When you get an email from joe@example.com and example.com is trustworthy and uses SPF, then you know that the sender in fact was joe@example.com
It's easy enough to set up SPF for any domain.
Gmail, Yahoo, Outlook etc all use it.
When you get an email from joe@example.com and example.com is trustworthy and uses SPF, then you know that the sender in fact was joe@example.com
It's easy enough to set up SPF for any domain.
Gmail, Yahoo, Outlook etc all use it.
In addition, the limitations of DKIM also apply to SPF:
> DKIM is useful, but limited. All it does is verify that an email which claims to be from paypal.com is really from paypal.com. What it lacks is the ability to show warnings such as “this email wasn’t signed, do you want to trust it?” and “this signature isn’t recognized, yikes!”
Such a warning already exists: https://lifehacker.com/stop-looking-like-a-phisher-in-gmail-...
Source: spent years maintaining a broken or missing SPF whitelist..