Scenario: imagine your bank uses Mailbox.org to send emails. How would you verify that an email is legit? Any Mailbox user can send emails through Mailbox with your bank as "from" and all of these emails pass SPF and DKIM checks. Your mail server has no way to distinct a legit email from a fake one. This is why it's important that the server does this check (check that sender account and "from" match / are a valid combination).
The actual complaint here is that mailbox.org is not policing the "From:" address and thus are providing such an ability to people that have not bothered to spin up a mail server on a domain they control.
Yeah, banks should sign their emails. I think that even Facebook does this if you give them a public key.
E: by valid I meant valid and aligned (according to DMARC), sorry
I now think that the DMARC stuff is a red herring and would actually help make the current mailbox.org behaviour not all that problematic (they specify "reject" in their DMARC policy). The actual point of dispute is the lack of enforcement of the "From:" address domain.
Mailbox.org’s servers have access to 4 private keys as far as I know. These (I mean the matching public keys) are stated in mailbox.org’s DNS records. If you send from an @mailbox.org address you trust mailbox.org to do checking on the Header-From when signing it, as you have no control over which keys you state in DNS. This is the same situation as for any mail provider with a shared domain.
What’s even worse, when using mailbox.org with a custom domain they will have you state the exact same 4 keys in your domain’s DNS records for DKIM to work. There is no way to upload custom keys. So even someone with a custom domain has to trust mailbox.org to not sign strangers’ e-mails.
Added: Wait, how would that even work? You need to generate your own DKIM key.
If anybody realizes you’re using that service they can immediately impersonate you.
Please name even a single major mail provider that allows to send emails with arbitrary "from" headers.
https://datatracker.ietf.org/doc/html/rfc7208 https://datatracker.ietf.org/doc/html/rfc7489