_extract_email_address took the FIRST <...> pair, so From: "Victim <victim@example.com>" <attacker@evil.test> resolved to the victim. The attacker's own domain passes DMARC truthfully, so the allowlist (EMAIL_ALLOWED_USERS), pairing and session identity were all evaluated against an address the sender does not control. Use email.utils.parseaddr, which keeps the quoted text as the display name and returns the real addr-spec. RFC 5322 folding is unfolded first so a folded quoted display name is not mistaken for the mailbox. Salvages #124322.