Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
decode-spam-headers — 이메일이 스팸으로 분류된 이유를 이해하는 데 도움이 되는 스크립트 | Kitploit
도구/GitHubGitHub/mgeeky/decode-spam-headers
Phishing ToolsInformation GatheringRed TeamingEmail SecurityLog Analysis
GitHubmgeeky/decode-spam-headers

decode-spam-headers

이메일이 스팸으로 분류된 이유를 이해하는 데 도움이 되는 스크립트

저장소 보기
698986개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

decode-spam-headers.py

일상적인 관리 업무를 위해 특정 이메일이 스팸/정크함에 들어간 이유를 이해하려고 하든, 레드팀 피싱 시뮬레이션 목적으로 이해하려고 하든, 이 스크립트가 도움을 드릴 수 있습니다!

아이디어는 MS Office365 E5 환경(MS Defender for Office365 탑재)을 대상으로 상업용 피싱 시뮬레이션을 진행하던 중 떠올랐습니다. 짐작하시겠지만, 피싱 시뮬레이션 관점에서 보면 상당히 까다로운 보안 스택입니다. 이 모든 Office365 SMTP 헤더를 수동으로 파고들어 SCL 값을 골라내려던 끝에, SMTP 헤더용 제대로 된 파서를 만들 때가 왔다는 결론에 도달했습니다.

시간이 지나면서 점점 더 많은 SMTP 헤더에 대한 지원을 추가하게 되었고, 그래서 이 도구가 탄생했습니다. 이제 수십 가지의 다양한 헤더를 이해하는 도구입니다.

정보

이 도구는 입력으로 모든 SMTP 헤더가 포함된 *.EML 또는 *.txt 파일을 받습니다. 그런 다음 흥미로운 헤더의 하위 집합을 추출하고 105개 이상의 테스트를 사용하여 가능한 한 많이 디코딩을 시도합니다.

이 스크립트는 또한 모든 IPv4 주소와 도메인 이름을 추출하여 전체 DNS 조회를 수행합니다.

결과 출력에는 이 이메일이 차단되었을 수 있는 이유에 대한 유용한 정보가 포함됩니다.

클라이언트에게 보내기 전에 피싱 HTML 코드를 다듬고 싶다면, 제 phishing-HTML-linter.py에 입력으로 넣는 것도 고려해 보세요. HTML에서 스팸 점수를 높일 수 있는 악취 를 찾아내는 데 꽤 괜찮은 성능을 발휘합니다.

예시 스크린샷

  • MTA 서버 체인(깔끔하게 파싱된 Received 헤더):

1.png

  • 공개 문서에 따라 최대한 디코딩된 다양한 헤더(여기서는 Office365 ForeFront Spam Report):

2.png

  • 스팸 분류 단서를 적극적으로 검증하고 찾기 위해 구현된 다양한 사용자 정의 휴리스틱, 여기서는 도메인 가장 을 감지하는 로직:

3.png

  • 스크립트는 Office365 안티스팸 규칙 중 일부를 리버스 엔지니어링하고 문서화하는 동시에, 다른 불투명한 안티스팸 헤더에 대한 공개 지식을 수집하려고 시도합니다:

4.png

  • 보고서는 보기 좋은 HTML로 생성할 수 있습니다(사용법: py decode-spam-headers.py headers.txt -f html -o report.html):

5.png

처리되는 헤더

처리되는 헤더(85개 이상의 헤더가 파싱됨):

  • X-forefront-antispam-report
  • X-exchange-antispam
  • X-exchange-antispam-mailbox-delivery
  • X-exchange-antispam-message-info
  • X-microsoft-antispam-report-cfa-test
  • Received
  • From
  • To
  • Subject
  • Thread-topic
  • Received-spf
  • X-mailer
  • X-originating-ip
  • User-agent

이 헤더들 대부분은 완전히 문서화되어 있지 않으므로, 이 스크립트가 모든 세부 사항을 정확히 집어내지는 못하지만, 적어도 제가 찾을 수 있는 모든 정보를 수집합니다.

