Apple recently patched two serious email spoofing vulnerabilities in its iCloud Mail system that allowed users with free iCloud accounts to impersonate any @icloud.com address—even those belonging to high-profile identities. The flaw enabled spoofed emails to pass crucial sender-validation checks including SPF, DKIM, and DMARC, thanks to inconsistent parsing of message headers.
How the Spoofing Worked
The issue stemmed from the way Apple’s SMTP (Simple Mail Transfer Protocol) infrastructure processed email headers. Researchers found that malformed From: headers—specifically ones using unusual carriage return characters—were handled differently by separate internal parsers. One parser failed to treat the manipulated field as a sender header during authentication, while another later cleaned it up, leaving a valid-looking sender address for the recipient’s mail server. This allowed the visible sender to be changed without triggering rejection.
A second attack involved violating SMTP “dot-stuffing” rules—standards that handle lines beginning with periods. In this case again, different parts of the pipeline parsed messages differently, letting malicious senders survive scrutiny and make emails appear legitimately from any @icloud.com user.
Why SPF, DKIM & DMARC Didn’t Block It
Even though the spoofed emails still passed SPF, DKIM, and DMARC checks, these mechanisms failed to detect the issue because Apple applied cryptographic signatures after the problematic parsing stage. Since the visible sender domain remained @icloud.com, DKIM alignment held up and DMARC checks passed. The mail also originated from Apple’s infrastructure, satisfying SPF. These combined “pass” results on all three fronts would normally be seen as strong proof of authenticity.
Timeline & Fixes
The vulnerability was first disclosed to Apple by security researcher Timo Longin from SEC Consult on May 21, 2024. Apple addressed the initial proof-of-concept but the second bypass was only discovered later. The final fixes were confirmed as implemented in December 2025, with a full technical write-up released on October 1, 2026. Longin was awarded $15,000 under Apple’s bug bounty program for the findings.
What This Reveals
This case underscores how email authentication depends not just on standards like SPF, DKIM, and DMARC, but on consistent, secure handling across every stage of message processing. Parsing vulnerabilities—especially across SMTP servers—can let malicious actors impersonate any account, even on systems employing top-tier validation tools.
For users and organizations: scrutinize email headers carefully. Watch for discrepancies between the visible “From:” field and the Return-Path or MAIL FROM. Treat urgent or credential requests with suspicion. For defenders: make sure monitoring isn’t limited to just authentication passes—trace the full delivery chain and audit internal mail handling from authentication through delivery.
This vulnerability may now be remediated, but the broader lesson remains: security is only as strong as its weakest link. Protocol compliance, header parsing, and internal processing all require tight controls. Moving forward, how providers handle malformed headers and enforce SMTP standards will matter more than ever.