Free tools Windows power users keep installed
One-click scans. No signup required.
Yes, SMTP smuggling can make a forged message pass some email-authentication checks—but it does not break DMARC itself. The technique exploits a disagreement between mail servers about where one message ends and another begins. In the cases SEC Consult disclosed in 2023, a message relayed through legitimate sending infrastructure could inherit that infrastructure’s SPF authorization, while a receiving server interpreted an unusual line-ending sequence as a message boundary. The reported results depended on specific server behaviors and receiver conditions; they are historical findings, not a current inventory of vulnerable providers.
What SMTP smuggling is
SMTP smuggling is a mail-parsing mismatch. Two servers handling the same SMTP traffic can interpret its message boundaries differently: the sending server may treat a sequence as part of one message, while the receiving server treats it as the end of that message and parses following data separately.
Think of two mailrooms disagreeing about where one letter ends and the next begins. The analogy only goes so far: in real mail flow, SMTP servers parse message data and authentication checks occur at different points, so a boundary mismatch can affect what a downstream server sees.
During SMTP’s DATA transfer, the conventional end-of-data marker is CRLF, a dot, then CRLF (rn.rn). SEC Consult described cases involving bare carriage returns (CR) or line feeds (LF) that different servers handled inconsistently. If one server relays a crafted sequence and another accepts it as an end marker, the receiving server may stop parsing the first message and treat subsequent material as separate content.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
How a forged message can pass authentication checks
SMTP smuggling does not cryptographically defeat DMARC. Rather, it can exploit where authentication is evaluated relative to the parsing mismatch. In the outbound cases SEC Consult described, the sending service could relay a crafted message using its legitimate mail infrastructure. SPF could then authorize the sending service’s IP address, even when the visible sender identity in the message was forged.
DMARC commonly passes when either SPF or DKIM passes with alignment to the visible From domain. A successful SPF-alignment check can therefore make a forged message appear authenticated in the demonstrated flow. That does not mean every DMARC deployment is ineffective: the technique depends on the particular sending and receiving servers, message path, and receiver behavior.
Rank #2
- Pass the Securing Email with Email Security Appliance 300-720 SESA with updated flashcards packed with detailed content aligned to the latest exam blueprint. Cover all core topics without the overload found in lengthy study guides. Get 300+ Securing Email with Email Security Appliance 300-720 SESA flashcards on 8-1/2″ x 11″ perforated card stock.
What SEC Consult reported in 2023
SEC Consult published its findings on December 18, 2023, describing outbound cases involving Microsoft Exchange Online and GMX/Ionos, and inbound exposure involving Cisco Secure Email Gateway and Cisco Secure Email Cloud Gateway default handling. The table distinguishes the reported paths; it is disclosure history, not a ranking or a statement about current vulnerability status.
| Path | Reported behavior and dependency | Disclosure status reported by SEC Consult |
|---|---|---|
| Microsoft Exchange Online outbound | A crafted sequence could be relayed through Exchange Online; the reported path depended on the recipient’s inbound SMTP server supporting BDAT/CHUNKING. | SEC Consult said Microsoft fixed the issue around October 16, 2023. |
| GMX/Ionos outbound | The researchers described an outbound smuggling path involving the provider’s mail infrastructure and the receiving server’s handling of nonstandard end-of-data sequences. | SEC Consult said GMX fixed the issue around August 10, 2023. |
| Cisco Secure Email inbound | SEC Consult described default “CR and LF Handling” behavior that converted bare CR/LF characters to CRLF, which could enable inbound smuggling in relevant conditions. | SEC Consult said Cisco did not treat the behavior as a vulnerability and did not plan to change the default; its recommendation was a manual configuration change. |
The Exchange Online example is particularly dependent on the receiving system: SEC Consult said the recipient’s inbound SMTP server had to support BDAT/CHUNKING. Other paths also required their own server behaviors. The findings do not establish that every mail server accepts the relevant terminator or that every provider or implementation was tested.
Rank #3
- Pass the Securing Email with Email Security Appliance with updated flashcards packed with detailed content aligned to the latest exam blueprint. Cover all core topics without the overload found in lengthy study guides. Get 300+ Securing Email with Email Security Appliance flashcards on 8-1/2″ x 11″ perforated card stock.
