Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Simple. Their ip addresses of their client/guest-servers are whitelisted in the SPF records. So anyone can impersonate them.

Not 100% sure if that was the case now, as I can't find the email anymore, but I've been getting them from both sendgrid and mailgun.

Mailgun's SPF (was at least):

  v=spf1 include:spf1.mailgun.org include:spf2.mailgun.org include:_spf.google.com include:aspmx.pardot.com include:mail.zendesk.com include:spf.mailjet.com ~all

  spf1.mailgun.org: v=spf1 ip4:104.130.122.0/23 ip4:146.20.112.0/26 ip4:141.193.32.0/23 ip4:161.38.192.0/20 ~all

  v=spf1 ip4:209.61.151.0/24 ip4:166.78.68.0/22 ip4:198.61.254.0/23 ip4:192.237.158.0/23 ip4:23.253.182.0/23 ip4:104.130.96.0/28 ip4:146.20.113.0/24 ip4:146.20.191.0/24 ip4:159.135.224.0/20 ip4:69.72.32.0/20 ~all
In the mailgun case I received mails from for example 198.61.254.24 with from: invoice@mailgun.com

This is actually part of a bigger issue, where lots of people use the same email service to send out emails. In theory that should work with gmail or office365, but iirc gmail forces your from sometimes, and google+ms probably thought about this, right? ;)



I'm surprised they give clients access to their own DKIM.


It doesn't pass DKIM. But the fact that it's sent through Sendgrid's platform gives the e-mail credibility. Because no one expects Sendgrid to allow random customers to set e-mail (not necessarily envelope) from address to @sendgrid.com.


Based on my experience with sendgrid it's par for the course.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: