which loophole? I didn't see it mentioned in the article.
and this quote is not correct:
> Note that an email doesn't need to pass both DKIM and SPF. Just one is enough to validate an email.
Unless it was said in regards to DMARC, it usually depends on the mailfilter of the receiver. If it was said in regards to DMARC then it's just another point why DMARC is bad.
and this quote is not correct:
> Note that an email doesn't need to pass both DKIM and SPF. Just one is enough to validate an email.
Unless it was said in regards to DMARC, it usually depends on the mailfilter of the receiver. If it was said in regards to DMARC then it's just another point why DMARC is bad.