SShortSingh.
Back to feed

SPF Lookup Counter Bug Undercounted GitHub's DNS Limit, Leaving It at the Edge

0
·3 views

A developer discovered that their free SPF-checking tool incorrectly reported GitHub's SPF record as using 8 of the allowed 10 DNS lookups, when the true count is exactly 10. The error stemmed from counting only the include directives in GitHub's own record, without recursively evaluating the nested records inside each included domain. RFC 7208 caps SPF evaluation at 10 DNS-triggering lookups across the entire include tree, not just the top-level record. Two hidden lookups — one inside Salesforce's record via an exists: macro and one inside SendGrid's record via a nested include — pushed GitHub's real total to the limit. The developer has since corrected the tool to walk the full include tree and published a Node.js code snippet demonstrating how to count lookups accurately using Google's DNS-over-HTTPS API.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

AI in Benefits Administration: Architecture and Compliance Now Drive Software Purchases

As of 2026, the central concern in AI-powered benefits administration has shifted from automation potential to accountability — specifically, whether employers can demonstrate how AI reached a benefits decision. Legal and regulatory scrutiny around AI in plan administration is intensifying, according to mid-2026 benefits-law analysis. A Software Advice report found that integration quality influenced 33% of benefits software purchases, while AI capabilities drove 26%, making system architecture a top buying criterion. Experts recommend keeping core eligibility, deduction, and compliance logic deterministic, with AI confined to support functions such as plan explanations, document extraction, and anomaly detection. Every AI action should pass policy, identity, and schema validation checks before execution, with full audit trails maintained throughout.

0
ProgrammingDEV Community ·

Developer Reflects on Earning LeetCode's 365-Day Submission Badge

A software developer has earned LeetCode's 365 Days Badge after accumulating over 365 days of problem submissions on the platform. The milestone represents total submission days rather than a consecutive daily streak, a distinction the developer highlights as meaningful. Over this period, the developer focused on building skills across data structures and algorithms, Java, backend engineering, and problem solving. The experience reinforced the idea that learning software engineering is non-linear, with some problems solved quickly and others requiring repeated attempts. The developer frames the achievement not as a measure of skill, but as evidence of sustained effort and consistency over time.

0
ProgrammingDEV Community ·

Why Real-World OCR Fails on Phone-Captured Documents and How to Fix It

Most document-automation pipelines are built and tested on clean digital PDFs, but real-world inputs captured via phone cameras introduce skew, uneven lighting, and perspective distortion that cause OCR engines to silently return wrong results. The core problem is that these failures are not loud — the system produces output that appears valid but contains extraction errors, often concentrated in high-stakes fields like dates, amounts, and quantities. Preprocessing steps such as adaptive thresholding and deskewing can resolve the majority of phone-capture failures before any OCR engine is applied. Beyond preprocessing, production-grade systems should assign confidence scores to every extraction and route low-confidence results to a human-review queue rather than directly into records. Treating raw accuracy as the primary metric is misleading; what matters is whether the system reliably signals uncertainty and maintains an audit trail for every automated decision.

0
ProgrammingDEV Community ·

gstack Wraps AI Coding Agents With Structured Engineering Workflows

gstack is an open-source project by Garry Tan that adds a structured software engineering process on top of existing AI coding agents like Claude Code, rather than replacing them. The project provides 23 specialized roles — including product review, security analysis, browser-based QA, and release preparation — exposed as slash commands written in Markdown. These roles are designed to run in sequence, mimicking a sprint cycle where each skill passes its output to the next, creating a virtual engineering team workflow. gstack is not tied to a single AI agent; its setup script auto-detects installed agents and supports tools such as Cursor, Codex CLI, and others. The project is MIT licensed, built with TypeScript and Bun, and positions itself as a process layer rather than a standalone platform or foundation model.