Hacker News new | ask | show | jobs
by throwaway2346mg 1075 days ago
I'm not sure if this is relevant in regards to the security disclosure itself. If you're not using Mailgun then this doesn't affect you.

However, with regards to "SPF is more than enough", the fact here is that the SPF header isn't passed to the webhook, so it can't used in a mailgun inbound route.