santifer/career-ops · warning

gmail: skipping spoofed/unauthenticated email

Error message

gmail: skipping spoofed/unauthenticated email "${subject}"

What it means

The Gmail ingest path fail-closes on DMARC/authentication failures: when the message's headers do not pass isAuthenticEmail (missing/failing SPF, DKIM, or DMARC alignment), the email is skipped and its id is marked processed so it is never retried. This prevents spoofed job-reply emails from being ingested as trusted data.

Solutions

  1. Verify the sender is legitimate out-of-band; if the domain is genuinely yours/partner's, fix its SPF/DKIM/DMARC records.
  2. For forwarded mail, prefer fetching from the original mailbox/label rather than a forwarding chain that strips auth headers.
  3. Check isAuthenticEmail's header parsing if ALL legitimate mail is being skipped (e.g. unusual Authentication-Results header layout from a custom gateway).
  4. Do not bypass this check to ingest unauthenticated mail — it is deliberately fail-closed.

Example fix

// before
// spoofed mail skipped silently into processedIds
// after: diagnose auth headers of a legit sender
// confirm Authentication-Results contains spf=pass dkim=pass dmarc=pass
// or add the gateway's ARC seals / whitelist path in isAuthenticEmail
Defensive patterns

Strategy: validation

Validate before calling

function headersHaveAuth(headers) {
  const ar = headers.find(h => h.name?.toLowerCase() === 'authentication-results')?.value || '';
  return /dmarc\s*=\s*pass/i.test(ar);
}

Try / catch

if (!isAuthenticEmail(headers)) {
  processedIds.add(m.id); // mark seen, never retry
  console.warn(`gmail: skipping spoofed/unauthenticated email "${subject}"`);
  return;
}

Prevention

When it happens

Trigger: Ingesting a Gmail message whose Authentication-Results headers fail or lack authentication signals — spoofed senders, forwarded mail that strips auth headers, mailing-list rewrites, or a misconfigured sender domain (DMARC fail).

Common situations: A recruiter's mail server lacks a DMARC record; a company uses a forwarding service that breaks DKIM; phishing attempts impersonating a job board; legitimate mail re-sent through a legacy gateway.

Understand the failure class

Related errors


AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16). Data as JSON: /api/errors/0efefc6abc0ebe5b. Report an issue: GitHub.

Appendix: source

Thrown at plugins/gmail/index.mjs:122

    const seenUrls = new Set();
    const jobs = [];

    for (const m of messages) {
      if (processedIds.has(m.id)) continue;
      // Per-message resilience: a single bad detail fetch is skipped, not fatal.
      let msg;
      try {
        msg = await (await ctx.fetch(`${GMAIL_API}/messages/${m.id}?format=full`, { headers: auth })).json();
      } catch (err) {
        console.warn(`gmail: failed to fetch message ${m.id} — ${err.message}`);
        continue;
      }
      const headers = msg.payload?.headers || [];
      const subject = headers.find(h => h.name?.toLowerCase() === 'subject')?.value || '';

      // Fail-closed on spoofed mail (DMARC).
      if (!isAuthenticEmail(headers)) {
        console.warn(`gmail: skipping spoofed/unauthenticated email "${subject}"`);
        processedIds.add(m.id);
        continue;
      }

      const seed = parseRoleAtCompany(subject);
      const cleanUrls = extractUrls(getMessageBody(msg.payload)).filter(isCleanUrl);
      for (const url of cleanUrls) {
        if (seenUrls.has(url)) continue;
        seenUrls.add(url);
        jobs.push({
          title: seed?.role || 'Job lead (email)',
          url,
          company: companyFromUrl(url) || seed?.company || '',
          location: '',
        });
      }
      processedIds.add(m.id);
    }

View on GitHub (pinned to aac998c7ed)