{"record":{"id":"0efefc6abc0ebe5b","repo":"santifer/career-ops","slug":"gmail-skipping-spoofed-unauthenticated-email-s","errorCode":null,"errorMessage":"gmail: skipping spoofed/unauthenticated email \"${subject}\"","messagePattern":"gmail: skipping spoofed/unauthenticated email \"(.+?)\"","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"plugins/gmail/index.mjs","lineNumber":122,"sourceCode":"    const seenUrls = new Set();\n    const jobs = [];\n\n    for (const m of messages) {\n      if (processedIds.has(m.id)) continue;\n      // Per-message resilience: a single bad detail fetch is skipped, not fatal.\n      let msg;\n      try {\n        msg = await (await ctx.fetch(`${GMAIL_API}/messages/${m.id}?format=full`, { headers: auth })).json();\n      } catch (err) {\n        console.warn(`gmail: failed to fetch message ${m.id} — ${err.message}`);\n        continue;\n      }\n      const headers = msg.payload?.headers || [];\n      const subject = headers.find(h => h.name?.toLowerCase() === 'subject')?.value || '';\n\n      // Fail-closed on spoofed mail (DMARC).\n      if (!isAuthenticEmail(headers)) {\n        console.warn(`gmail: skipping spoofed/unauthenticated email \"${subject}\"`);\n        processedIds.add(m.id);\n        continue;\n      }\n\n      const seed = parseRoleAtCompany(subject);\n      const cleanUrls = extractUrls(getMessageBody(msg.payload)).filter(isCleanUrl);\n      for (const url of cleanUrls) {\n        if (seenUrls.has(url)) continue;\n        seenUrls.add(url);\n        jobs.push({\n          title: seed?.role || 'Job lead (email)',\n          url,\n          company: companyFromUrl(url) || seed?.company || '',\n          location: '',\n        });\n      }\n      processedIds.add(m.id);\n    }","sourceCodeStart":104,"sourceCodeEnd":140,"githubUrl":"https://github.com/santifer/career-ops/blob/aac998c7ed7248ea853b720ceeb1fdbeb322fc5d/plugins/gmail/index.mjs#L104-L140","documentation":"The Gmail ingest path fail-closes on DMARC/authentication failures: when the message's headers do not pass isAuthenticEmail (missing/failing SPF, DKIM, or DMARC alignment), the email is skipped and its id is marked processed so it is never retried. This prevents spoofed job-reply emails from being ingested as trusted data.","triggerScenarios":"Ingesting a Gmail message whose Authentication-Results headers fail or lack authentication signals — spoofed senders, forwarded mail that strips auth headers, mailing-list rewrites, or a misconfigured sender domain (DMARC fail).","commonSituations":"A recruiter's mail server lacks a DMARC record; a company uses a forwarding service that breaks DKIM; phishing attempts impersonating a job board; legitimate mail re-sent through a legacy gateway.","solutions":["Verify the sender is legitimate out-of-band; if the domain is genuinely yours/partner's, fix its SPF/DKIM/DMARC records.","For forwarded mail, prefer fetching from the original mailbox/label rather than a forwarding chain that strips auth headers.","Check isAuthenticEmail's header parsing if ALL legitimate mail is being skipped (e.g. unusual Authentication-Results header layout from a custom gateway).","Do not bypass this check to ingest unauthenticated mail — it is deliberately fail-closed."],"exampleFix":"// before\n// spoofed mail skipped silently into processedIds\n// after: diagnose auth headers of a legit sender\n// confirm Authentication-Results contains spf=pass dkim=pass dmarc=pass\n// or add the gateway's ARC seals / whitelist path in isAuthenticEmail","handlingStrategy":"validation","validationCode":"function headersHaveAuth(headers) {\n  const ar = headers.find(h => h.name?.toLowerCase() === 'authentication-results')?.value || '';\n  return /dmarc\\s*=\\s*pass/i.test(ar);\n}","typeGuard":null,"tryCatchPattern":"if (!isAuthenticEmail(headers)) {\n  processedIds.add(m.id); // mark seen, never retry\n  console.warn(`gmail: skipping spoofed/unauthenticated email \"${subject}\"`);\n  return;\n}","preventionTips":["Never bypass the DMARC fail-closed gate to ingest unauthenticated mail.","For forwarded mail, ingest from the original mailbox/label instead of forwarding chains.","If a legit partner domain is skipped, fix its SPF/DKIM/DMARC rather than whitelisting blindly."],"tags":["email","security","dmarc","spoofing","gmail"],"backgroundTag":"authentication-required","analyzedSha":"aac998c7ed7248ea853b720ceeb1fdbeb322fc5d","analyzedAt":"2026-09-16T06:35:29.214Z","contentChangedAt":"2026-09-16T06:35:29.214Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}