Hi Team ,
I hope you are doing well.
Any updates on my report?
Kind regards ,
Vaishnavi Pardeshi
Security Researcher
On Thu, Nov 26, 2020 at 10:10 PM Security Researcher <
vaishnaviresearcher(a)gmail.com> wrote:
Dear Team,
I am Vaishnavi Pardeshi working as a security researcher and I found a bug
in your website . Report of bug is as Follows .
a) VULNERABILITY TYPE- SPF RECORD NOT FOUND
b) HOW TO REPRODUCE(POC-ATTACHED IMAGE):-
1.GO TO-
https://www.kitterman.com/spf/validate.html
<https://mxtoolbox.com/>
2.put this " sparta.eu " and CLICK GET SPF RECORD
3.YOU WILL SEE THE FAULT(NO SPF RECORD FOUND )
4.In the new page that loads shows NO SPF RECORD FOUND
c) Impact
*Not* having *SPF* (Sender Policy Framework) record for a domain may help
an attacker to send spoofed email, which will look like, originated from
the real domain. *Not* only that, but this will also result in land
emails in the SPAM box when *SPF missing*.
d) Solution :
Enable SPF RECORD
Kind regards ,
Vaishnavi Pardeshi