리버스 엔지니어링 노력

저는 공개적으로 문서화되지 않은 다양한 Office365 ForeFront 안티스팸 규칙(SFS, ENG)을 찾아내고 이해하기 위해 상당한 노력을 기울이고 있습니다.```

(5) Test: X-Forefront-Antispam-Report

HEADER: X-Forefront-Antispam-Report

VALUE: CIP:209.85.167.100;CTRY:US;LANG:de;SCL:5;SRV:;IPV:NLI;SFV:SPM;H:mail-lf1-f100.google.com;PTR:mail-l f1-f100.google.com;CAT:DIMP;SFTY:9.19;SFS:(4636009)(956004)(166002)(6916009)(356005)(336012)(19 625305002)(22186003)(5660300002)(4744005)(6666004)(35100500006)(82960400001)(26005)(7596003)(7636003)(554460 02)(224303003)(1096003)(58800400005)(86362001)(9686003)(43540500002);DIR:INB;SFTY:9.19;

[...]

root@kitploit:~
    - Message matched 24 Anti-Spam rules (SFS):           <============ opaque anti-spam rules
            - (1096003)
            - (166002)
            - (19625305002)
            - (22186003)
            - (224303003)
            - (26005)
            - (336012)
            - (356005)
            - (35100500006)         - (SPAM) Message contained embedded image.
root@kitploit:~
이 프로세스는 순전히 수동으로 진행되며, 특별히 설계된 메일을 Office365 메일 서버로 전송한 다음 수집된 규칙을 수동으로 검토하고 연관시키는 방식입니다.

이미 60개 이상의 메일을 보냈으며, 지금까지 Microsoft의 규칙에 대해 알 수 있었던 내용은 다음과 같습니다:```py

    #
    # Below rules were collected solely in a trial-and-error manner or by scraping any 
    # pieces of information from all around the Internet.
    #
    # They do not represent the actual Anti-Spam rule name or context and surely represent 
    # something close to what is understood (or they may have totally different meaning).
    # 
    # Until we'll be able to review anti-spam rules documention, there is no viable mean to map
    # rule ID to its meaning.
    #

    Anti_Spam_Rules_ReverseEngineered = \
    {
        '35100500006' : logger.colored('(SPAM) Message contained embedded image.', 'red'),

        # https://docs.microsoft.com/en-us/answers/questions/416100/what-is-meanings-of-39x-microsoft-antispam-mailbox.html
        '520007050' : logger.colored('(SPAM) Moved message to Spam and created Email Rule to move messages from this particular sender to Junk.', 'red'),

        # triggered on an empty mail with subject being: "test123 - viagra"
        '162623004' : 'Subject line contained suspicious words (like Viagra).',

        # triggered on mail with subject "test123" and body being single word "viagra"
        '19618925003' : 'Mail body contained suspicious words (like Viagra).',

        # triggered on mail with empty body and subject "Click here"
        '28233001' : 'Subject line contained suspicious words luring action (ex. "Click here"). ',

        # triggered on a mail with test subject and 1500 words of http://nietzsche-ipsum.com/
        '30864003' : 'Mail body contained a lot of text (more than 10.000 characters).',

        # mails that had simple message such as "Hello world" triggered this rule, whereas mails with
        # more than 150 words did not.
        '564344004' : 'HTML mail body with less than 150 words of text (not sure how much less though)',

        # message was sent with a basic html and only one <u> tag in body.
        '67856001' : 'HTML mail body contained underline <u> tag.',

        # message with html,head,body and body containing simple text with no b/i/u formatting.
        '579124003' : 'HTML mail body contained text, but no text formatting (<b>, <i>, <u>) was present',

        # This is a strong signal. Mails without <a> doesnt have this rule.
        '166002' : 'HTML mail body contained URL <a> link.',

        # Message contained <a href="https://something.com/file.html?parameter=value" - GET parameter with value.
        '21615005' : 'Mail body contained <a> tag with URL containing GET parameter: ex. href="https://foo.bar/file?aaa=bbb"',

