Scan rule · RSC-SEC-100
Phishing-ready: mail spoofing plus login (composite)
SecuritySeverity: MediumCWE-290
Combines a domain without SPF/DMARC with a login or contact form on the site — the ingredients of a credible phishing mail in the domain's name.
Scan tier
External scan (anonymous)
How to fix it
Publish SPF and DMARC records (DMARC at least `p=quarantine`) and protect login pages with a second factor.