frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Ask HN: How the hell haven't we solved phishing emails yet?

5•mdni007•5h ago
How is it possible that in 2025 with all the amazing advancements in AI, I am still getting phishing emails? Emails attempting to look as if its coming from Coinbase, or some stock broker, or bank, or even UPS/USPS/FEDEX? These emails dont look even remotely legit so how do they manage to pass through? Even the email addresses are from some completely different domain. I am using Outlook and Gmail. How/why have they not figured this out already? Even ignoring AI, I don't know much about email but why isn't there something like a CA for email?

Comments

toomuchtodo•5h ago
We have DMARC, DKIM, and SPF [1], and while this provides some signal with regards to mail origination, it falls flat when emails are being sent from Gmail, Yahoo, and other large service providers. This is why email security gateways exist, to wrap stronger security controls around inbound email. This might be email content classification and heuristics, this might be replacing links with control middleware to scan and detonate malware or other exfiltration code and prevent clickers from clicking, etc. None of these mitigations will be perfect though, they will each have some degree of failure or miss.

> Even ignoring AI, I don't know much about email but why isn't there something like a CA for email?

Is there demand for this? Would users pay for it? Or would they tolerate the existing experience with whatever does or does not end of in their Spam folder? The options here are to pick an email provider based on what they can offer from an email protection perspective, or wiring up your own defenses using something that can read your inbox and action emails within it (if your email provider's solution is lacking).

[1] https://www.cloudflare.com/learning/email-security/dmarc-dki...

gogurt2000•5h ago
Huh. In 20 years of using gmail I can't remember ever seeing a phishing email in my inbox (they're all filtered out as spam so I never see them). I'm curious what's led to our different experiences.
mdni007•5h ago
I've used the same email since I was a kid and gave my email to any website that would ask for it without a thought. So now I'm facing the consequences. My email is just my name (which is very common) so I'm fortunate to have it and never wanted to make a new one.
cookiengineer•5h ago
Microsoft has paid customers, which send emails via Microsoft Azure hosts. So they're specifically allowlisted and are bypassing Microsoft O365 filters.

Same for Google Business customers.

Phishers pay to send the emails. You don't pay to receive no email. So that's the conflict of interest of these businesses.

The "CA" for email is basically SPF/DKIM/DMARC as extensions but they're kind of useless because all email providers are lying about quarantine mechanisms anyways. Nothing happens if you report an abuse of spam policies.

But I'm kind of biased because I maintain my own antispam repository [1].

Most of the professional phishing campaigns use e.g. cloned websites under a different top level domain (like company-global.com or company-eu.com), with even legit looking profiles on LinkedIn which are even LLM controlled in their responses. They use pictures and sometimes even identities of real people, and the humans usually don't know about anything that's happening online with their identity in their name.

[1] https://github.com/cookiengineer/antispam

mdni007•5h ago
> Phishers pay to send the emails. You don't pay to receive no email. So that's the conflict of interest of these businesses.

> The "CA" for email is basically SPF/DKIM/DMARC as extensions but they're kind of useless because all email providers are lying about quarantine mechanisms anyways. Nothing happens if you report an abuse of spam policies.

So it sounds like these email providers simply won't do anything since they're not being paid or forced to do so. I don't understand why there isnt any push from financial institutions? Since access to their customer's accounts is usually the end goal for these phishing emails.

Or maybe the FTC/FCC should step in. Or some legislation is needed to enforce this.

chrisjj•5h ago
Simple. There's no money to be made from fixing it.

I spent a week on Inertia Rails and SSR setup. I wrote this so you don't have to

https://tuyenhx.com/blog/inertia-rails-shadcn-typescript-ssr-en/
1•tuyenhx•2m ago•0 comments

IEEE Milestone Proposal: Convolutional Neural Networks

https://ieeemilestones.ethw.org/Milestone-Proposal_talk:Theories_on_Neural_Networks
1•mscii•3m ago•0 comments

Agent Name Service (ANS):A Directory for AI Agent Discovery and Interoperability

https://arxiv.org/abs/2505.10609
1•thebeardisred•3m ago•0 comments

The Future of Junior Software Engineering Roles

https://adventuresincoding.substack.com/p/the-future-of-junior-software-engineering
1•pootietangus•4m ago•1 comments

