SkillAgentSearch skills...

email-security

DMARC/SPF/DKIM check, email spoofing, SMTP test, and security header analysis

Install / Use

npx skills add uphiago/recon-skills --skill email-security

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

84/100

Category

Security

Supported Platforms

Universal

Our assessment of email-security

email-security scores 84/100 on our quality scale, 685th of 971 Security skills we index.

Its SKILL.md is 3.1 KB long, well organised into 19 sections with 3 code examples: a solid amount of guidance for an agent.

With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
18/20
Description
12/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 29 days ago, so email-security is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

email-security compared with similar skills

All 4 of these similar skills score higher than email-security; compare them before choosing.

SkillScoreStarsUpdatedFormat
email-security (this skill)by uphiago841.3k29d agoSKILL.md
algorithmic-artby anthropics100177.9k8d agoSKILL.md
pptxby anthropics100177.9k8d agoSKILL.md
designby nextlevelbuilder100130.2k9d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k9d agoSKILL.md

Frequently asked questions

How do I install email-security?
Run npx skills add uphiago/recon-skills --skill email-security. The install tabs above show the steps for each supported agent.
Which AI agents does email-security work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is email-security safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is email-security still maintained?
The repository was last updated 29 days ago, so email-security is actively maintained.

name: email-security description: "DMARC/SPF/DKIM check, email spoofing, SMTP test, and security header analysis" version: 1.1.0 revision_date: 2026-07-25 license: MIT category: recon tags: [email, SPF, DKIM, DMARC, spoofing, SMTP, recon]

Email Security -- DMARC, SPF, DKIM

When to Use

  • During passive reconnaissance (Phase 1)
  • After initial DNS enumeration
  • DMARC p=none means the domain can be totally spoofed
  • Critical for identifying phishing/business email compromise risks

DMARC/SPF/DKIM Check Commands

# SPF
dig +short TXT $target | grep "v=spf1"

# DMARC
dig +short TXT _dmarc.$target

# DKIM (common selector: google)
dig +short TXT google._domainkey.$target

# MX
dig +short MX $target

Interpreting Results

| Config | Meaning | Risk | |--------|---------|------| | v=spf1 ~all (softfail) | SPF suggests blocking but doesnt enforce | Spoofed emails may pass | | v=spf1 ?all (neutral) | SPF does nothing | Totally permissive | | v=spf1 include:amazonses.com ~all | SES can send as domain | Any AWS SES account can spoof | | v=DMARC1; p=none | DMARC disabled | Zero spoofing protection | | v=DMARC1; p=quarantine | Failed emails go to spam | Partial protection | | v=DMARC1; p=reject | Failed emails rejected | Full protection | | DKIM missing | No cryptographic signature | Email can be forged |

Email Spoofing via SMTP

# Test SMTP relay
timeout 3 bash -c 'exec 3<>/dev/tcp/TARGET/25; head -1 <&3'

# Send spoofed email via open relay (swaks)
swaks --to victim@target.com --from admin@target.com   --server TARGET --body "Spoofed email"

Headers That Indicate Security Level

| Header | Value | Meaning | |--------|-------|---------| | Authentication-Results | spf=pass | SPF passed | | Authentication-Results | spf=fail | SPF failed | | Authentication-Results | dmarc=pass | DMARC passed | | Authentication-Results | dmarc=fail | DMARC failed | | Authentication-Results | dkim=pass | DKIM passed | | Received-SPF | Pass | Sender authorized | | Received-SPF | Softfail | Sender not fully authorized | | Received-SPF | Fail | Sender not authorized | | ARC-Authentication-Results | | Authentication chain |

AWS SES Spoofing (When SPF includes amazonses.com)

With v=spf1 include:amazonses.com ~all:

  1. Create AWS account
  2. Configure SES with your own domain (verified)
  3. Send email with From: admin@target.com
  4. SPF PASSES (because of include:amazonses.com)
  5. DMARC p=none -- provider delivers normally

Real-World Cases

Real-world case (CRITICAL): Political party -- DMARC p=none on both domains (DOMAIN_PLACEHOLDER_A, DOMAIN_PLACEHOLDER_B). SPF with include:amazonses.com (any SES account can send as the domain). Total email spoofing.

Pitfalls

| Issue | Solution | |-------|----------| | SPF lookup limit | DNS has 10 lookup limit for SPF includes | | DKIM selector unknown | Try common selectors: google, selector1, selector2, 2022, 2023 | | DMARC reporting | rua=mailto: may leak authentication results to third party |

Verification

# Verify email spoofing is possible
# Send test email and check headers:
dig +short TXT _dmarc.target.com
# If p=none -> confirmed spoofable

Related Skills

View on GitHub
GitHub Stars1.3k
CategorySecurity
Updated29d ago
Forks215

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions