Skip to main content

Sender spoofing in Proton Mail via display-name homograph

0
Medium
Published: 09/28/2026 (09/28/2026, 16:14:39 UTC)
Source: Reddit Cybersecurity

Description

A sender spoofing vulnerability in Proton Mail's web interface allows an attacker to forge the sender identity using display-name homographs that visually mimic legitimate email addresses. The issue exploits the font rendering of certain characters (e.g., capital 'I' vs lowercase 'l') in the default system font, making look-alike domains indistinguishable from real ones. Proton Mail does not display authentication failure warnings for domains without DMARC records, allowing spoofed messages to appear clean and trustworthy in the inbox. Despite reporting and a bounty awarded in early 2025, Proton has not fixed the issue as of September 2026.

Reddit Discussion

r/cybersecurity·posted by u/__ThePasanger__
00

Proton Mail confirmed and paid for an email-spoofing bug, then left it unfixed for 16 months:
https://alonsovidales.github.io/protonmail-sender-spoofing/

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 16:17:50 UTC

Technical Analysis

The vulnerability involves Proton Mail's web interface displaying the From display name prominently without forcing the actual envelope sender address into view. An attacker can craft a display name containing an address-shaped string on a look-alike domain (e.g., gmaiI.com with a capital 'I' instead of an 'l'), which renders identically to the legitimate domain in the default macOS system font (SF Pro). Proton Mail's protections against encoding-based homographs do not cover this font-based homograph. Additionally, Proton Mail does not show an authentication-failure banner for messages from domains lacking DMARC records, even if SPF fails, resulting in spoofed messages delivered to the inbox without warning. A Reply-To header can redirect replies to an attacker-controlled address without visibility unless the user inspects headers manually. The issue was reported in February 2025, confirmed and bounty awarded in April 2025, but remains unpatched as of September 2026. Proton acknowledged the risk and promised a fix but has not shipped one, and the researcher publicly disclosed the issue after Proton did not act within the disclosure policy timeframe.

Potential Impact

Attackers can send emails that appear to come from legitimate senders by exploiting visual homographs in the display name, potentially deceiving users into trusting and acting on spoofed messages. The lack of authentication-failure warnings for domains without DMARC records increases the risk of successful phishing or social engineering attacks. Replies to such spoofed emails can be redirected to attacker-controlled addresses without user awareness. This undermines user trust in Proton Mail's sender identity verification and could facilitate targeted impersonation attacks.

Defensive Guidance

As of the latest information, no official fix has been released by Proton Mail despite the issue being confirmed and a bounty awarded. Users should exercise caution when verifying sender identities, especially if the sender domain lacks a DMARC record. Proton Mail users and administrators should monitor official Proton communications for updates. Patch status is not yet confirmed — check the vendor advisory or Proton Mail's official channels for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aba9326f7a7c54106e989ab

Added to database: 09/28/2026, 16:17:42 UTC

Last enriched: 09/28/2026, 16:17:50 UTC

Last updated: 09/29/2026, 03:47:36 UTC

Views: 23

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses