Testing Smtp Smuggling And Email Spoofing

Test a mail setup for sender spoofing that survives authentication: SPF, DKIM, and DMARC records that exist but do not align or enforce, subdomains left unprotected, and the end-of-data desync known as SMTP smuggling, where an inbound and an outbound mail server disagree on where one message ends so a second message with a forged, auth-passing sender is smuggled in. Covers policy present but not enforced, alignment gaps between the envelope and header sender, missing subdomain policy, open relay, and inconsistent message-boundary parsing between hops. Use when auditing a domain's mail authentication or a mail server's boundary handling. The crafted or smuggled message is the source, an accepted spoofed delivery is the sink.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/testing-smtp-smuggling-and-email-spoofing commit 59df45f044

Frequently asked questions

npx skillmds@latest add unboundcompute/testing-smtp-smuggling-and-email-spoofing