IN PROGRESS
Technical summary
NEXUS Email Auth & Spoof Lab audits the email authentication of domains (SPF, DKIM, DMARC and BIMI) with an A+ to F score and weakness diagnosis based on RFCs 7208, 6376 and 7489. The spoofing lab ethically simulates the decision of receiving servers, generating before/after headers as evidence without sending real messages, with an audit history and /emailauth slash integration.
Executed scope
- Plugin registration in
plugin.php:registerTab('email-auth-audit', tab.php)with theshieldicon (Security category),registerDoc('email-auth-audit', doc.md)and 10 API actions viaregisterApiAction(eaa_prefix). - Database: MySQL tables
eaa_history(domain, score, spf_status, dkim_status, dmarc_status, dmarc_policy, bimi_status, details LONGTEXT, created_at, withidx_domain/idx_score/idx_created_atindexes) andeaa_domains(monitoring portfolio: UNIQUE domain, last_score, auto_check, last_audit_at) — created withCREATE TABLE IF NOT EXISTSineaa_install(); no install.sql. - Centralized configuration in
eaa_settings(viaDB::getConfig):dns_resolver(native/cloudflare_doh/google_doh),custom_selectors(DKIM selector list) andauto_notify_alerts. - DNS lookup (
eaa_dns_query): nativedns_get_recordresolver (TXT/MX/CNAME) with automatic DNS-over-HTTPS fallback (Cloudflarecloudflare-dns.com/dns-queryor Googledns.google/resolve) and result caching. - SPF audit (RFC 7208):
v=spf1validation, qualifier analysis (-all,~all,?all,+all), DNS lookup counting (10-lookup hard limit) and detection of conflicting multiple records. - DMARC audit (RFC 7489): extraction of the
p=,sp=,pct=,rua=,ruf=,aspf=,adkim=tags and multiple DMARC record detection — a critical failure that voids protection at receivers (RFC 7489 §6.6.3). - DKIM audit (RFC 6376): scanning of common selectors (
default,google,k1,s1,mail,selector1,s2048,dkim,sendgrid,mandrill) plus custom selectors, with RSA/Ed25519 public key analysis. - BIMI & MX audit:
v=BIMI1record validation and MX presence. - Authentication score A+ to F: matrix derived from SPF/DMARC/DKIM/BIMI and detected weaknesses, with per-finding recommendations.
- Spoofing lab (
eaa_simulate_spoof): deterministic simulation of the receiving server decision (Google Workspace, Microsoft 365) withDELIVERED_INBOX(vulnerable),REJECTED_SMTP(protected, p=reject),DELIVERED_SPAM(quarantine, p=quarantine) andRFC_VIOLATION(multiple DMARC) scenarios — generating before/after evidence headers (Authentication-Results,Received-SPF,DKIM-Signature,Return-Path) without sending real messages, with default attacker IP203.0.113.45(TEST-NET). - Alignment diagnosis: didactic explanation of strict vs relaxed alignment between the Envelope Sender (RFC 5321) and the Header From (RFC 5322).
- History and portfolio:
eaa_history(audits with 1–100 limit) andeaa_domains_list/eaa_domain_save/eaa_domain_delete(monitored domains withlast_score). - Fast Responses:
fastr.jsonmanifest with/emailauth <domain>(instant audit with score, SPF, DMARC and DKIM) pluseaa_fastr_suggest. - Intel Hub:
nx_intel_register_enricher('email-auth-audit', ['domain'], 'eaa_intel_enrich', 43)— exposes the score, DMARC policy and SPF status of the domain's last audit. - Interface (
tab.php, 689 lines): 4 tabs — Audit (A+ to F score card with semantic colors + SPF/DMARC/DKIM/BIMI status cards with RFCs), Lab (simulation with before/after headers), Alignment (didactic) and History (score evolution).
Stack and tools
- PHP 8 backend (no framework) + MySQL (
eaa_history,eaa_domains) - Native DNS lookups (
dns_get_record) + DNS-over-HTTPS fallback (Cloudflare/Google) - Alpine.js + Tailwind CSS (4 tabs, score card, status cards and header visualization)
- Internal Plugin API (PluginManager tabs/docs/actions +
fastr.json+ intel enricher) - NEXUS API Bearer token authentication on API calls
Operational tags
- SPF
- DKIM
- DMARC
- BIMI
- Spoofing
- Security
- DNS
- Audit
- NEXUS Plugin
Operational result
- Clear, actionable score: A+ to F rating with RFC-referenced weaknesses and practical recommendations.
- Ethical simulation: proves the impact of a fix (e.g.,
p=none→p=reject) without sending real emails. - Forensic evidence:
Authentication-Results,Received-SPF,DKIM-SignatureandReturn-Pathbefore/after headers ready for reports. - Monitoring portfolio: tracked domains with latest score and on-demand auditing.
- Evolution history: score tracking over time per domain.
- Quick access:
/emailauth <domain>slash command straight from the Fastr terminal.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS Email Auth & Spoof Lab audits the email authentication of domains (SPF, DKIM, DMARC and BIMI) with an A+ to F score and weakness diagnosis based on RFCs 7208, 6376 and 7489. The spoofing lab ethically simulates the decision of receiving servers, generating before/after headers as evidence without sending real messages, with an audit history and /emailauth slash integration.
Architecture and organization
- PHP 8
- MySQL
- Alpine.js
- Tailwind CSS
- DNS (TXT/MX)
- DNS-over-HTTPS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.