Check · Domain & email identity · default severity high
Email spoofing policy (DMARC)
What Kavach checks
DMARC tells the world's mail servers to reject email that fakes your domain.
Why it matters
Without an ENFORCING DMARC (p=quarantine/reject), anyone can send phishing that looks exactly like it came from you -- the root of most Business Email Compromise.
How an attacker uses it
- Attacker sends an invoice email 'from' ceo@yourcompany.com.
- With no enforcing DMARC, it lands in the inbox, fully trusted.
- Finance pays the attacker's bank details.
How to fix it
Publish a DMARC record and move to p=quarantine, then p=reject: v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 2.