Files
nuclei-templates/dns/spoofable-spf-records-ptr.yaml
2025-10-26 16:17:37 +00:00

25 lines
785 B
YAML

id: spoofable-spf-records-ptr
info:
name: Spoofable SPF Records with PTR Mechanism
author: binaryfigments
severity: info
description: SPF records in DNS containing a PTR mechanism are spoofable.
reference:
- https://www.digitalocean.com/community/tutorials/how-to-use-an-spf-record-to-prevent-spoofing-improve-e-mail-reliability
classification:
cwe-id: CWE-200
metadata:
max-request: 1
tags: dns,spf,discovery
dns:
- name: "{{FQDN}}"
type: TXT
matchers:
- type: word
words:
- "v=spf1"
- " ptr "
condition: and
# digest: 4a0a0047304502200b6d8acb41b41527a0a28b3eb1520883e46a9052e783672192350a431f6c1a9e02210088d3135e773f2831f15df45e53d841f81056bdcffa4d1b3e9b31bc279dd3a60a:922c64590222798bb761d5b6d8e72950