How large were the reported exposure estimates?
SEC Consult gave several scale estimates in its 2023 disclosure. These numbers describe potential exposure or provider background at that time, not confirmed compromises or present-day counts of vulnerable systems.
- About 1.35 million domains: SEC Consult’s 2023 estimate of domains associated with GMX/Ionos infrastructure, based on domains pointing to the relevant service. It is not a current count of vulnerable domains.
- More than 40,000 instances or domains: SEC Consult’s 2023 estimate of Cisco Secure Email Cloud Gateway exposure under default configuration, based on passive DNS observations. It is not a confirmed current vulnerable population.
- Millions of domains: SEC Consult said domains pointing their SPF records to Exchange Online could be involved in the outbound case. Exploitable delivery still depended on receiving-server behavior.
- Around 20 million users: SEC Consult cited this as background scale for GMX as an email provider, not as an affected-user count.
These figures are not attack or compromise totals. The disclosure did not establish an independent prevalence count or a number of real-world attacks resulting from the technique.
Rank #4
- XGS 108 with 1 Year Xstream Protection - Next-generation firewall appliance with Xstream Protection subscription providing zero-day defense, cloud sandboxing, email filtering, intrusion prevention, and advanced reporting, managed through Sophos Central for unified policies and reporting.
- 6 x 2.5 GE copper ports and 1 SFP fiber port, supporting up to 12.5 Gbps firewall performance for growing business networks.
- Zero day protection with cloud sandboxing, email filtering, and advanced reporting for full enterprise coverage.
- TLS inspection and next generation intrusion prevention block hidden threats in encrypted traffic and stop sophisticated attacks.
- Includes Xstream Protection – Advanced security bundle with zero-day protection, cloud sandboxing, email filtering, and automated threat response, providing full coverage against the most sophisticated cyberattacks.
What administrators should check
For Cisco Secure Email Gateway deployments
SEC Consult’s specific recommendation for Cisco Secure Email Gateway and its cloud counterpart was to change CR and LF Handling from Clean to Allow. According to the researchers, Clean allows the message but converts bare CR and LF characters to CRLF; Allow passes the bare characters to the downstream mail server, which they expected to recognize only the standard CRLF-dot-CRLF marker as end of data.
Before changing a production gateway, check the current Cisco documentation for your product and deployed version, confirm the setting’s present behavior, and test operational impact in your own environment. The recommendation reflects SEC Consult’s 2023 analysis; it should not be treated as a substitute for current vendor guidance.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsBest Value
- XGS 88W with 1 Year Xstream Protection - Next-generation firewall appliance with Xstream Protection subscription providing zero-day defense, cloud sandboxing, email filtering, intrusion prevention, and advanced reporting, managed through Sophos Central for unified policies and reporting.
- Built in Wi Fi 6 with 4 x 2.5 GE copper ports, delivering up to 9.9 Gbps firewall performance for secure wired and wireless networks.
- Zero day protection with cloud sandboxing, email filtering, and advanced reporting for full enterprise coverage.
- TLS inspection and next generation intrusion prevention block hidden threats in encrypted traffic and stop sophisticated attacks.
- Includes Xstream Protection – Advanced security bundle with zero-day protection, cloud sandboxing, email filtering, and automated threat response, providing full coverage against the most sophisticated cyberattacks.
For other SMTP gateways and mail flows
- Inventory the inbound and outbound SMTP gateways that handle your organization’s mail, including relays between hosted providers and on-premises systems.
- Review how each deployed server handles bare CR/LF characters, the DATA end-of-data marker, and BDAT/CHUNKING where applicable.
- Test the actual deployed configuration with authorized tools and controlled mail flows; a result for one server version or path does not establish behavior across all receivers.
- Keep SPF, DKIM, and DMARC enabled and correctly configured, while treating them as one layer of defense alongside consistent SMTP parsing and gateway configuration.
SEC Consult’s findings show why authentication results need to be understood in the context of the mail path: a mismatch between relays can undermine assumptions about what content was authenticated. They do not show that changing a DMARC policy alone resolves an SMTP implementation mismatch.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

