How to deal with bogus security reports?
We started to receive a lot of questionable security reports to our security@domain mail. All are from India, all use gmail addresses. Usually they claim that there is no DMARC (but they did not bother to check SPF). Or they get 302 from our server and use <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> to claim: "The information can be used by attackers for further finding of exploits and information gathering."
They are partly like scams, but reporting them to google gmail did not help. Any clue?