Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

merten.vg

@mvg@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Software engineer (mostly with AI these days), father of two kids, and dog-father to a Bernese Mountain Dog.

I very nearly got burned by a phishing scam earlier this year, which got me wondering why this continues to be a problem. I didn't find any reasonable answers, so I thought I'd take a shot at creating one myself. Now I moonlight on project DMCN and hope to share it with the world and help it grow.

#golang #infosec #email #dmcn

0 Followers
0 Following
2 Posts
Joined August 26, 2026
GitHub:
https://github.com/mertenvg
DMCN Project:
https://dmcn.dev
Open post
merten.vg @mvg@infosec.exchange
· 1mo ago
Boosted by @welcome@friends.deko.cloud
#introduction Hi, I'm Merten. I've been a software engineer for 24+ years, and earlier this year I very nearly got taken by a phishing scam. I caught it late enough that it genuinely rattled me, and the fact that I came that close at all got me wondering why this is still a problem after all this time. If all that experience isn't enough to save you, it probably isn't a user-education problem. What I found was that SMTP has never had a way to prove who actually sent a message. SPF, DKIM and DMARC all check the domain and the server, but never the person, so a lookalike domain can pass all three and still land in your inbox looking perfectly fine. Everything built since has been trying to guess at the answer from the outside, which is a good part of why we are all still guessing. I couldn't find anyone working on that particular part, so I thought I'd have a go at it myself. I've always found that turning something intricate into something simple is where the real value is, and the simple version here is that the address is a keypair, verifiable all the way up to its domain and the servers hosting it, so a message either checks out against the sender's key or it doesn't. There's a spec and a reference server, both Apache-2.0, and it'll run in a single container if you'd like to poke at it. I moonlight on it, so it moves at evenings-and-weekends pace. I'll mostly be posting about mail infrastructure and protocol design, and occasionally about being wrong on both. If you spot something I've got wrong, I'd genuinely like to hear it. Spec, code and docs are all at https://dmcn.dev #infosec #email #identity #dmcn
dmcn.dev
0
0
1
0
Open post
merten.vg @mvg@infosec.exchange
· 1mo ago
A phishing invoice from a lookalike domain passes every gate we built: SPF, DKIM, DMARC. Not by defeating them — by satisfying them. The attacker owns the domain, so all three checks are telling the truth. What if... a sender you have never corresponded with before was simply shown to you as a sender you have never corresponded with before? Not spam. Not fine. New. #email #infosec #dmcn
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:31:04 UTC