I have found the vulnerability in hagander.net and It was my moral obligation to report it to them.
----- Reply to message -----
Subject: Re: Vulnerability Report (DMARC RECORD)
Date: Fri, 16 Apr 2021, 13:11
From: Magnus Hagander <magnus@hagander.net>
To: <arslan.whitehat@inbox.eu>
On Fri, Apr 16, 2021 at 12:05 PM <arslan.whitehat@inbox.eu> wrote:
>
> Hello Team,
> I am a security researcher and I founded this vulnerability in your website.

First of all, this is not a vulnerability.
Second, this is not about a website, it's about email.



> Hoping for the bounty for my ethical Disclosure.

Please note that

1. The PostgreSQL open source project does not have a bug bounty
program. Individual vendors may, but not the open source project.

2. You announced your "discovery" publicly, that's not the normal way
to get a bounty from *any* source. But luckily, it wasn't actually a
vulnerability.


//Magnus