
Two vulnerabilities in Apple’s iCloud Mail infrastructure let an authenticated user send messages that appeared to come from any @icloud.com address while passing SPF, DKIM, and DMARC checks.
The findings were published by Timo Longin, a principal security consultant at SEC Consult, known for his earlier research into SMTP smuggling. Longin discovered the flaws during a research project with the SEC Consult Vulnerability Lab and first reported the issue to Apple in May 2024.
iCloud Mail is Apple’s email service, available through its devices, web interface, and compatible email clients. Its outgoing mail infrastructure normally prevents users from sending messages with a From address that does not belong to their authenticated account.
Longin found two ways around that restriction by exploiting differences in how components inside Apple’s infrastructure interpreted message headers. The techniques, described as “header smuggling,” could support convincing impersonation and phishing attempts without requiring access to the impersonated mailbox.
How the spoofing worked
Unlike traditional SMTP smuggling, which manipulates message boundaries to inject commands for another email, these attacks changed the sender address displayed to the recipient.
The first method used standalone carriage-return characters inside a malformed From header. Apple’s initial sender check ignored that header and validated another containing the authenticated user’s legitimate address.
A later processing stage normalized the malformed header, making the attacker’s chosen address recognizable as the sender. Additional formatting pushed the legitimate From header into the message body, while multipart formatting concealed the unwanted content from the recipient’s view.

After Apple tightened its parsing, Longin discovered a second technique involving “dot-stuffing,” an SMTP mechanism that adds and removes leading periods during transmission.
Differences in how Apple’s components handled these periods let a disguised From header become active later in the pipeline. Another parsing discrepancy moved the legitimate sender header into the body, again leaving the spoofed address visible.
The messages passed email authentication because they traveled through authorized Apple servers and received a valid DKIM signature after the headers had been transformed. SPF and DMARC checks authenticated the relevant domain without establishing that the sender controlled the specific mailbox shown to recipients.

SEC Consult
Fixes took repeated attempts
Apple awarded a $15,000 bounty for the initial report in November 2024, but the subsequent investigation uncovered further bypasses.
According to SEC Consult’s disclosure timeline, one attempted fix merely blocked the substring “admin” in the From header. The researchers demonstrated that other addresses, including security@icloud.com, remained spoofable.
An update Apple reported deploying in May 2025 also failed to eliminate the bypass. The researchers found their previous method no longer worked and confirmed remediation on December 9, 2025.
The spoofed messages still contained traces of the authenticated sender in their raw headers, including the Return-Path and authentication results. SEC Consult suggested that provider-aware filtering could flag unexpected differences between that address and the visible From address.
Users should keep in mind that passing email authentication checks does not guarantee the identity of an individual sender. Unexpected requests for payments, credentials, or sensitive information should always be verified through a separate, trusted channel.







Leave a Reply