It can be done, according to research presented at Black Hat USA on August 6, 2026: an email's styling code (CSS) can draw a convincing fake login box inside webmail and record what you type, with no JavaScript, link or attachment. The defense is a simple habit: never enter a password into anything inside an email.
Key takeaways
- Gareth Heyes of PortSwigger presented "CSS: the bomb inside your inbox" at Black Hat USA 2026 on August 6, and the paper was published the same day.
- Using styling code and HTML that had already passed a sanitizer, the research built a convincing fake login screen and a working keylogger, without JavaScript.
- Webmail services studied included Gmail, Outlook, Yahoo Mail, AOL Mail, Fastmail and Proton Mail.
- A real sign-in page never appears inside the body of an email. If you see one, close the message and sign in from your bookmark.
- DMARC can't block this technique when attackers use their own domain, but enforced DMARC lets receiving servers reject the version that forges your own domain, such as a fake note from your IT team.
What happened?
Black Hat USA, the security research conference that marked its 29th anniversary this year, ran August 1–6, 2026 at Mandalay Bay in Las Vegas. On its final day, Thursday August 6, Gareth Heyes of the web security company PortSwigger presented research called "CSS: the bomb inside your inbox," and PortSwigger published the paper the same day.
First, what is CSS?
CSS (Cascading Style Sheets) is the code that decides how web pages and HTML emails look: fonts, colors, spacing, layout. Webmail services let messages carry styling so newsletters and receipts look right, but they try to strip out anything dangerous before showing the message to you. That cleanup step is called sanitizing.
What the research showed
According to PortSwigger, webmail clients that display untrusted CSS inside their own trusted interface, and try to sanitize it, can be pushed past those safety boundaries to steal passwords, leak tokens and compromise third-party websites. The highlights:
- A fake login screen and a keylogger made of style code. PortSwigger says the research created a convincing fake login screen and a functional keylogger that worked with CSS and HTML that had already been filtered by a sanitizer.
- No JavaScript required. The Hacker News reported that the techniques can build a fake sign-in form that captures a password without JavaScript, run a CSS-only keylogger, track when an email is opened, overlay attacker content on the page, redirect clicks and leak tokens.
- Sanitizers missed a trick. PortSwigger says abusing HTML labels to trigger actions on form elements was missed by the HTML sanitizers of at least three webmail clients.
The webmail services studied were Yahoo Mail, AOL Mail, Fastmail, Proton Mail, Gmail and Outlook, according to PortSwigger and The Hacker News. On fixes, PortSwigger says two Fastmail bugs were fixed and that Gmail was still open to a tracking technique despite repeated reports. The Hacker News added that a Proton Mail bypass no longer worked on retest and that an Outlook technique still worked when the research was published. That status may change quickly, so check with your provider rather than relying on a snapshot.
Why does this matter for your business?
Many of us have learned to be careful with links and attachments. This research is a reminder that the message itself can be the trap: an email with neither removes two of the warning signs people are taught to look for.
It also plays on trust. The fake box appears inside the webmail tab your staff use all day, not on a strange website, so "it's inside Gmail, so it must be Gmail" feels reasonable. It isn't.
Where SPF, DKIM and DMARC fit
Be clear about what email authentication does here:
- What it doesn't do: SPF, DKIM and DMARC confirm which domain sent a message. They don't judge whether the content is safe. A booby-trapped email sent from an attacker's own, properly configured domain can pass all three.
- What it does do: if your domain has no enforced DMARC policy, an attacker can put your own domain in the From line, for example a message from "IT Support" at your company address asking staff to "re-enter your password to keep your mailbox." With DMARC at
p=reject, receiving servers can refuse that forgery. Check yours with our free domain scanner.
Why the sign-in method matters
A keylogger can only capture what people type. Microsoft describes passkeys as "phishing-resistant by design" because they use public-key cryptography rather than shared secrets, so there's no typed secret to steal. We covered why attackers now target sign-ins in our look at the Talos and IBM July reports.
Quick reference: who does what
| Action | Who | Why it helps |
|---|---|---|
| Never type a password into anything inside an email | Everyone | Defeats the fake login box, whatever the technique |
| Sign in only from a bookmark or the app | Everyone | Keeps you on the real sign-in page |
| Report odd-looking or "please sign in" emails | Everyone | Lets IT warn others and remove copies |
| Keep browsers, mail apps and devices updated | IT or the device owner | Picks up vendors' security fixes |
Enforce DMARC (p=reject) on your domain |
Domain owner | Lets receivers reject mail forging your exact domain |
| Move to passkeys or other phishing-resistant MFA | IT | A captured password alone is no longer enough to sign in |
What should you do now?
- Adopt one rule: login pages never live inside emails. A password field, sign-in box or "verify your account" form inside the message body is a red flag. Close the message and go to the service through your bookmark or by typing the address.
- Keep webmail, browsers and mail apps up to date. Restart when prompted so updates actually apply.
- Make reporting easy. Show staff where the "Report phishing" or "Report junk" button is in your mail app, and thank people who use it.
- Enforce DMARC on your domain. If you're still at
p=none, our DMARC setup guide walks through moving to quarantine and then reject safely. - Plan the move to phishing-resistant MFA, starting with administrators and anyone who handles payments.
- If someone did type a password into an email, change it right away from the real site, sign out other sessions, and tell whoever manages your email.
Frequently asked questions
Can just opening an email steal my password?
In this research, the password theft relied on the victim typing into a fake form or login box drawn inside the message. Opening the email alone could reveal that you opened it, since The Hacker News lists open-tracking among the techniques, but the keystrokes only leak if you type. That's why "never type credentials into an email" is such an effective rule.
Which email services were affected?
According to PortSwigger and The Hacker News, the research looked at Yahoo Mail, AOL Mail, Fastmail, Proton Mail, Gmail and Outlook. Vendors respond at different speeds: PortSwigger and The Hacker News reported that some fixes were already in place on publication day while other techniques still worked. Keep your apps updated and follow your provider's security notices.
Does DMARC stop CSS attacks?
Not directly. DMARC checks whether a message really comes from the domain in the From address; it doesn't inspect the styling or content. At quarantine or reject, it lets receiving servers block criminals forging your exact domain, so a fake "IT department" email is much harder to send from your company's own address. Pair it with the no-typing rule and phishing-resistant MFA.
What should I do if I typed my password into a suspicious email?
Act quickly. Change the password from the service's real website or app, sign out of other sessions if the service allows it, and turn on MFA if it isn't already on. Tell your IT contact or email provider so they can check for suspicious sign-ins or new mailbox rules. If the same password was used elsewhere, change it there too.
Sources
- PortSwigger Research — CSS: the bomb inside your inbox (August 6, 2026)
- The Hacker News — New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens (August 6, 2026)
- Business Wire — Black Hat USA Announces Over 100 Briefings for its 29th Anniversary Event in Las Vegas (June 2, 2026)
- Microsoft Security Blog — Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID (July 13, 2026)
- Microsoft Learn — Email authentication in cloud organizations (reference documentation, undated)
Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.