SPF.Guru

Reporting a security issue

Email security@spf.guru. You will get a reply. This page says what is worth reporting, what is not, and what happens next, so that nobody spends an afternoon on something that was never going to go anywhere.

There is no bug bounty. SPF Guru is free, has no revenue and is run by one person. Reports are read and acted on, and you will be credited if you want to be, but nobody is paid. If a payout is what you are looking for, this is not the place, and saying so here is more honest than letting you find out after the work.

In scope

Anything on https://spf.guru and the DNS names this service answers on:

Not in scope

Not because these are unwelcome, but because they are already known, already decided, or not this site's to fix:

What to send

Enough to reproduce it. A URL, the input, what you expected, what happened. If it needs a specific domain or a specific sending address, say which. Video is rarely necessary; the exact request usually is.

What happens next

Testing against the live site

Reasonable testing is fine and needs no permission. Automated scanning at volume is not: it costs real DNS queries against other people's nameservers, which is unfair to them rather than to us. If you need to run something heavy, say so first and we will work out how.

Never test with a domain you do not control if the test involves anything other than reading its public DNS.

Machine-readable version. The same contact details are at /.well-known/security.txt, per RFC 9116.

This is a free, best-effort service. The disclaimer covers what that means for relying on it.