Cognition in the Age of Offloading

https://thelastwave.substack.com/p/thinking-is-hard
1•johanam•5m ago•0 comments

Red Hat Brings Their Enterprise Linux on SiFive Hardware

https://www.sifive.com/blog/red-hat-enterprise-linux-on-sifive-hardware
1•thebeardisred•14m ago•0 comments

George Wendt, best known for playing Norm on Cheers, dies aged 76

https://www.theguardian.com/tv-and-radio/2025/may/20/george-wendt-dead-cheers-norm
2•mellosouls•14m ago•0 comments

Gail Wellington: far more than just a herder of CATS and mother of CDTV

https://commodore.international/2021/11/21/gail-wellington-far-more-than-just-a-herder-of-cats-and-mother-of-cdtv/
1•rmason•18m ago•2 comments

Apache SeaTunnel

https://github.com/apache/seatunnel
1•DSOfficial•24m ago•1 comments

At Least Two Newspapers Syndicated AI Garbage

https://www.theatlantic.com/technology/archive/2025/05/ai-written-newspaper-chicago-sun-times/682861/
2•JumpCrisscross•27m ago•0 comments

Proposal for Standardized JSX

https://vanillajsx.com/proposal/
2•90s_dev•28m ago•0 comments

FastMCP v2 – now defaults to streamable HTTP with SSE fallback

https://github.com/punkpeye/fastmcp/releases/tag/v2.0.0
2•punkpeye•28m ago•0 comments

The Dangers of Browsing AI Agents

https://arxiv.org/abs/2505.13076
2•walterbell•29m ago•0 comments

TeleMessage 410GB dump available to journalists

https://ddosecrets.com/article/telemessage
2•stubish•36m ago•1 comments

How Music Apps Die - The Design of Finale [video]

https://www.youtube.com/watch?v=Yqaon6YHzaU
2•DavidPiper•37m ago•1 comments

Microsoft-backed UK tech unicorn Builder.ai collapses into insolvency

https://www.ft.com/content/9fdb4e2b-93ea-436d-92e5-fa76ee786caa
3•mmarian•39m ago•3 comments

What if Vintage and Modern got together

https://www.jaydip.me/
2•jdsane•40m ago•0 comments

At Google I/O, everything is changing and normal and scary and chill

https://www.platformer.news/google-io-2025-ai-everything-everywhere/
1•spenvo•52m ago•0 comments

Astronomy: Time Is an Angle

https://oliverkwebb.github.io/articles/astronomy-angles/
2•oliverkwebb•54m ago•0 comments

Show HN: Toffu AI is a Vibe Marketing agent

https://toffu.ai
1•orarbel1•57m ago•0 comments

Teen swimmer caught in rip current rescued by drone [video]

https://www.youtube.com/watch?v=CdGxAbDFQDQ
2•handfuloflight•1h ago•0 comments

Build with Jules, your asynchronous coding agent

https://blog.google/technology/google-labs/jules/
1•badmonster•1h ago•1 comments

Code Improvement Practices at Meta

https://arxiv.org/abs/2504.12517
3•Gigacore•1h ago•0 comments

Relume

https://www.relume.io/
1•handfuloflight•1h ago•0 comments

Ask HN: Trivial things that you have weirdly strong opinions about

1•kaycebasques•1h ago•0 comments

Magnus Carlsen forced into a draw by more than 143000 people playing against him

https://apnews.com/article/chess-magnus-carlsen-match-world-freestyle-grandmaster-963a977765fa02d05a14d701666dfcd7
19•namanyayg•1h ago•4 comments

Good Design Comes from Looking, Great Design Comes from Looking Away

https://www.chrbutler.com/good-design-comes-from-looking-great-design-comes-from-looking-away
2•MBCook•1h ago•0 comments

A broken thruster jeopardized Voyager 1, but engineers executed a remote fix

https://www.npr.org/2025/05/20/nx-s1-5403501/voyager-thruster-nasa-interstellar
3•namanyayg•1h ago•1 comments

Waymo says it reached 10M robotaxi trips, doubling in five months

https://www.cnbc.com/2025/05/20/waymo-ceo-tekedra-mawakana-10-million.html
4•carbocation•1h ago•0 comments

The Agentic Web and Original Sin

https://stratechery.com/2025/the-agentic-web-and-original-sin/
1•VignuB•1h ago•0 comments