top | item 25802881

(no title)

lkurtz | 5 years ago

Only if they’re used. There are no DMARC records in place for harvard.edu or subdomains, which is kinda shocking.

discuss

order

oefrha|5 years ago

The lack of DMARC records, even if it could facilitate spoofing, won’t magically make reply emails addressed at a valid @harvard.edu address land in a spoofer’s inbox. A different Reply-To address is possible but then you can’t claim a lack of warning signal. There’s something else going on.