Security Architecture Overview: github.com
GitHub protects developer accounts and supply chain integrity with strict DMARC p=reject enforcement, neutralizing fake security alerts and compromised OAuth token lures.
Key Anti-Spoofing & Cryptographic Highlights
Frequently Asked Questions
Does GitHub use DMARC reject?
Yes. GitHub enforces p=reject to protect open-source developers from targeted credential theft.
Why does github.com's SPF include both Google and Mailgun?
GitHub uses both Google Workspace for internal staff email and Mailgun for transactional developer notifications (CI/CD alerts, PR comments, security advisories). Both sending providers are listed in the SPF record to ensure DMARC alignment for all outbound mail streams.
What SSL certificate does github.com use?
GitHub.com uses DigiCert Global Root G2-issued certificates. DigiCert is the dominant CA for high-traffic developer infrastructure. Following Microsoft's acquisition of GitHub, certificate management is tightly integrated with Azure CDN edge nodes.
What is GitHub's supply chain phishing threat model?
Attackers target developers with fake security vulnerability disclosure emails, spoofed Dependabot alerts, or fake 2FA reset requests. Because source code credentials grant access to production systems, developer-targeted phishing is classified as a supply chain attack vector.
How old is github.com?
GitHub.com was registered on October 9, 2007 — over 18 years ago. Despite being younger than most enterprise domains in this audit, its institutional ownership by Microsoft and consistent security posture provide a near-maximum trust score.
Does GitHub enforce FIDO2 hardware key authentication?
Yes. GitHub requires FIDO2 hardware security keys (e.g. YubiKey) for accounts with elevated privileges. This is relevant to email security: even with perfect DMARC, social engineering attacks that trick developers into resetting credentials remain a risk.