Loading HuntDB...

No valid SPF record not found

P
Ping Identity
Submitted None

Team Summary

Official summary from Ping Identity

There are no SPF Records found for ort-admin.pingone.com ## Description: There is an email spoofing vulnerability. Email spoofing is the forgery of an email header so that the message appears to have originated from someone or somewhere other than the actual source. Email spoofing is a tactic used in phishing and spam campaigns because people are more likely to open an email when they think it has been sent by a legitimate source. The goal of email spoofing is to get recipients to open, and possibly even respond to, a solicitation. ## The TXT records found for your domain are: No valid SPF record found of either type TXT or type SPF. ## Remediation: Replace ~all with -all to prevent fake email. ## Impact: An attacker would send a Fake email. The results can be more dangerous to your customers and may lead to loss in your business. PROGRAM NOTE: This issue is well known and does not pose a concrete and exploitable risk to the platform, and therefore is not eligible for bounties.

Reported by aravindn

Report Details

Additional information and metadata

State

Closed

Substate

Duplicate

Submitted

Weakness

Improper Authentication - Generic