Is email header "FROM" and "Return-Path" block spoofing possible?

I know the sender can spoof the email so that it looks like it was sent from somebody you may know, however, I thought that the email header information shows the actual sender information? Is it possible that the sender was able to forge the email header "FROM" and "Return-Path" blocks as well? As they are reflecting the actual spoofed email in the email header fields.

submitted by /u/Unknown_Mando
[link] [comments]

from hacking: security in practice https://ift.tt/328vZIx

Comments