Hi — not a code issue, sorry. This is about the domain in this repo's homepage, and I thought you would rather know than not.
What I found
classifier.dev has SPF but no DMARC record. _dmarc.classifier.dev does not exist.
This is the gap people miss: SPF authenticates the envelope sender, not the From: header your recipient actually sees. Without DMARC nothing ties the two together, so your classifier.dev SPF record ("v=spf1 include:_spf.mx.cloudflare.net ~all") does not stop someone putting From: billing@classifier.dev on a message. DMARC is the part that makes SPF count.
Verify it yourself in one line:
dig +short TXT _dmarc.classifier.dev
dig +short TXT classifier.dev | grep spf1
The fix — free, no strings
Add this TXT record and you go from nothing to full visibility immediately, with zero risk of losing real mail (p=none does not affect delivery):
Host: _dmarc.classifier.dev
Type: TXT
Value: v=DMARC1; p=none; rua=mailto:dmarc@classifier.dev; fo=1
That is genuinely the whole first step. Point rua at a mailbox you read, wait a week, and the aggregate reports will show you every system sending as classifier.dev — usually a couple you forgot about (a billing tool, a CRM, an old marketing platform). Once those are all passing, you move to p=quarantine and then p=reject, and spoofing stops working.
If you would rather not run that project
The record above is easy. The part that eats time is the middle bit — reading the XML aggregate reports, hunting down every legitimate sender, getting SPF and DKIM aligned for each one, and stepping the policy up without silently dropping your own invoices or password resets. That is the part people start and abandon at p=none for years.
I do that as a fixed-scope job: $90, about two weeks, and you end at p=reject with a one-page sender inventory. No retainer, no subscription — you pay when it is done and enforcing. If it turns out your setup is trivial I will say so and you can finish it yourself for free.
Either way, please add the record. Reply here if you want the paid version or if anything above does not match what you see.
— Fayaz Bin Salam (@p32929)
Hi — not a code issue, sorry. This is about the domain in this repo's homepage, and I thought you would rather know than not.
What I found
classifier.devhas SPF but no DMARC record._dmarc.classifier.devdoes not exist.This is the gap people miss: SPF authenticates the envelope sender, not the
From:header your recipient actually sees. Without DMARC nothing ties the two together, so yourclassifier.devSPF record ("v=spf1 include:_spf.mx.cloudflare.net ~all") does not stop someone puttingFrom: billing@classifier.devon a message. DMARC is the part that makes SPF count.Verify it yourself in one line:
The fix — free, no strings
Add this TXT record and you go from nothing to full visibility immediately, with zero risk of losing real mail (
p=nonedoes not affect delivery):That is genuinely the whole first step. Point
ruaat a mailbox you read, wait a week, and the aggregate reports will show you every system sending asclassifier.dev— usually a couple you forgot about (a billing tool, a CRM, an old marketing platform). Once those are all passing, you move top=quarantineand thenp=reject, and spoofing stops working.If you would rather not run that project
The record above is easy. The part that eats time is the middle bit — reading the XML aggregate reports, hunting down every legitimate sender, getting SPF and DKIM aligned for each one, and stepping the policy up without silently dropping your own invoices or password resets. That is the part people start and abandon at
p=nonefor years.I do that as a fixed-scope job: $90, about two weeks, and you end at
p=rejectwith a one-page sender inventory. No retainer, no subscription — you pay when it is done and enforcing. If it turns out your setup is trivial I will say so and you can finish it yourself for free.Either way, please add the record. Reply here if you want the paid version or if anything above does not match what you see.
— Fayaz Bin Salam (@p32929)