mail from launchpad can be spoofed by spammers

Bug #387321 reported by Craig
288
This bug affects 4 people
Affects Status Importance Assigned to Milestone
Launchpad itself
In Progress
Low
Unassigned

Bug Description

The launchpad.net domain does not have SPF or DKIM records, which means that other mail systems can masquerade as launchpad.net very easily and send spam as if they were the real launchpad.net mail servers.

visibility: private → public
affects: launchpad → launchpad-foundations
tags: added: email
Curtis Hovey (sinzui)
Changed in launchpad-foundations:
status: New → Triaged
importance: Undecided → Low
tags: added: feature
Revision history for this message
Gary Poster (gary) wrote :

RT 46019

Changed in launchpad:
assignee: nobody → Canonical LOSAs (canonical-losas)
Revision history for this message
Robert Collins (lifeless) wrote :

We're not going to add SPF records, but we will add DKIM signatures to things eventually - the RT is still open for doing that.

summary: - Add SPF records to protect against spam
+ mail from launchpad can be spoofed by spammers
description: updated
margaret yeager (1shult)
Changed in launchpad:
status: Triaged → Fix Released
Changed in ubuntu:
status: New → Fix Released
William Grant (wgrant)
Changed in launchpad:
status: Fix Released → Triaged
no longer affects: ubuntu
Revision history for this message
LaMont Jones (lamont) wrote :

RT#41726 is the relevant ticket, not 46019.

Changed in launchpad:
assignee: Canonical WebOps (canonical-losas) → William Grant (wgrant)
William Grant (wgrant)
Changed in launchpad:
assignee: William Grant (wgrant) → nobody
Revision history for this message
Colin Watson (cjwatson) wrote :

The new relevant internal ticket is https://portal.admin.canonical.com/C123312.

Revision history for this message
Colin Watson (cjwatson) wrote :

This is in progress, though the SPF policy still falls back to softfail for now:

  $ dig +short -t txt launchpad.net
  "v=spf1 ip4:185.125.188.250 ip4:185.125.188.251 ip4:91.189.90.7 ip4:91.189.95.10 ~all"

Email from Launchpad is now DKIM-signed provided that its From: address is @launchpad.net or a subdomain (needed to comply with DMARC). The bulk of Launchpad's outgoing email is bugs, code review, and answers, and that now meets those requirements, but there's a long tail of other types of email we send that will need to be audited.

Changed in launchpad:
status: Triaged → In Progress
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Related questions

Remote bug watches

Bug watches keep track of this bug in other bug trackers.