Newly added security tests, July 26, 2017: CVE-2017-9791
To bring you the most up-to-date security service and help you stay on top of threats, we update Detectify on a regular basis. Here are …

To bring you the most up-to-date security service and help you stay on top of threats, we update Detectify on a regular basis. Here are …

To prevent email spoofing, it is important to manually configure email authentication systems to the highest standard. This is a complicated process that often results in misconfigured email servers or companies simply skipping authentication and leaving their domain at risk of being spoofed. Here you can find our SPF research as well as a guide to help you configure your email server’s authentication.

Missing SPF records are a common and long-standing security issue that puts sensitive information at risk. To get a better idea of just how widespread the problem is, the Detectify team decided to scan the 500 top-ranked Alexa sites for it. We found that less than half of those domains have configured email authentication correctly to prevent spoofed emails being sent from their domains, which means that users are at risk of receiving false emails appearing to come from domains that they trust. To prevent spoofed emails, all systems must be manually configured correctly to the highest standard of authentication. Unfortunately, the process is complicated, and often servers are misconfigured. The Detectify team has put together an extensive guide to help you check if your domain is at risk of forced spoofed emails, and also give you the tools to configure the authentication correctly.