Kavach

Check · Domain & email identity · default severity medium

Email sender authorization (SPF)

What Kavach checks

SPF lists which servers are allowed to send mail as your domain.

Why it matters

A missing or `+all` SPF lets attackers send as you and weakens DMARC, which depends on SPF alignment.

How an attacker uses it

  1. Attacker's server sends mail claiming to be your domain.
  2. No SPF (or +all) means receiving servers can't tell it's fake.

How to fix it

Publish an SPF TXT record listing only your real senders and ending in -all.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 2.

Scan your site free → Monitor it continuously