Allows the receiver to verify that an email claimed to have come from a specific domain was authorized by the owner of that domain using a digital signature on the domain.
DMARC: Domain-based Message Authentication, Reporting and Conformance
You can then get IP and a lot from browser headers including
browser information, OS info, device types
Revealing your IP is not safe as even home routers have pretty static IP addresses
Last usually 30 days up to 3 months
💡 You can still release DHCP lease in your home router settings to get a new IP from the ISP.
You can send an image from a back-end server that you own
Some e-mail providers request it and hide users IP
You can send a direct link
No e-mail provider can protect you from that
🤗 Can be done through social engineering e.g.
You know from social media that Bob was celebrating yesterday. You send an e-mail stating "Hi Bob, crew and I had a great time last night, you're never going to guess what Sam did in toilet, threw himself up, check out his pictures"
E.g.
Install apache yum install httpd
Start apache systemctl start httpd
Create a file: cd /var/www/html/ then touch <RESOURCE_NAME>;