Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

SPF doesn't verify the sender, it only tells you if the server is allowed to send mail from a domain. You can still use the password for your account to forge the sending address of another user in the domain. Besides, the fact that your domain requires a password is only meaningful to you; it has no value to the outside world in terms of identity assurance.


>You can still use the password for your account to forge the sending address of another user in the domain.

Very few mail servers allow you to that. Once you add sender authentication, it generally comes with sender authorization.

>Besides, the fact that your domain requires a password is only meaningful to you

Almost all SMTP servers are locked down now, most requiring authentication. Those that aren't get blacklisted pretty quickly.

SPF tells you that the sender is authorized to send on behalf of that person.

It solves 99.9% of the issue.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: