Hi — not a code issue, sorry. This is about the domain in this repo's homepage, and I thought you would rather know than not.
What I found
openflowkit.com has SPF but no DMARC record. _dmarc.openflowkit.com does not exist.
This is the gap people miss: SPF authenticates the envelope sender, not the From: header your recipient actually sees. Without DMARC nothing ties the two together, so your openflowkit.com SPF record ("v=spf1 include:_spf.mx.cloudflare.net ~all") does not stop someone putting From: billing@openflowkit.com on a message. DMARC is the part that makes SPF count.
Verify it yourself in one line:
dig +short TXT _dmarc.openflowkit.com
dig +short TXT openflowkit.com | grep spf1
The fix — free, no strings
Add this TXT record and you go from nothing to full visibility immediately, with zero risk of losing real mail (p=none does not affect delivery):
Host: _dmarc.openflowkit.com
Type: TXT
Value: v=DMARC1; p=none; rua=mailto:dmarc@openflowkit.com; fo=1
That is genuinely the whole first step. Point rua at a mailbox you read, wait a week, and the aggregate reports will show you every system sending as openflowkit.com — usually a couple you forgot about (a billing tool, a CRM, an old marketing platform). Once those are all passing, you move to p=quarantine and then p=reject, and spoofing stops working.
If you would rather not run that project
The record above is easy. The part that eats time is the middle bit — reading the XML aggregate reports, hunting down every legitimate sender, getting SPF and DKIM aligned for each one, and stepping the policy up without silently dropping your own invoices or password resets. That is the part people start and abandon at p=none for years.
I do that as a fixed-scope job: $90, about two weeks, and you end at p=reject with a one-page sender inventory. No retainer, no subscription — you pay when it is done and enforcing. If it turns out your setup is trivial I will say so and you can finish it yourself for free.
Either way, please add the record. Reply here if you want the paid version or if anything above does not match what you see.
— Fayaz Bin Salam (@p32929)
Hi — not a code issue, sorry. This is about the domain in this repo's homepage, and I thought you would rather know than not.
What I found
openflowkit.comhas SPF but no DMARC record._dmarc.openflowkit.comdoes not exist.This is the gap people miss: SPF authenticates the envelope sender, not the
From:header your recipient actually sees. Without DMARC nothing ties the two together, so youropenflowkit.comSPF record ("v=spf1 include:_spf.mx.cloudflare.net ~all") does not stop someone puttingFrom: billing@openflowkit.comon a message. DMARC is the part that makes SPF count.Verify it yourself in one line:
The fix — free, no strings
Add this TXT record and you go from nothing to full visibility immediately, with zero risk of losing real mail (
p=nonedoes not affect delivery):That is genuinely the whole first step. Point
ruaat a mailbox you read, wait a week, and the aggregate reports will show you every system sending asopenflowkit.com— usually a couple you forgot about (a billing tool, a CRM, an old marketing platform). Once those are all passing, you move top=quarantineand thenp=reject, and spoofing stops working.If you would rather not run that project
The record above is easy. The part that eats time is the middle bit — reading the XML aggregate reports, hunting down every legitimate sender, getting SPF and DKIM aligned for each one, and stepping the policy up without silently dropping your own invoices or password resets. That is the part people start and abandon at
p=nonefor years.I do that as a fixed-scope job: $90, about two weeks, and you end at
p=rejectwith a one-page sender inventory. No retainer, no subscription — you pay when it is done and enforcing. If it turns out your setup is trivial I will say so and you can finish it yourself for free.Either way, please add the record. Reply here if you want the paid version or if anything above does not match what you see.
— Fayaz Bin Salam (@p32929)