{"success":true,"data":{"id":"received-spf-comment-injection-pass-fake","label":"SPF Comment-Injection \"(pass)\" Fake","description":"Received-SPF (or Authentication-Results) header whose leading result token is fail / softfail / neutral / temperror / permerror, but whose comment text embeds a positive pass-token (\"(pass)\" / \"result=pass\" / \"spf passed\" / \"sender authenticated\") — a forgery shape aimed at downstream scanners that grep for \"pass\" anywhere in the header without parsing the RFC 7208 structure. Legitimate SPF-fail comments narrate the negative result (e.g. \"sender domain does not designate 1.2.3.4 as permitted\"); they never contain a literal \"(pass)\" token or claim the check passed. Distinct from `received-spf-whitespace-evasion` — that signal fires on whitespace inside the `envelope-from=...` value; this one fires on the leading-result / comment-claim mismatch.","tier":"danger","category":"header","isThin":false}}