The vulnerability was first reported by a mathematician named Zachary Harris, who received an email purporting to come from a Google headhunter. The email's header information, which proves who sent it, apparently looked in order, but Harris noticed that a weak DKIM key was being used.