> On Feb 16, 2018, at 4:41 PM, John Hardin <jhar...@impsec.org> wrote: > > Not necessarily safe. If your MTA receives a message without a Message-ID, it > is supposed to generate one. And if it does so, it will probably do so using > your (recipient) domain...
Wouldn't this also FP on messages internal to the domain, i.e., sent from one user to another on the same domain? (Also, my Message-IDs don't seem to have this same format. Nor do yours.) --- Amir