While auditing apex TXT records I found five further vendor tokens that are self-identifying but
corroborate on too few domains to meet the ten-link bar in CONTRIBUTING.md, plus one token I cannot
attribute to a vendor at all. Raising them here rather than in a pull request.
Corpus: 6215 TXT records from 178 mutually independent apex domains, resolver 1.1.1.1. Zero false
positives for all patterns below.
| Candidate |
Pattern |
Domains |
Records |
| Cisco Intersight |
^intersight= |
8 |
12 |
| Trend Micro Email Security |
^tmes= |
5 |
7 |
| Axway Amplify |
axway-amplify= |
2 |
7 |
| Adobe Experience Manager |
^_aemverification\. |
1 |
6 |
| unattributed |
work-accounts-domain-verification= |
5 |
6 |
Details:
- Cisco Intersight —
intersight=<64 hex>, observed on bradesco.com.br, ibm.com, infosys.com, paypal.com, stone.com.br, theguardian.com, vale.com, wipro.com.
- Trend Micro Email Security —
tmes=<32 hex>, observed on assai.com.br, bradesco.com.br, braskem.com.br, infosys.com, suzano.com.br.
Corroborated internally: the same domains carry include:spf-us.tmes.trendmicro.com in their SPF.
- Axway Amplify —
axway-amplify=<uuid>, observed on bosch.com, bradesco.com.br.
- Adobe Experience Manager —
_aemverification.<env>-publish-aem.<domain>, observed on
santander.com.br only. Interesting because it also leaks the
environment name (dev/stage/prod), but a single domain is not a fingerprint.
work-accounts-domain-verification= — 5 domains (bradesco.com.br, databricks.com, flipkart.com, google.com, wise.com). I could not find
public documentation tying this token to a vendor, so I am not proposing a technology for it. If a
maintainer recognises it, I will happily write the entry and the corroboration.
Question: is the ten-link rule a hard bar for dns.TXT fingerprints specifically? A verification
token is self-identifying in a way a scriptSrc pattern is not, and measured on this same corpus the
catalog already carries loom-verification (4 domains),
windsurf-verification= (4) and heroku-domain-verification
(0).
While auditing apex TXT records I found five further vendor tokens that are self-identifying but
corroborate on too few domains to meet the ten-link bar in
CONTRIBUTING.md, plus one token I cannotattribute to a vendor at all. Raising them here rather than in a pull request.
Corpus: 6215 TXT records from 178 mutually independent apex domains, resolver
1.1.1.1. Zero falsepositives for all patterns below.
^intersight=^tmes=axway-amplify=^_aemverification\.work-accounts-domain-verification=Details:
intersight=<64 hex>, observed on bradesco.com.br, ibm.com, infosys.com, paypal.com, stone.com.br, theguardian.com, vale.com, wipro.com.tmes=<32 hex>, observed on assai.com.br, bradesco.com.br, braskem.com.br, infosys.com, suzano.com.br.Corroborated internally: the same domains carry
include:spf-us.tmes.trendmicro.comin their SPF.axway-amplify=<uuid>, observed on bosch.com, bradesco.com.br._aemverification.<env>-publish-aem.<domain>, observed onsantander.com.br only. Interesting because it also leaks the
environment name (dev/stage/prod), but a single domain is not a fingerprint.
work-accounts-domain-verification=— 5 domains (bradesco.com.br, databricks.com, flipkart.com, google.com, wise.com). I could not findpublic documentation tying this token to a vendor, so I am not proposing a technology for it. If a
maintainer recognises it, I will happily write the entry and the corroboration.
Question: is the ten-link rule a hard bar for
dns.TXTfingerprints specifically? A verificationtoken is self-identifying in a way a
scriptSrcpattern is not, and measured on this same corpus thecatalog already carries
loom-verification(4 domains),windsurf-verification=(4) andheroku-domain-verification(0).