Recently, security researcher Timo Longin, in collaboration with the SEC Consult Vulnerability Lab, uncovered critical vulnerabilities within Apple’s iCloud email infrastructure. These flaws made it possible for individuals with a free iCloud account to send emails that appeared to originate from any @icloud.com address. This exploitation of the system allowed emails to pass the stringent SPF, DKIM, and DMARC checks, which are fundamental to verifying the sender’s identity in email communications.
Email Authentication Challenges
Apple has since addressed these vulnerabilities after a period of responsible disclosure. The findings underscore that email authentication reliability hinges on the robustness of the systems processing emails before they exit a provider’s network. In this instance, the issue did not stem from compromised iCloud accounts or weaknesses in recipients’ mailboxes. Instead, it arose from discrepancies in how different parts of Apple’s SMTP processing handled the same email data.
The SMTP, or Simple Mail Transfer Protocol, remains a cornerstone of internet email. It involves both an envelope sender, known as MAIL FROM or Return-Path, and a visible From: header that appears in users’ email clients. Typically, iCloud ensures that authenticated accounts only utilize permitted sender addresses. Attempts to alter the visible sender to another iCloud identity would result in an error from Apple’s service, stating the address was unauthorized for the user.
Technical Insights into the Vulnerability
Longin discovered methods to manipulate iCloud’s internal parsers, leading them to interpret messages differently. One issue involved inserting unusual carriage-return characters within the From: header. The initial parser failed to process the altered field as a standard sender header during user validation. However, a subsequent parser corrected the message, presenting it as a valid sender header to receiving mail servers.
The SEC Consult’s technical report revealed the gravity of the situation: users authenticated as one iCloud address could make delivered emails appear to come from another, high-value identities included. Furthermore, a second issue exploited SMTP dot-stuffing rules, with parsers inconsistently applying these rules, allowing spoofed headers to bypass iCloud’s checks.
Implications and Lessons for Email Security
Worryingly, these spoofed emails could pass SPF, DKIM, and DMARC checks. SPF verified that Apple’s legitimate infrastructure dispatched the email, DKIM succeeded due to iCloud’s cryptographic signature application post-processing, and DMARC passed because the visible sender domain matched. These checks are often considered strong proof of email legitimacy by users and mail systems.
The incident highlights potential vulnerabilities in trusted provider-side parsing, which can undermine security protocols. SEC Consult initially reported the issue to Apple in May 2024, leading to final fixes confirmed by December 2025. Apple acknowledged Longin’s findings with a $15,000 reward from its Security Bounty Program.
This case echoes previous SMTP smuggling research, demonstrating how inconsistent protocol handling can enable widespread email spoofing. The broader lesson for cybersecurity teams is clear: while SPF, DKIM, and DMARC are crucial, they do not guarantee complete security. It’s vital to scrutinize full message headers, monitor for discrepancies between visible From: addresses and Return-Paths, and treat unexpected requests with skepticism.
