Cover image for project: NEXUS Email Auth Audit IN PROGRESS

Technical summary

NEXUS plugin for email authentication auditing (SPF, DKIM, DMARC, BIMI) with an RFC-referenced A+ to F score, multiple-DMARC-record detection and an ethical spoofing simulation lab with before/after headers — without sending real messages.

Executed scope

  • plugin.json: v1.0.0, slug nexus-email-auth-audit (legacy_slugs: ["email-auth-audit"]), name "Email Auth & Spoof Lab", "Segurança" category (Segurança tab, shield icon, is_core: false).
  • Lazy schema (eaa_install(), CREATE TABLE IF NOT EXISTS; no install.sql) — eaa_history (id, domain, score, statuses, details LONGTEXT JSON, created_at; idx_domain/idx_score/idx_created_at) and eaa_domains (portfolio: domain UNIQUE uk_domain, last_score, auto_check, last_audit_at).
  • Settings (DB::getConfig('eaa_settings')) — dns_resolver (native | cloudflare_doh | google_doh), custom_selectors (CSV), auto_notify_alerts.
  • DNS resolution (eaa_dns_query) — native dns_get_record (TXT/MX/CNAME/A/AAAA) with automatic DNS-over-HTTPS fallback (Cloudflare dns-query or Google resolve, Accept: application/dns-json, 3s connect / 6s timeout).
  • SPF audit (RFC 7208) — v=spf1; multiple records (HIGH §3.2 — PermError), missing (HIGH §3), final qualifier (SPF_WEAK_QUALIFIER HIGH §4.6 for ?all/+all), 10 DNS lookup limit (HIGH §4.6.4) and includes.
  • DMARC audit (RFC 7489) — _dmarc.<domain>; p/sp/pct/rua/aspf/adkim tags; missing (HIGH §6.1); multiple records (CRITICAL §6.6.3 — the receiver IGNORES all and treats as no DMARC); p=none (MEDIUM §6.3), pct<100 (LOW), no rua (LOW); strict/relaxed alignment.
  • DKIM audit (RFC 6376) — common + custom selector sweep at {sel}._domainkey.<domain> (TXT v=DKIM1/p= or CNAME); missing (MEDIUM §3.1).
  • BIMI & MX — default._bimi.<domain> (v=BIMI1) and MX presence.
  • A+ to F score — A+ = DMARC reject pct 100 + SPF -all + DKIM; A = reject/quarantine pct 100 + DKIM; B = quarantine pct<100 or reject without DKIM; C = p=none; D = SPF ?all/+all or multiple records; F = no DMARC and no SPF.
  • Persistence — INSERT into eaa_history (full JSON in details) + upsert into eaa_domains (ON DUPLICATE KEY UPDATE last_score).
  • Spoof Defense Lab (eaa_simulate_spoof) — deterministic receiver simulation (Google Workspace/M365) with default IP 203.0.113.45 (TEST-NET, RFC 5737): DELIVERED_INBOX (VULNERÁVEL) / REJECTED_SMTP (PROTEGIDO, 550 5.7.1) / DELIVERED_SPAM (QUARENTENA) / DELIVERED_INBOX_RFC_VIOLATION; real before/after headers (Authentication-Results, Received-SPF, Return-Path, missing DKIM-Signature, X-NEXUS-Audit-Verdict) — no email is ever sent; didactic alignment summary (RFC 5321 Envelope vs RFC 5322 Header From).
  • API: 10 actions (eaa_audit, eaa_simulate, eaa_history 1–100, eaa_domains_list, eaa_domain_save/eaa_domain_delete, eaa_settings_get/eaa_settings_save, eaa_fastr, eaa_fastr_suggest) — Bearer authentication.
  • Intel Hub — email-auth-audit enricher (domain field, priority 43): exposes score, dmarc_policy and spf_status from the last audit.
  • Fastr — /emailauth <domain> (markdown with Score, SPF, DMARC, DKIM and weaknesses; help shows usage).
  • Alpine.js UI (tab.php, 46 KB) — slate + indigo-600 theme, Segurança tab; 5 sub-tabs (Domain Audit with a severity-colored A+–F Score card and simulation actions, Spoof Defense Lab with current vs fixed scenario and before/after headers, Alignment Guide RFC 7489 strict vs relaxed, Audit History, Settings with DNS resolver and DKIM selectors).
  • No cron and no i18n (PT UI; simulated headers in EN).

Stack and tools

  • PHP 8 (no framework)
  • MySQL 8 (eaa_history, eaa_domains)
  • Alpine.js + Tailwind CSS (premium light, slate/indigo)
  • cURL + native DNS + DNS-over-HTTPS (Cloudflare/Google)
  • NEXUS plugin system (PluginManager: tabs, docs, API actions, Fastr, Intel enrichers)

Operational tags

  • Email
  • SPF
  • DKIM
  • DMARC
  • BIMI
  • Spoofing
  • RFC 7489
  • Segurança
  • Plugin NEXUS

Operational result

  • Measurable email posture: A+ to F score with explicit rules and RFC-referenced weaknesses (7208, 6376, 7489) — no guesswork.
  • Critical failure detection: multiple DMARC/SPF records nullify protection (RFC 7489 §6.6.3) and drop the score to D.
  • Before/after proof: real Authentication-Results headers show how p=reject blocks spoofing at the SMTP handshake (550 5.7.1).
  • 100% ethical lab: deterministic simulation without sending messages; attack IP in TEST-NET.
  • Continuous monitoring: domain portfolio (eaa_domains) with last score and full-payload audit history.
  • Integrated intelligence: domain enricher in the Intel Hub (score + DMARC policy + SPF status).
  • /emailauth <domain> chat command.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Technical email authentication auditor for domain reputation protection. Inspects and validates SPF, DKIM, and DMARC DNS records, mitigating email spoofing and phishing while ensuring optimal deliverability.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.