A bug in Gmail allows hackers to hide their identities and pretend to be other people or organizations.
Yan Zhu, a security researcher, discovered the bug at the end of October, while Google had stated that the specific problem had been fixed.
To be safe, Gmail users should look carefully at the email address. Don't click reply if asked for verification. Start a conversation, or send an email if you're sure what the recipient's real email address is.
Email spoofing allows hackers to send an email that appears to be from another account while hiding the real address it comes from.
According to the researcher, the sender's real email address is hidden, and the recipient will not be able to discover it even if they open the email and look at the contents.
Zhu told Motherboard that he had changed his name to Yan “security@google.com” with an extra character in quotation marks and sent Motherboard a screenshot of the correspondence. According to Motherboard, DomainKeys Identified Mail (DKIM) digitally signs emails for a domain and determines authenticity.
When John Shier, a security officer, flagged a series of emails to see if they were fake, DKIM was one of the pieces of evidence that led him to his conclusions. DKIM does not filter or identify fraudulent emails, but it can be useful for approving legitimate emails.
Google uses it to authenticate emails originating from eBay and PayPal. When messages arrive in Gmail claiming to be from an address but lacking the DKIM signature, they are not even allowed to enter the spam email category.

