Vulnerabilities in SPF

I mentioned in a previous post that DKIM and SPF have known vulnerabilities. SPF has two that are currently being exploited. The first one exploits over-broad include mechanisms and what constitutes SPF being considered to pass. For example if the SPF record for domain.victim looked like this: v=spf1 +include:_spf.google.com +include:hosting.provider ~all If you can control an IP within the range covered by hosting.provider then you can do something like this: SMTP HELO/EHLO address: kflynn@domain.hacker ...

July 19, 2026 · 2 min · Ken O'Driscoll

New Sender Requirements 2024

2024 Update: Gmail and Yahoo! Change Their Sending Requirements Last updated: 10 August 2024 Refer to Chapter 8 (Sender Reputation) and Chapter 11 (Email Authentication) of Email Deliverability Explained (2nd edition) for background information on topics discussed in this post. Back in October 2023 Google and Yahoo! simultaneously announced that they would begin enforcing new requirements for bulk senders from February 2024 onwards. By June 2024 all of the new requirements are officially being enforced. ...

August 10, 2024 · 9 min · Ken O'Driscoll