        # Message contained <a href="https://something.com/file.html?parameter=https://another.com/website" 
        # - GET parameter with value, being a URL to another website
        '45080400002' : 'Something about <a> tag\'s URL. Possibly it contained GET parameter with value of another URL: ex. href="https://foo.bar/file?aaa=https://baz.xyz/"',

        # Message contained <a> with href pointing to a file with dangerous extension, such as file.exe
        '460985005' : 'Mail body contained HTML <a> tag with href URL pointing to a file with dangerous extension (such as .exe)',

        #
        # Message1: GoPhish -> VPS 587/tcp redirector -> smtp.gmail.com:587 -> target
        # Message2: GoPhish -> VPS 587/tcp redirector -> smtp-relay.gmail.com:587 -> target
        #
        # These were the only differences I spotted:
        #   Message1 - FirstHop Gmail SMTP Received with ESMTPS.
        #   Message2 - FirstHop Gmail SMTP-Relay Received with ESMTPSA.
        #
        '121216002' : 'First Hop MTA SMTP Server used as a SMTP Relay. It\'s known to originate e-mails, but here it acted as a Relay. Or maybe due to use of "with ESMTPSA" instead of ESMTPS?',

        # Triggered on message with <a> added to HTML: <a href="https://support.spotify.com/is-en/">https://www.reddit.com/</a>
        '966005' : 'Mail body contained link tag with potentially masqueraded URL: <a href="https://attacker.com">https://example.com</a>',

        #
        # Message1: GoPhish EC2 -> another EC2 with socat to smtp.gmail.com:587 (authenticated) -> Target
        # Message2: GoPhish EC2 -> Gsuite -> Target
        #
        # Subject, mail body were exactly the same.
        #
        # Below two rules were added to the second message. My understanding is that they're somehow referring
        # to the reputation of the first-hop server, maybe reverse-DNS resolution.
        #
        '5002400100002' : "(GUESSING) Somehow related to First Hop server reputation, it's reverse-PTR resolution or domain impersonation",
        '58800400005'   : "(GUESSING) Somehow related to First Hop server reputation, it's reverse-PTR resolution or domain impersonation",

        '19625305002' : '(GUESSING) Something to do with the HTML code and used tags/structures',
        '43540500002' : '(GUESSING) Something to do with the HTML code and used tags/structures',

        '460985005' : '(GUESSING) Something to do with either more-complex HTML code or with the <a> tag and its URL.',

        # Triggered on an empty text message, subject "test" - that was marked with "Domain Impersonation", however 
        # ForeFront Anti-Spam headers did not support that Domain Impersonation. Weird.
        '22186003' : '(GUESSING) Something to do with either Text message (non-HTML) or probable Domain Impersonation',

        # Found by @ipSlav (https://github.com/mgeeky/decode-spam-headers/issues/15)
        '42882007' : 'Missing Reply-To Address. Might be fixed by adding -ReplyTo flag to Send-MailMessage',
        '78352004' : 'Missing Reply-To Address. Might be fixed by adding -ReplyTo flag to Send-MailMessage',
    }

다른 Office365 안티스팸 규칙에 대해 알고 있거나 (위에서 설명한 규칙에 대한 제안 사항이 있다면) 이 저장소의 이슈에서 알려주세요. 바로 추가하겠습니다. :)

사용법

처음 사용하기 전에 필요한 Python3 종속성을 설치하세요:``` bash$ pip3 install -r requirements.txt

root@kitploit:~
도움말:```
PS> py .\decode-spam-headers.py --help
usage: decode-spam-headers.py [options] <file | --list tests>

optional arguments:
  -h, --help            show this help message and exit

Required arguments:
  infile                Input file to be analysed or --list tests to show available tests.

Options:
  -o OUTFILE, --outfile OUTFILE
                        Output file with report
  -f {json,text,html}, --format {json,text,html}
                        Analysis report format. JSON, text. Default: text
  -N, --nocolor         Dont use colors in text output.
  -v, --verbose         Verbose mode.
  -d, --debug           Debug mode.
  -l, --list            List available tests and quit. Use it like so: --list tests

Tests:
  -i tests, --include-tests tests
                        Comma-separated list of test IDs to run. Ex. --include-tests 1,3,7
  -e tests, --exclude-tests tests
                        Comma-separated list of test IDs to skip. Ex. --exclude-tests 1,3,7
  -r, --resolve         Resolve IPv4 addresses / Domain names.
  -R, --dont-resolve    Do not resolve anything.
  -a, --decode-all      Decode all =?us-ascii?Q? mail encoded messages and print their contents.

