Skip to content

Centrifuge - #1 Vulnerability Report (Missing DMARC Record) #2

@roony0072

Description

@roony0072

Dear Team,

I found an weak spot on your website.

Vulnerability Name: Missing DMARC Record

Vulnerable URL: centrifuge.io

Email spoofing is possible due to missing DMARC Records.

Due to this Server Security Misconfiguration > Mail Server Misconfiguration > Email Spoofing to Inbox due to Missing or Misconfigured DMARC on Email Domain.

To check DMARC record.
Link: https://mxtoolbox.com/DMARC.aspx

As said by you for DMARC you don't want to reject any messages you can set 'P=None'
DMARC

Attached screenshot for your reference.
centrifugeDMARC

Regards,
Rohan Patil

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions