Skip to content

Email Security policies #10151

@dotBATmanNO

Description

@dotBATmanNO

What:
js.org and (many of) its subdomains fail to restrict attackers from sending fraudulent e-mails.

Why:
The main js.org domain has a DMARC policy of "none"
Subdomains, such as npm.js.org, fail to specify both SPF and DMARC

Impact
Fraudulent e-mails can have an impact on

  • Integrity; The attackers can exploit the trust js.org (and subdomains) holds with all of the contributors, this trust could deteriorate.
  • Availability; Sites that have been abused for spam or phishing will be blocked in spam filters, this could trigger the domains to be blocked by firewalls as "malicious".

More information:
A lot of resources offer strong advice on e-mail security policies,
One such service is https://internet.nl

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions