IN PROGRESS
Technical summary
NEXUS plugin for email authentication auditing (SPF, DKIM, DMARC, BIMI) with an RFC-referenced A+ to F score, multiple-DMARC-record detection and an ethical spoofing simulation lab with before/after headers — without sending real messages.
Executed scope
plugin.json: v1.0.0, slugnexus-email-auth-audit(legacy_slugs: ["email-auth-audit"]), name "Email Auth & Spoof Lab", "Segurança" category (Segurança tab,shieldicon,is_core: false).- Lazy schema (
eaa_install(),CREATE TABLE IF NOT EXISTS; noinstall.sql) —eaa_history(id, domain, score, statuses,detailsLONGTEXT JSON, created_at;idx_domain/idx_score/idx_created_at) andeaa_domains(portfolio: domain UNIQUEuk_domain,last_score,auto_check,last_audit_at). - Settings (
DB::getConfig('eaa_settings')) —dns_resolver(native|cloudflare_doh|google_doh),custom_selectors(CSV),auto_notify_alerts. - DNS resolution (
eaa_dns_query) — nativedns_get_record(TXT/MX/CNAME/A/AAAA) with automatic DNS-over-HTTPS fallback (Cloudflaredns-queryor Googleresolve,Accept: application/dns-json, 3s connect / 6s timeout). - SPF audit (RFC 7208) —
v=spf1; multiple records (HIGH §3.2 — PermError), missing (HIGH §3), final qualifier (SPF_WEAK_QUALIFIERHIGH §4.6 for?all/+all), 10 DNS lookup limit (HIGH §4.6.4) and includes. - DMARC audit (RFC 7489) —
_dmarc.<domain>;p/sp/pct/rua/aspf/adkimtags; missing (HIGH §6.1); multiple records (CRITICAL §6.6.3 — the receiver IGNORES all and treats as no DMARC);p=none(MEDIUM §6.3),pct<100(LOW), norua(LOW);strict/relaxedalignment. - DKIM audit (RFC 6376) — common + custom selector sweep at
{sel}._domainkey.<domain>(TXTv=DKIM1/p=or CNAME); missing (MEDIUM §3.1). - BIMI & MX —
default._bimi.<domain>(v=BIMI1) and MX presence. - A+ to F score — A+ = DMARC
rejectpct 100 + SPF-all+ DKIM; A =reject/quarantinepct 100 + DKIM; B = quarantine pct<100 or reject without DKIM; C =p=none; D = SPF?all/+allor multiple records; F = no DMARC and no SPF. - Persistence — INSERT into
eaa_history(full JSON indetails) + upsert intoeaa_domains(ON DUPLICATE KEY UPDATE last_score). - Spoof Defense Lab (
eaa_simulate_spoof) — deterministic receiver simulation (Google Workspace/M365) with default IP203.0.113.45(TEST-NET, RFC 5737):DELIVERED_INBOX(VULNERÁVEL) /REJECTED_SMTP(PROTEGIDO, 550 5.7.1) /DELIVERED_SPAM(QUARENTENA) /DELIVERED_INBOX_RFC_VIOLATION; real before/after headers (Authentication-Results,Received-SPF,Return-Path, missingDKIM-Signature,X-NEXUS-Audit-Verdict) — no email is ever sent; didactic alignment summary (RFC 5321 Envelope vs RFC 5322 Header From). - API: 10 actions (
eaa_audit,eaa_simulate,eaa_history1–100,eaa_domains_list,eaa_domain_save/eaa_domain_delete,eaa_settings_get/eaa_settings_save,eaa_fastr,eaa_fastr_suggest) — Bearer authentication. - Intel Hub —
email-auth-auditenricher (domainfield, priority 43): exposesscore,dmarc_policyandspf_statusfrom the last audit. - Fastr —
/emailauth <domain>(markdown with Score, SPF, DMARC, DKIM and weaknesses;helpshows usage). - Alpine.js UI (
tab.php, 46 KB) — slate + indigo-600 theme, Segurança tab; 5 sub-tabs (Domain Audit with a severity-colored A+–F Score card and simulation actions, Spoof Defense Lab with current vs fixed scenario and before/after headers, Alignment Guide RFC 7489 strict vs relaxed, Audit History, Settings with DNS resolver and DKIM selectors). - No cron and no i18n (PT UI; simulated headers in EN).
Stack and tools
- PHP 8 (no framework)
- MySQL 8 (
eaa_history,eaa_domains) - Alpine.js + Tailwind CSS (premium light, slate/indigo)
- cURL + native DNS + DNS-over-HTTPS (Cloudflare/Google)
- NEXUS plugin system (PluginManager: tabs, docs, API actions, Fastr, Intel enrichers)
Operational tags
- SPF
- DKIM
- DMARC
- BIMI
- Spoofing
- RFC 7489
- Segurança
- Plugin NEXUS
Operational result
- Measurable email posture: A+ to F score with explicit rules and RFC-referenced weaknesses (7208, 6376, 7489) — no guesswork.
- Critical failure detection: multiple DMARC/SPF records nullify protection (RFC 7489 §6.6.3) and drop the score to D.
- Before/after proof: real
Authentication-Resultsheaders show howp=rejectblocks spoofing at the SMTP handshake (550 5.7.1). - 100% ethical lab: deterministic simulation without sending messages; attack IP in TEST-NET.
- Continuous monitoring: domain portfolio (
eaa_domains) with last score and full-payload audit history. - Integrated intelligence: domain enricher in the Intel Hub (score + DMARC policy + SPF status).
/emailauth <domain>chat command.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Technical email authentication auditor for domain reputation protection. Inspects and validates SPF, DKIM, and DMARC DNS records, mitigating email spoofing and phishing while ensuring optimal deliverability.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- cURL
- DNS
- DNS-over-HTTPS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.