Check · Domain & email identity · default severity medium
Email sender authorization (SPF)
What Kavach checks
SPF lists which servers are allowed to send mail as your domain.
Why it matters
A missing or `+all` SPF lets attackers send as you and weakens DMARC, which depends on SPF alignment.
How an attacker uses it
- Attacker's server sends mail claiming to be your domain.
- No SPF (or +all) means receiving servers can't tell it's fake.
How to fix it
Publish an SPF TXT record listing only your real senders and ending in -all.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 2.