> Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates?
I'm honestly not 100% sure, but I think in the context of a phishing site using trademarks like that falls under fair use. But IANAL.
> Github has spf records setup so I would be interested to know how you manage to spoof the actual email address itself without getting flagged as spam.
I don't know much about spf records, honestly--for every site I had to try multiple "From" and "Reply-To" addresses to get the emails past gmail's spam filter. Some of them didn't even arrive in my spam folder, (apparently they just got killed on some intermediate hop). support@github.com definitely works, at least for me--you should try it yourself and see how it goes.
Hope this helps!