This is why I like to use Gmail’s “show original” feature To actually see where the email came from instead of just trusting it.
https://thehackernews.com/...
https://thehackernews.com/...

Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials
Phishers abused Google Sites and DKIM replay to send valid-signed emails, bypassing filters and stealing credentials.
https://thehackernews.com/2025/04/phishers-exploit-google-sites-and-dkim.html?fbclid=IwZXh0bgNhZW0CMTEAAR7pe6gI7dO9yQs-HWgQmsOXDbiFqwZXAXdRF9T03fmr5oc0f_UrY2k-a4OrSA_aem_Q5Gca1wSJOuBqJtLR7l50w&m=1
3 days ago
(E)