MattKeeley / Spoofy

Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
Other
637 stars 58 forks source link

DKIM Collection/Analysis #25

Open Zamanry opened 7 months ago

Zamanry commented 7 months ago

Love the tool! Have we considered adding DKIM support as well? There is research out there on bypassing DKIM requirements and it would be nice to have a single tool to identify and evaluate the DKIM record? My previous coworker had wrote some code here on how guessing common DKIM subdomains that may be helpful:

Some example of DKIM attacks: