
Security researcher Alonso Vidales has disclosed a sender-spoofing issue in Proton Mail that he says can make fraudulent messages appear to come from trusted contacts without showing an authentication warning.
According to the report, Proton acknowledged the finding and awarded a bounty in April 2025, but the technique remained reproducible in September 2026.
Vidales, a senior software engineer at Microsoft, first reported the issue on February 13, 2025. He tested it against his own Proton accounts using the SMTP testing utility swaks.
Proton Mail is a privacy-focused email service offering encrypted communications. The reported weakness concerns how sender identities and authentication warnings appear, potentially giving phishing messages a convincing look without requiring access to a legitimate sender’s account.
Look-alike sender identities
The technique combines attacker-controlled sender text, visually confusable characters, and what Vidales describes as inconsistent authentication warnings.
His demonstration impersonated Google CEO Sundar Pichai using the address-shaped string sundar@gmaiI.com, with a capital “I” replacing the lowercase “l” in Gmail’s domain.
According to Vidales, those characters render identically in the default macOS system font used by the web interface, making the look-alike domain appear legitimate. He says Proton prominently displays the forged identity, while inspecting the underlying sender details requires manually expanding the message header.

Vidales
An attacker can also supply a separate Reply-To address, directing responses to an inbox they control. That destination may remain unnoticed unless the recipient checks the message details before replying.
Vidales reports that the forged identity also appeared in a macOS desktop notification, extending the deception beyond the mail interface, where users have fewer details available to assess a message.
The researcher says test messages reached his inbox without an authentication warning despite failing Sender Policy Framework (SPF) checks, which determine whether a sending server is authorized to send mail for a domain.
He attributes the missing warning to the absence of a Domain-based Message Authentication, Reporting, and Conformance (DMARC) record for the relevant sender domain. DMARC evaluates authentication against the domain in the message’s From address, which can differ from the envelope sender checked by SPF.
Bounty awarded in 2025
The disclosure includes a correspondence timeline in which Proton initially asked whether the message had reached spam. Vidales clarified that it arrived in the inbox without an alert and supplied a demonstration video.
On April 15, 2025, Proton said it had decided to make changes after the findings and awarded the bounty, though Vidales noticed no changes.
He reported the issue again on August 30, 2026. Proton initially treated the submission as an already-reported finding, then said it would contact the relevant engineering team after he explained the earlier report and payment.
CyberInsider has contacted Proton Mail to learn more about the current exploitability of the sender spoofing flaw and whether a fix is on the way, and we will update this post as soon as we hear back.
Users should expand sender details and check both the From and Reply-To addresses before responding to unexpected requests. Sensitive requests involving payments, credentials, or personal information should be verified through a separate, trusted channel, even when no warning appears.






Leave a Reply