[GH-ISSUE #2465] Email spoofing, DMARC records are disable, DNS records also not found #685

Open
opened 2026-02-26 18:48:04 +03:00 by kerem · 1 comment
Owner

Originally created by @wibewithme on GitHub (Feb 10, 2026).
Original GitHub issue: https://github.com/documenso/documenso/issues/2465

Issue Description

If DMARC is not enable then any attacker can send email on the behalf of yours email address.

Steps to Reproduce

Go to the website Documenso.com.
click sign up.
you will get the email in your inbox.
collect the company's email from their and go the the website emkei.cz (to send a fake mail on the behalf of the company)
now fill all the requirements and send it to any other email address.
the another user will get mail from the documenso's email address.

Expected Behavior

nobody can send email on the behalf of the company's email.
it can lead to massive attack perform with phishing and more than a phising.
can spoil the company reputation.

Current Behavior

the current behavior is that any attack can send the email to any user on the behalf of the company's email.

Screenshots (optional)

I don't know hereby how to upload the screenshots. but you can follow my steps to get the bug.
if you face any issue then please drop me a email on "legendaniljoshi12@gmail.com".

Operating System [e.g., Windows 10]

kali linux

Browser [e.g., Chrome, Firefox]

firefox

Version [e.g., 2.0.1]

No response

Please check the boxes that apply to this issue report.

  • I have searched the existing issues to make sure this is not a duplicate.
  • I have provided steps to reproduce the issue.
  • I have included relevant environment information.
  • I have included any relevant screenshots.
  • I understand that this is a voluntary contribution and that there is no guarantee of resolution.
  • I want to work on creating a PR for this issue if approved
Originally created by @wibewithme on GitHub (Feb 10, 2026). Original GitHub issue: https://github.com/documenso/documenso/issues/2465 ### Issue Description If DMARC is not enable then any attacker can send email on the behalf of yours email address. ### Steps to Reproduce Go to the website Documenso.com. click sign up. you will get the email in your inbox. collect the company's email from their and go the the website emkei.cz (to send a fake mail on the behalf of the company) now fill all the requirements and send it to any other email address. the another user will get mail from the documenso's email address. ### Expected Behavior nobody can send email on the behalf of the company's email. it can lead to massive attack perform with phishing and more than a phising. can spoil the company reputation. ### Current Behavior the current behavior is that any attack can send the email to any user on the behalf of the company's email. ### Screenshots (optional) I don't know hereby how to upload the screenshots. but you can follow my steps to get the bug. if you face any issue then please drop me a email on "legendaniljoshi12@gmail.com". ### Operating System [e.g., Windows 10] kali linux ### Browser [e.g., Chrome, Firefox] firefox ### Version [e.g., 2.0.1] _No response_ ### Please check the boxes that apply to this issue report. - [x] I have searched the existing issues to make sure this is not a duplicate. - [x] I have provided steps to reproduce the issue. - [x] I have included relevant environment information. - [ ] I have included any relevant screenshots. - [ ] I understand that this is a voluntary contribution and that there is no guarantee of resolution. - [ ] I want to work on creating a PR for this issue if approved
Author
Owner

@github-actions[bot] commented on GitHub (Feb 10, 2026):

Thank you for opening your first issue and for being a part of the open signing revolution!

One of our team members will review it and get back to you as soon as it possible 💚

Meanwhile, please feel free to hop into our community in Discord

<!-- gh-comment-id:3876005045 --> @github-actions[bot] commented on GitHub (Feb 10, 2026): Thank you for opening your first issue and for being a part of the open signing revolution! <br /> One of our team members will review it and get back to you as soon as it possible 💚 <br /> Meanwhile, please feel free to hop into our community in [Discord](https://documen.so/discord)
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/documenso#685
No description provided.