Any idea of how to spoof an email sender in python using smtplib?

Viewed 4877

I was wasting another day of my life messing around with python and I was thinking about how to spoof an email address using smtplib in python. I thought it could be possible to spoof the from address by using the code below but it didn't work. I have seen projects on github that seem to be able to actually spoof the email but if i were to create a program of my own that does this, how exactly would it work? Any ideas? Code:

import smtplib

username = (mygmailusername)
password = (mypassword)
fakefrom = "donaldtrump@gmail.com"
toEmail = (toAddress)

server = smtplib.SMTP("smtp.gmail.com",587)
server.starttls()
server.login(username,password)
server.sendmail(fakefrom,toEmail,"this is the fbi. OPEN UP")
server.close()
2 Answers

Most providers check the account with the sender address, and disallow if the sender address dosn't match with sender. Try if you have a setup box network, to use your provider network smtp server without authentification on smtp 25 port, and most of time the mail can be sent. But with that method, many receiver servers will tag directly this mail as spam/dangerous. You can try that directly in your message tool (outlook,...) it s the same behavior as you code.

Sorry I'm a bit late. The problem, here lies with the second-to-last line:

server.sendmail(fakefrom,toEmail,"this is the fbi. OPEN UP")

You are trying to use the 'fake from' address to actually send the email which isn't what you want to be doing. You just want to 'spoof' it and make the recipient think that the email came from a different address. You do that by defining the sender details in the message body.

The code that you would need to use to make this work would be:

import smtplib

username = (mygmailusername)
password = (mypassword)

fake_from = "donaldtrump@gmail.com"
fake_name = "Donald Trump"

to_email = (toAddress)
to_name = (toName)

subject = "Bonjour"
content = "This is the fbi. OPEN UP"

message = f"From: {fake_name} <{fake_from}>\nTo: {to_name} <{to_email}>\nSubject: {subject}\n\n{content}"

server = smtplib.SMTP("smtp.gmail.com", 587)
server.starttls()
server.login(username, password)
server.sendmail(username, to_email, message.encode())
server.close()
Related