테스트의 일부만 실행하려면 먼저 선택할 테스트 ID를 알아야 합니다. 해당 목록을 얻으려면 스크립트를 -l tests와 함께 실행하세요.

사용 가능한 테스트와 해당 ID 목록:``` C:> py decode-spam-headers.py -l tests

[.] Available tests:

root@kitploit:~
    TEST_ID - TEST_NAME
    --------------------------------------
          1 - Received - Mail Servers Flow
          2 - Extracted IP addresses
          3 - Extracted Domains
          4 - Bad Keywords In Headers
          5 - Sender Address Analysis
          6 - Subject and Thread Topic Difference
          7 - Authentication-Results
          8 - ARC-Authentication-Results
          9 - Received-SPF
         10 - Mail Client Version
         11 - User-Agent Version
         12 - X-Forefront-Antispam-Report
         13 - X-MS-Exchange-Organization-SCL
         14 - X-Microsoft-Antispam-Mailbox-Delivery
         15 - X-Microsoft-Antispam Bulk Mail
         16 - X-Exchange-Antispam-Report-CFA-Test
         17 - Domain Impersonation
         18 - SpamAssassin Spam Status
         19 - SpamAssassin Spam Level
         20 - SpamAssassin Spam Flag
         21 - SpamAssassin Spam Report
         22 - OVH's X-VR-SPAMCAUSE
         23 - OVH's X-Ovh-Spam-Reason
         24 - OVH's X-Ovh-Spam-Score
         25 - X-Virus-Scan
         26 - X-Spam-Checker-Version
         27 - X-IronPort-AV
         28 - X-IronPort-Anti-Spam-Filtered
         29 - X-IronPort-Anti-Spam-Result
         30 - X-Mimecast-Spam-Score
         31 - Spam Diagnostics Metadata
         32 - MS Defender ATP Message Properties
         33 - Message Feedback Loop
         34 - End-to-End Latency - Message Delivery Time
         36 - X-IP-Spam-Verdict
         37 - X-Amp-Result
         38 - X-IronPort-RemoteIP
         39 - X-IronPort-Reputation
         40 - X-SBRS
         41 - X-IronPort-SenderGroup
         42 - X-Policy
         43 - X-IronPort-MailFlowPolicy
         44 - X-SEA-Spam
         45 - X-FireEye
         46 - X-AntiAbuse
         47 - X-TMASE-Version
         48 - X-TM-AS-Product-Ver
         49 - X-TM-AS-Result
         50 - X-IMSS-Scan-Details
         51 - X-TM-AS-User-Approved-Sender
         52 - X-TM-AS-User-Blocked-Sender
         53 - X-TMASE-Result
         54 - X-TMASE-SNAP-Result
         55 - X-IMSS-DKIM-White-List
         56 - X-TM-AS-Result-Xfilter
         57 - X-TM-AS-SMTP
         58 - X-TMASE-SNAP-Result
         59 - X-TM-Authentication-Results
         60 - X-Scanned-By
         61 - X-Mimecast-Spam-Signature
         62 - X-Mimecast-Bulk-Signature
         63 - X-Forefront-Antispam-Report-Untrusted
         64 - X-Microsoft-Antispam-Untrusted
         65 - X-Mimecast-Impersonation-Protect
         66 - X-Proofpoint-Spam-Details
         67 - X-Proofpoint-Virus-Version
         68 - SPFCheck
         69 - X-Barracuda-Spam-Score
         70 - X-Barracuda-Spam-Status
         71 - X-Barracuda-Spam-Report
         72 - X-Barracuda-Bayes
         73 - X-Barracuda-Start-Time
         74 - Similar to SpamAssassin Spam Level headers
         75 - SMTP Header Contained IP address
         76 - Other unrecognized Spam Related Headers
         77 - Other interesting headers
         78 - Security Appliances Spotted
         79 - Email Providers Infrastructure Clues
         80 - X-Microsoft-Antispam-Message-Info (use -a to show its results)
         81 - Decoded Mail-encoded header values (use -a to show its results)
         82 - Header Containing Client IP
         83 - Office365 Tenant ID
         84 - Organization Name
         85 - MS Defender for Office365 Safe Links Version
         86 - Suspicious Words in Headers
         87 - AWS SES Outgoing
         88 - IronPort-Data
         89 - IronPort-HdrOrder
         90 - X-DKIM
         91 - DKIM-Filter
         92 - X-SpamExperts-Class
         93 - X-SpamExperts-Evidence
         94 - X-Recommended-Action
         95 - X-AppInfo
         96 - X-Spam
         97 - X-TM-AS-MatchedID
         98 - MTA Hostname Exposed
         99 - Office365 First Contact Safety Tip
        100 - EOP - Bypass Focused Inbox
        101 - EOP - Enhanced Filtering - SkipListedInternetSender
        102 - EOP - Enhanced Filtering - ExternalOriginalInternetSender
        103 - Cloudmark Analysis
        104 - The Real Sender - via Authenticated-Sender
        105 - Identified Sender Addresses
        106 - Unsual SMTP headers
root@kitploit:~
### HTML 보고서

