Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How to prevent mail spoofing?

Nico
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 3, 2020

If you forge the from: header in a mail send to Jira to match the mail address of a registered user, Jira will create an issue and set the reporter to the registered user, even though the mail header says:

Authentication-Results: mx.google.com; spf=fail (google.com: domain of <email address> does not designate <IP address> as permitted sender) [...]

Is there a way to set the reporter for an issue created from a mail that failed basic SPF checks to "unknown"?

0 answers

Suggest an answer

Log in or Sign up to answer