Vunerability : spf
Unknown
Vulnerability Details
Heĺlo sir, im an independent security researcher. I found an vunerability in your website
Your website https://github.com/paragonie doesn't have valid spf records. To recover this do validate your spf. Sender Policy Framework (SPF): This allows you specify which mail servers are allowed to send mails for your domain. There is of course nothing to stop a spammer sending a mail from their mail server for your domain, but e-mail clients can then check the SPF policy for your site, see it's not on the approved list and then choose to either ignore the mail completely, or at least mark it as likely spam. For more details https://en.m.wikipedia.org/wiki/Sender_Policy_Framework
Regards,
Neeraj
Actions
View on HackerOneReport Stats
- Report ID: 130990
- State: Closed
- Substate: not-applicable
- Upvotes: 2