HTML 보고서를 생성하려면 - 다음 매개변수를 사용하세요:```
  PS> py decode-spam-headers.py headers.txt -f html -o report.html

샘플 실행

샘플 실행 (출력 구조와 내용은 스크립트의 이전 버전에서 비롯된 것입니다):``` PS> py decode-spam-headers.py headers.txt


(1) Test: Received - Mail Servers Flow

HEADER: Received

VALUE: ...

ANALYSIS: - List of server hops used to deliver message:

root@kitploit:~
      --> (1) "attacker" <[email protected]>

           |_> (2) SMTP-SERVICE (44.55.66.77)
                  time: 01 Jan 2021 12:34:20

              |_> (3) mail-wr1-f51.google.com (209.85.221.51)
                      time: 01 Jan 2021 12:34:20
                      version: fuzzy match: Exchange Server 2019 CU11; October 12, 2021; 15.2.986.9

                  |_> (4) SN1NAM02FT0061.eop-nam02.prod.protection.outlook.com (2603:10b6:806:131:cafe::e5)
                          time: 01 Jan 2021 12:34:20
                          version: fuzzy match: Exchange Server 2019 CU11; October 12, 2021; 15.2.986.9

                      |_> (5) SA0PR11CA0138.namprd11.prod.outlook.com (2603:10b6:806:131::23)
                              time: 01 Jan 2021 12:34:20
                              version: fuzzy match: Exchange Server 2019 CU11; October 12, 2021; 15.2.986.9

                          |_> (6) CP2PR80MB4114.lamprd80.prod.outlook.com (2603:10d6:102:3c::15)
                                  time: 01 Jan 2021 12:34:23

                              |_> (7) "Victim Surname" <[email protected]>

[...]


(4) Test: Mail Client Version

HEADER: X-Mailer

VALUE: OEM

ANALYSIS: - X-Mailer header was present and contained value: "OEM".


(5) Test: X-Forefront-Antispam-Report

HEADER: X-Forefront-Antispam-Report

VALUE: CIP:209.85.167.100;CTRY:US;LANG:de;SCL:5;SRV:;IPV:NLI;SFV:SPM;H:mail-lf1-f100.google.com;PTR:mail-l f1-f100.google.com;CAT:DIMP;SFTY:9.19;SFS:(4636009)(956004)(166002)(6916009)(356005)(336012)(19 625305002)(22186003)(5660300002)(4744005)(6666004)(35100500006)(82960400001)(26005)(7596003)(7636003)(554460 02)(224303003)(1096003)(58800400005)(86362001)(9686003)(43540500002);DIR:INB;SFTY:9.19;

ANALYSIS: - Microsoft Office365/Exchange ForeFront Anti-Spam report

root@kitploit:~
    - CIP: Connecting IP address: 209.85.167.100

    - CTRY: The source country as determined by the connecting IP address
            - US

    - LANG: The language in which the message was written
            - de

    - IPV: Ingress Peer Verification status
            - NLI: The IP address was not found on any IP reputation list.

