Google fixes serious email authentication bug - make sure you're not affected

Gmail
(Image credit: Google)

Google says that it has fixed an issue in Gmail that saw scammers impersonating a legitimate, and more importantly, verified company, but fortunately, it looks like no users were harmed.

The email service provider just recently expanded on the BIMI email authentication program it launched almost two years ago by allowing certain eligible companies to show a blue checkmark next to their name, in a bid to help users distinguish safe emails in the inbox.

The emails in question appeared to come from delivery giant UPS, however fortunately, The Register reports that no malicious payload was included.

Gmail authentication hacked

BIMI requires that participating companies adopt Domain-based Message Authentication, Reporting, and Conformance (DMARC) as well as either Sender Policy Framework (SPF) or DomainKeys Identified Mail (DKIM).

A vulnerability in SPF is to blame for allowing scammers to pretend to be UPS, even adopting the company’s logo and blue checkmark, according to Chris Plummer who shared their findings via a Tweet.

The thread details Google’s initial response, along the lines of “won’t fix - intended behavior,” before pressure from Plummer and the Internet saw it rethink its stance. A later communication from Google to Plummer reads:

“After taking a closer look we realized that this indeed doesn’t seem like a generic SPF vulnerability. Thus we are reopening this and the appropriate team is taking a closer look at what is going on.”

Google apologized to Plummer for its initial response, which it said “might have been frustrating,” and thanked the Twitter user for “pressing on for [Google] to take a closer look.”

While this example in isolation appears not to have caused any trouble, it’s unclear how many other accounts have been impersonated and how many email users have fallen victim to other scams.

A Google spokesperson told TechRadar Pro:

"This issue stems from a third-party security vulnerability allowing bad actors to appear more trustworthy than they are. To keep users safe, we are requiring senders to use the more robust DomainKeys Identified Mail (DKIM) authentication standard to qualify for Brand Indicators for Message Identification (blue checkmark) status."

Google confirmed that the change has now been fully rolled out.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
Shadowed hands on a digital background reaching for a login prompt.
A flaw in Google OAuth system is exposing millions of users via abandoned accounts
Isometric demonstrating multi-factor authentication using a mobile device.
Google is ditching SMS - and will now use QR codes for Gmail account authentication
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
 In this photo illustration a Google Play logo seen displayed on a smartphone.
The end of fake VPNs? Google Play Store now shows which VPNs are secure enough to be trusted
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring