From 76e8eee4dcba9ecaa1100a5fa554b4ca0a616b0e Mon Sep 17 00:00:00 2001 From: Hadi <112569860+anotherhadi@users.noreply.github.com> Date: Mon, 1 Sep 2025 14:13:16 +0200 Subject: [PATCH] Email spoofing: only for primary email Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com> --- README.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 5d45ba8..f11e2eb 100644 --- a/README.md +++ b/README.md @@ -166,7 +166,9 @@ Here’s the process: 1. Create a new repository. 2. Make a commit using the **target's email** as the author. 3. Push the commit to GitHub. -4. Observe which GitHub account gets associated with that commit. +4. Observe which GitHub account the commit is linked to. This method **always + works**, but it only reveals the account if the email is set as the user’s + **primary email**. All of these steps are handled **automatically by the tool**, so you just need to provide the target email.