    - SFV: Message Filtering
            - SPM: The message was marked as spam by spam filtering.

    - H: The HELO or EHLO string of the connecting email server.
            - mail-lf1-f100.google.com

    - PTR: Reverse DNS of the Connecting IP peer's address
            - mail-lf1-f100.google.com

    - CAT: The category of protection policy
            - DIMP: Domain Impersonation

    - SFTY: The message was identified as phishing
            - 9.19: Domain impersonation. The sending domain is attempting to impersonate a protected domain

    - DIR: Direction of email verification
            - INB: Inbound email verification

    - Message matched 24 Anti-Spam rules (SFS):
            - (1096003)
            - (166002)
            - (19625305002)
            - (22186003)
            - (224303003)
            - (26005)
            - (336012)
            - (356005)
            - (35100500006)         - (SPAM) Message contained embedded image.
            - (43540500002)
            - (4636009)
            - (4744005)
            - (55446002)
            - (5660300002)
            - (58800400005)
            - (6666004)
            - (6916009)
            - (7596003)
            - (7636003)
            - (82960400001)
            - (86362001)
            - (956004)
            - (9686003)

    - SCL: Spam Confidence Level: 5
            - SPAM: Spam filtering marked the message as Spam

More information: - https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-spam-message-headers - https://docs.microsoft.com/en-us/exchange/antispam-and-antimalware/antispam-protection/antispam-stamps - https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels - https://docs.microsoft.com/en-us/exchange/monitoring/trace-an-email-message/run-a-message-trace-and-view-results


(6) Test: X-Microsoft-Antispam-Mailbox-Delivery

HEADER: X-Microsoft-Antispam-Mailbox-Delivery

VALUE: ucf:0;jmr:1;auth:0;dest:J;ENG:(910001)(944506458)(944626604)(750132)(520011016);

ANALYSIS: - This header denotes what to do with received message, where to put it.

root@kitploit:~
    - auth: Message originating from Authenticated sender
            - 0: Not Authenticated

    - dest: Destination where message should be placed
            - J: JUNK directory

    - Message matched 6 Anti-Spam Delivery rules:
            - (520011016)
            - (750132)
            - (910001)
            - (944506458)
            - (944626604)

(7) Test: X-Microsoft-Antispam Bulk Mail

HEADER: X-Microsoft-Antispam VALUE: BCL:0;

ANALYSIS: - BCL: BULK Confidence Level: 0 The message isn't from a bulk sender.

root@kitploit:~
More information:
            - https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/bulk-complaint-level-values

[...]


(10) Test: MS Defender ATP Message Properties

HEADER: X-MS-Exchange-AtpMessageProperties

VALUE: SA|SL

ANALYSIS: - MS Defender Advanced Threat Protection enabled following protections on this message: - Safe Attachments Protection - Safe Links Protection


(11) Test: Domain Impersonation

HEADER: From

VALUE: "attacker" [email protected]

ANALYSIS: - Mail From: [email protected]

root@kitploit:~
            - Mail Domain: attacker.com
                   --> resolves to: 11.22.33.44
                       --> reverse-DNS resolves to: ec2-11-22-33-44.eu-west-3.compute.amazonaws.com
                           (sender's domain: amazonaws.com)

            - First Hop:   SMTP-SERVICE (44.55.66.77)
                   --> resolves to:
                       --> reverse-DNS resolves to: host44-55-66-77.static.arubacloud.pl
                           (first hop's domain: arubacloud.pl)

    - Domain SPF: "v=spf1 include:_spf.google.com ~all"

    - WARNING! Potential Domain Impersonation!
            - Mail's domain should resolve to:      amazonaws.com
            - But instead first hop resolved to:    arubacloud.pl
root@kitploit:~
---

