There is a novel email spoofing method called SMTP smuggling, which essentially exploits the fact that different SMTP servers interpret the end of data sequence (<CR><LF>.<CR><LF>) differently. This creates the opportunity to send/receive spoofed emails.
โ
Cisco's Secure Email solution by default uses a Setting which can make you vulnerable to the above attack. However, the good news is that this setting can be changed.
โ
When creating a Listener, we recommend that you change the CR and LF Handling to "Allow", instead of the vulnerable default setting of "Clean" by editing your Listener Settings.