Nicola Seidita
Email Spoofing and Domain Impersonation: A Technical and Experimental Study of DMARC Enforcement and Risk Assessment Frameworks.
Rel. Andrea Atzeni, Paolo Dal Checco. Politecnico di Torino, Master of science program in Cybersecurity, 2026
|
Preview |
PDF (Tesi_di_laurea)
- Thesis
Licence: Creative Commons Attribution Non-commercial No Derivatives. Download (4MB) | Preview |
|
|
Archive (ZIP) (Documenti_allegati)
- Other
Licence: Creative Commons Attribution Non-commercial No Derivatives. Download (26MB) |
Abstract
Email spoofing and domain impersonation represent persistent threats to digital communications, enabling Business Email Compromise (BEC), financial fraud, and reputational damage. Despite the availability of authentication standards such as SPF, DKIM, and DMARC, adoption remains incomplete and enforcement policies are frequently misconfigured, reducing their preventive effectiveness. This thesis investigates email authentication from a multidisciplinary perspective, integrating technical analysis, forensic methodologies, and legal accountability frameworks. First, the work examines the operational interplay between SPF, DKIM, and DMARC, highlighting common configuration weaknesses and their security implications. A technical and comparative evaluation of existing DMARC compliance and forensic tools is conducted, with particular focus on configuration-based exposure analysis and evidentiary preservation.
Building upon these foundations, the thesis introduces two original contributions
Relators
Academic year
Publication type
Number of Pages
Course of studies
Classe di laurea
URI
![]() |
Modify record (reserved for operators) |
