upvote
I think on the sending side, being able to send from others’ addresses is fixed by now: https://userforum-en.mailbox.org/topic/anti-spoofing-for-cus...

But it definitely used to be possible, I tried once with success.

Anti spoofing for incoming mails was not perfect the last time I checked either, but is a different issue.

reply
For incoming mail, your client should check regardless of the server provider. On Thunderbird I have this extension: https://github.com/mcortt/EagleEye . It checks for any SPF, DKIM and DMARC fails and shows a banner. SPF/DKIM/DMARC is minimum and pretty useless against spam though. All phishing e-mails in my GMail account have impeccable SPF/DKIM records.
reply