Skip to content

standard

SPF

Email authentication standard (RFC 7208) letting domain owners publish DNS records naming authorized mail servers, helping detect spoofed senders.

Known aliases

  • RFC 7208
  • Sender Policy Framework
  • v=spf1

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

DMARC fails mail that passes SPF and DKIM under the wrong domain

Transactional mail can pass SPF and DKIM and still fail DMARC when neither aligns with the visible From domain, a dev.to Node.js guide shows. Because forwarding breaks SPF, the author treats aligned DKIM as the path to protect.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence50
invest5 publishers

Revolut released passports and Bitcoin histories on an email that passed domain authentication

The request came from an unauthorized account on a real government domain, and Revolut acted on it. The company calls the number of affected customers limited, and it declined to say how many or name the agency.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 55%
Investor
Investor 22%

Reality

Evidence68
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence66
build1 publisher

Two records for one DNS entry turn a verified badge into a drift check

A dev.to onboarding design keeps the SPF, DKIM and DMARC values you generated in one row and the answers a resolver returned in another. Its comparator is a single stripped string match, so an SPF value the customer appended to lands in drifted.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives20
Confidence60

Earlier coverage

  1. Email and Slack disagree on what a conversation is, and the join key is the envelope

    Build · August 15, 2026 · 1 publisher