Cover image for project: NEXUS Email Auth & Spoof Lab IN PROGRESS

Technical summary

NEXUS Email Auth & Spoof Lab audits the email authentication of domains (SPF, DKIM, DMARC and BIMI) with an A+ to F score and weakness diagnosis based on RFCs 7208, 6376 and 7489. The spoofing lab ethically simulates the decision of receiving servers, generating before/after headers as evidence without sending real messages, with an audit history and /emailauth slash integration.

Executed scope

  • Plugin registration in plugin.php: registerTab('email-auth-audit', tab.php) with the shield icon (Security category), registerDoc('email-auth-audit', doc.md) and 10 API actions via registerApiAction (eaa_ prefix).
  • Database: MySQL tables eaa_history (domain, score, spf_status, dkim_status, dmarc_status, dmarc_policy, bimi_status, details LONGTEXT, created_at, with idx_domain/idx_score/idx_created_at indexes) and eaa_domains (monitoring portfolio: UNIQUE domain, last_score, auto_check, last_audit_at) — created with CREATE TABLE IF NOT EXISTS in eaa_install(); no install.sql.
  • Centralized configuration in eaa_settings (via DB::getConfig): dns_resolver (native/cloudflare_doh/google_doh), custom_selectors (DKIM selector list) and auto_notify_alerts.
  • DNS lookup (eaa_dns_query): native dns_get_record resolver (TXT/MX/CNAME) with automatic DNS-over-HTTPS fallback (Cloudflare cloudflare-dns.com/dns-query or Google dns.google/resolve) and result caching.
  • SPF audit (RFC 7208): v=spf1 validation, qualifier analysis (-all, ~all, ?all, +all), DNS lookup counting (10-lookup hard limit) and detection of conflicting multiple records.
  • DMARC audit (RFC 7489): extraction of the p=, sp=, pct=, rua=, ruf=, aspf=, adkim= tags and multiple DMARC record detection — a critical failure that voids protection at receivers (RFC 7489 §6.6.3).
  • DKIM audit (RFC 6376): scanning of common selectors (default, google, k1, s1, mail, selector1, s2048, dkim, sendgrid, mandrill) plus custom selectors, with RSA/Ed25519 public key analysis.
  • BIMI & MX audit: v=BIMI1 record validation and MX presence.
  • Authentication score A+ to F: matrix derived from SPF/DMARC/DKIM/BIMI and detected weaknesses, with per-finding recommendations.
  • Spoofing lab (eaa_simulate_spoof): deterministic simulation of the receiving server decision (Google Workspace, Microsoft 365) with DELIVERED_INBOX (vulnerable), REJECTED_SMTP (protected, p=reject), DELIVERED_SPAM (quarantine, p=quarantine) and RFC_VIOLATION (multiple DMARC) scenarios — generating before/after evidence headers (Authentication-Results, Received-SPF, DKIM-Signature, Return-Path) without sending real messages, with default attacker IP 203.0.113.45 (TEST-NET).
  • Alignment diagnosis: didactic explanation of strict vs relaxed alignment between the Envelope Sender (RFC 5321) and the Header From (RFC 5322).
  • History and portfolio: eaa_history (audits with 1–100 limit) and eaa_domains_list/eaa_domain_save/eaa_domain_delete (monitored domains with last_score).
  • Fast Responses: fastr.json manifest with /emailauth <domain> (instant audit with score, SPF, DMARC and DKIM) plus eaa_fastr_suggest.
  • Intel Hub: nx_intel_register_enricher('email-auth-audit', ['domain'], 'eaa_intel_enrich', 43) — exposes the score, DMARC policy and SPF status of the domain's last audit.
  • Interface (tab.php, 689 lines): 4 tabs — Audit (A+ to F score card with semantic colors + SPF/DMARC/DKIM/BIMI status cards with RFCs), Lab (simulation with before/after headers), Alignment (didactic) and History (score evolution).

Stack and tools

  • PHP 8 backend (no framework) + MySQL (eaa_history, eaa_domains)
  • Native DNS lookups (dns_get_record) + DNS-over-HTTPS fallback (Cloudflare/Google)
  • Alpine.js + Tailwind CSS (4 tabs, score card, status cards and header visualization)
  • Internal Plugin API (PluginManager tabs/docs/actions + fastr.json + intel enricher)
  • NEXUS API Bearer token authentication on API calls

Operational tags

  • Email
  • SPF
  • DKIM
  • DMARC
  • BIMI
  • Spoofing
  • Security
  • DNS
  • Audit
  • NEXUS Plugin

Operational result

  • Clear, actionable score: A+ to F rating with RFC-referenced weaknesses and practical recommendations.
  • Ethical simulation: proves the impact of a fix (e.g., p=none → p=reject) without sending real emails.
  • Forensic evidence: Authentication-Results, Received-SPF, DKIM-Signature and Return-Path before/after headers ready for reports.
  • Monitoring portfolio: tracked domains with latest score and on-demand auditing.
  • Evolution history: score tracking over time per domain.
  • Quick access: /emailauth <domain> slash command straight from the Fastr terminal.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS Email Auth & Spoof Lab audits the email authentication of domains (SPF, DKIM, DMARC and BIMI) with an A+ to F score and weakness diagnosis based on RFCs 7208, 6376 and 7489. The spoofing lab ethically simulates the decision of receiving servers, generating before/after headers as evidence without sending real messages, with an audit history and /emailauth slash integration.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.