
SimpleEmailSpoofer
A simple Python CLI to spoof emails.

A simple Python CLI to spoof emails.

Automation to assess the state of your M365 tenant against CISA's baselines

An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

A toolkit to attack Office365

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule…

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

Bash script to check if a domain or list of domains can be spoofed based in DMARC records

Scans DNS MX records to detect misconfigured, expiring, or unregistered domains vulnerable to email takeover, with automatic reclamation support for…

small python3 tool to check common vulnerabilities in SMTP servers

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Automated pipeline that resolves Swiss municipality domains, scrapes websites for email addresses, and classifies email providers via MX, SPF, DKIM,…

Tool to find SMTP servers vulnerable to open relay

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

Web application that lets you test if your domain is vulnerable to email spoofing

A program to map out SPF and DKIM records for a large number of domains

Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.

Open source tooling to stop ICS phishing (malicious calendar invites)