4 ms·
I run a domain for our community association. I had an “ethical hacker” discover that I had neglected to set up spf records for that domain. I had to deal with
by ipython 3y ago
I run a domain for our community association. I had an “ethical hacker” discover that I had neglected to set up spf records for that domain. I had to deal with him sending a bunch of nasty emails to our other board members after I refused to pay him for his “discovery”. (Actually I offered him a cut of my salary as a board member, which at $0, came out to be… less than he was hoping for)
I’ll definitely keep a link to this for next time this happens.
- aidos 3y agoAs a general rule, you really do want to set up SPF, dkim and dmarc. Without them there’s a real vulnerability there. The annoying case is when you have them correctly configured but are using ~all instead of -all so you still need to deal with the beg bounties.
- blincoln 3y agoYeah, I'm honestly surprised the organization is able to email anyone else. Even 8-10 years ago, I would have expected the major providers to drop email sent from a host without some or all of those elements configured.