Sender spoofing in Proton Mail via display-name homograph
A sender spoofing vulnerability in Proton Mail's web interface allows an attacker to forge the sender identity using display-name homographs that visually mimic legitimate email addresses. The issue exploits the font rendering of certain characters (e.g., capital 'I' vs lowercase 'l') in the default system font, making look-alike domains indistinguishable from real ones. Proton Mail does not display authentication failure warnings for domains without DMARC records, allowing spoofed messages to appear clean and trustworthy in the inbox. Despite reporting and a bounty awarded in early 2025, Proton has not fixed the issue as of September 2026.
AI Analysis
Technical Summary
The vulnerability involves Proton Mail's web interface displaying the From display name prominently without forcing the actual envelope sender address into view. An attacker can craft a display name containing an address-shaped string on a look-alike domain (e.g., gmaiI.com with a capital 'I' instead of an 'l'), which renders identically to the legitimate domain in the default macOS system font (SF Pro). Proton Mail's protections against encoding-based homographs do not cover this font-based homograph. Additionally, Proton Mail does not show an authentication-failure banner for messages from domains lacking DMARC records, even if SPF fails, resulting in spoofed messages delivered to the inbox without warning. A Reply-To header can redirect replies to an attacker-controlled address without visibility unless the user inspects headers manually. The issue was reported in February 2025, confirmed and bounty awarded in April 2025, but remains unpatched as of September 2026. Proton acknowledged the risk and promised a fix but has not shipped one, and the researcher publicly disclosed the issue after Proton did not act within the disclosure policy timeframe.
Potential Impact
Attackers can send emails that appear to come from legitimate senders by exploiting visual homographs in the display name, potentially deceiving users into trusting and acting on spoofed messages. The lack of authentication-failure warnings for domains without DMARC records increases the risk of successful phishing or social engineering attacks. Replies to such spoofed emails can be redirected to attacker-controlled addresses without user awareness. This undermines user trust in Proton Mail's sender identity verification and could facilitate targeted impersonation attacks.
Mitigation Recommendations
As of the latest information, no official fix has been released by Proton Mail despite the issue being confirmed and a bounty awarded. Users should exercise caution when verifying sender identities, especially if the sender domain lacks a DMARC record. Proton Mail users and administrators should monitor official Proton communications for updates. Patch status is not yet confirmed — check the vendor advisory or Proton Mail's official channels for current remediation guidance.
Sender spoofing in Proton Mail via display-name homograph
Description
A sender spoofing vulnerability in Proton Mail's web interface allows an attacker to forge the sender identity using display-name homographs that visually mimic legitimate email addresses. The issue exploits the font rendering of certain characters (e.g., capital 'I' vs lowercase 'l') in the default system font, making look-alike domains indistinguishable from real ones. Proton Mail does not display authentication failure warnings for domains without DMARC records, allowing spoofed messages to appear clean and trustworthy in the inbox. Despite reporting and a bounty awarded in early 2025, Proton has not fixed the issue as of September 2026.
Reddit Discussion
Proton Mail confirmed and paid for an email-spoofing bug, then left it unfixed for 16 months:
https://alonsovidales.github.io/protonmail-sender-spoofing/
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves Proton Mail's web interface displaying the From display name prominently without forcing the actual envelope sender address into view. An attacker can craft a display name containing an address-shaped string on a look-alike domain (e.g., gmaiI.com with a capital 'I' instead of an 'l'), which renders identically to the legitimate domain in the default macOS system font (SF Pro). Proton Mail's protections against encoding-based homographs do not cover this font-based homograph. Additionally, Proton Mail does not show an authentication-failure banner for messages from domains lacking DMARC records, even if SPF fails, resulting in spoofed messages delivered to the inbox without warning. A Reply-To header can redirect replies to an attacker-controlled address without visibility unless the user inspects headers manually. The issue was reported in February 2025, confirmed and bounty awarded in April 2025, but remains unpatched as of September 2026. Proton acknowledged the risk and promised a fix but has not shipped one, and the researcher publicly disclosed the issue after Proton did not act within the disclosure policy timeframe.
Potential Impact
Attackers can send emails that appear to come from legitimate senders by exploiting visual homographs in the display name, potentially deceiving users into trusting and acting on spoofed messages. The lack of authentication-failure warnings for domains without DMARC records increases the risk of successful phishing or social engineering attacks. Replies to such spoofed emails can be redirected to attacker-controlled addresses without user awareness. This undermines user trust in Proton Mail's sender identity verification and could facilitate targeted impersonation attacks.
Defensive Guidance
As of the latest information, no official fix has been released by Proton Mail despite the issue being confirmed and a bounty awarded. Users should exercise caution when verifying sender identities, especially if the sender domain lacks a DMARC record. Proton Mail users and administrators should monitor official Proton communications for updates. Patch status is not yet confirmed — check the vendor advisory or Proton Mail's official channels for current remediation guidance.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aba9326f7a7c54106e989ab
Added to database: 09/28/2026, 16:17:42 UTC
Last enriched: 09/28/2026, 16:17:50 UTC
Last updated: 09/29/2026, 03:47:36 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.