### 크레딧

- [ipSlav](https://github.com/ipSlav) - [두 개의 Office365 불투명 규칙을 식별한 점](https://github.com/mgeeky/decode-spam-headers/issues/15): `42882007` 및 `78352004`


---

### 알려진 문제

- `getOffice365TenantNameById(tenantID)` 메서드는 아직 완성되지 않았습니다. Office365 테넌트 GUID를 테넌트 이름으로 매핑하는 몇 가지 방법을 알고 있지만, 아직 안정적인 방법을 확립하지 못했습니다.
- `Authentication-Results` 헤더는 아직 완전히 파싱되지 않았습니다. [Microsoft 문서](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-spam-message-headers?view=o365-worldwide)에 따라 `reason` 처리 및 기타 필드를 포함해야 합니다.

---

### ☕ 후원하기 ☕

이 프로젝트와 다른 프로젝트들은 잠 못 이루는 밤과 **많은 노력**의 결과물입니다. 제가 하는 일을 좋아하시고 항상 커뮤니티에 환원하는 점을 고맙게 여기신다면,
감사 인사를 전하기 위해 [커피 한 잔 사주시는 것](https://github.com/sponsors/mgeeky) _(아니면 차라리 맥주 한 잔)_ 을 고려해 보세요! 💪 

---```
Mariusz Banach / mgeeky, (@mariuszbit)
<mb [at] binary-offensive.com>
도구 다운로드
  • X-forefront-antispam-report
  • X-microsoft-antispam-mailbox-delivery
  • X-microsoft-antispam
  • X-exchange-antispam-report-cfa-test
  • X-spam-status
  • X-spam-level
  • X-spam-flag
  • X-spam-report
  • X-vr-spamcause
  • X-ovh-spam-reason
  • X-vr-spamscore
  • X-virus-scanned
  • X-spam-checker-version
  • X-ironport-av
  • X-ironport-anti-spam-filtered
  • X-ironport-anti-spam-result
  • X-mimecast-spam-score
  • Spamdiagnosticmetadata
  • X-ms-exchange-atpmessageproperties
  • X-msfbl
  • X-ms-exchange-transport-endtoendlatency
  • X-ms-oob-tlc-oobclassifiers
  • X-ip-spam-verdict
  • X-amp-result
  • X-ironport-remoteip
  • X-ironport-reputation
  • X-sbrs
  • X-ironport-sendergroup
  • X-policy
  • X-ironport-mailflowpolicy
  • X-remote-ip
  • X-sea-spam
  • X-fireeye
  • X-antiabuse
  • X-tmase-version
  • X-tm-as-product-ver
  • X-tm-as-result
  • X-imss-scan-details
  • X-tm-as-user-approved-sender
  • X-tm-as-user-blocked-sender
  • X-tmase-result
  • X-tmase-snap-result
  • X-imss-dkim-white-list
  • X-tm-as-result-xfilter
  • X-tm-as-smtp
  • X-scanned-by
  • X-mimecast-spam-signature
  • X-mimecast-bulk-signature
  • X-sender-ip
  • X-forefront-antispam-report-untrusted
  • X-microsoft-antispam-untrusted
  • X-sophos-senderhistory
  • X-sophos-rescan
  • X-MS-Exchange-CrossTenant-Id
  • X-OriginatorOrg
  • IronPort-Data
  • IronPort-HdrOrdr
  • X-DKIM
  • DKIM-Filter
  • X-SpamExperts-Class
  • X-SpamExperts-Evidence
  • X-Recommended-Action
  • X-AppInfo
  • X-Spam
  • X-TM-AS-MatchedID
  • X-MS-Exchange-EnableFirstContactSafetyTip
  • X-MS-Exchange-Organization-BypassFocusedInbox
  • X-MS-Exchange-SkipListedInternetSender
  • X-MS-Exchange-ExternalOriginalInternetSender
  • X-CNFS-Analysis
  • X-Authenticated-Sender
  • X-Apparently-From
  • X-Env-Sender
  • Sender