On October 1, 2026, SEC Consult published a report describing two flaws in Apple’s outbound iCloud Mail processing. In proof-of-concept demonstrations, an authenticated iCloud sender could make a message’s visible From address appear to be another @icloud.com identity—and the messages passed SPF, DKIM and DMARC checks. SEC Consult confirmed that Apple’s deployed fixes had remediated the issues on December 9, 2025.

Two parser mismatches enabled sender spoofing

The flaws arose because successive parsers interpreted parts of an email differently. One involved unusual carriage-return characters in a From header. The other used inconsistent handling of SMTP dot-stuffing, a convention for handling lines that begin with a period during message transmission.

In both demonstrations, the visible From identity could differ from the authenticated sender and the SMTP envelope sender shown in Return-Path. The examples included addresses such as admin@icloud.com and security@icloud.com.

Why SPF, DKIM and DMARC passed

SPF checks whether a sending server is authorized for a domain. DKIM uses a digital signature to check a message’s association with a domain, while DMARC checks alignment between the domain in the visible From address and a domain authenticated by SPF or DKIM.

The demonstrated messages passed all three checks. In other words, those results did not guarantee that the visible sender identity matched the account that authenticated to iCloud. A Return-Path address different from the visible From address could provide a clue in the message’s raw headers.

Apple’s fixes were verified before publication

SEC Consult confirmed on December 9, 2025, that Apple’s deployed fixes remediated the reported issues. The technical report was published on October 1, 2026, after that confirmation.

Sender spoofing is not account takeover

Changing an email’s displayed From identity is different from accessing the Apple Account named in that address. Apple says that knowing an email address alone does not grant access to its account. Its account-security guidance recommends checking account settings for unfamiliar devices and contact information; if you suspect someone has accessed your account, Apple advises changing the password and removing unrecognized devices.