santifer/career-ops · warning
gmail: skipping spoofed/unauthenticated email
Error message
gmail: skipping spoofed/unauthenticated email "${subject}" What it means
The Gmail ingest path fail-closes on DMARC/authentication failures: when the message's headers do not pass isAuthenticEmail (missing/failing SPF, DKIM, or DMARC alignment), the email is skipped and its id is marked processed so it is never retried. This prevents spoofed job-reply emails from being ingested as trusted data.
Solutions
- Verify the sender is legitimate out-of-band; if the domain is genuinely yours/partner's, fix its SPF/DKIM/DMARC records.
- For forwarded mail, prefer fetching from the original mailbox/label rather than a forwarding chain that strips auth headers.
- Check isAuthenticEmail's header parsing if ALL legitimate mail is being skipped (e.g. unusual Authentication-Results header layout from a custom gateway).
- Do not bypass this check to ingest unauthenticated mail — it is deliberately fail-closed.
Example fix
// before // spoofed mail skipped silently into processedIds // after: diagnose auth headers of a legit sender // confirm Authentication-Results contains spf=pass dkim=pass dmarc=pass // or add the gateway's ARC seals / whitelist path in isAuthenticEmail
Defensive patterns
Strategy: validation
Validate before calling
function headersHaveAuth(headers) {
const ar = headers.find(h => h.name?.toLowerCase() === 'authentication-results')?.value || '';
return /dmarc\s*=\s*pass/i.test(ar);
} Try / catch
if (!isAuthenticEmail(headers)) {
processedIds.add(m.id); // mark seen, never retry
console.warn(`gmail: skipping spoofed/unauthenticated email "${subject}"`);
return;
} Prevention
- Never bypass the DMARC fail-closed gate to ingest unauthenticated mail.
- For forwarded mail, ingest from the original mailbox/label instead of forwarding chains.
- If a legit partner domain is skipped, fix its SPF/DKIM/DMARC rather than whitelisting blindly.
When it happens
Trigger: Ingesting a Gmail message whose Authentication-Results headers fail or lack authentication signals — spoofed senders, forwarded mail that strips auth headers, mailing-list rewrites, or a misconfigured sender domain (DMARC fail).
Common situations: A recruiter's mail server lacks a DMARC record; a company uses a forwarding service that breaks DKIM; phishing attempts impersonating a job board; legitimate mail re-sent through a legacy gateway.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- a 40-hex commit --sha is required
- a16z-speedrun-talent: URL must use HTTPS
- Access denied: Egress guard blocked private target IP
- Access denied: Egress guard blocked private target IP
- Access denied: Egress guard blocked private target IPv6
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/0efefc6abc0ebe5b.
Report an issue: GitHub.
Appendix: source
Thrown at plugins/gmail/index.mjs:122
const seenUrls = new Set();
const jobs = [];
for (const m of messages) {
if (processedIds.has(m.id)) continue;
// Per-message resilience: a single bad detail fetch is skipped, not fatal.
let msg;
try {
msg = await (await ctx.fetch(`${GMAIL_API}/messages/${m.id}?format=full`, { headers: auth })).json();
} catch (err) {
console.warn(`gmail: failed to fetch message ${m.id} — ${err.message}`);
continue;
}
const headers = msg.payload?.headers || [];
const subject = headers.find(h => h.name?.toLowerCase() === 'subject')?.value || '';
// Fail-closed on spoofed mail (DMARC).
if (!isAuthenticEmail(headers)) {
console.warn(`gmail: skipping spoofed/unauthenticated email "${subject}"`);
processedIds.add(m.id);
continue;
}
const seed = parseRoleAtCompany(subject);
const cleanUrls = extractUrls(getMessageBody(msg.payload)).filter(isCleanUrl);
for (const url of cleanUrls) {
if (seenUrls.has(url)) continue;
seenUrls.add(url);
jobs.push({
title: seed?.role || 'Job lead (email)',
url,
company: companyFromUrl(url) || seed?.company || '',
location: '',
});
}
processedIds.add(m.id);
}View on GitHub (pinned to aac998c7ed)