All methodologies
Email & mail-server security

Email Security Testing Methodology

Mail-server and email-authentication assessment — SPF, DKIM, DMARC, transport security, and the spoofing and relay weaknesses that enable phishing and business email compromise.

Phase 1

Reconnaissance

Map the mail estate

Enumerate MX records, mail servers, and published email-authentication policy for the domain.

MX / DNS enumeration
SPF / DKIM / DMARC lookup
Exchange fingerprinting
Phase 2

Server Enumeration

Fingerprint the servers

Identify mail services and supported protocols (SMTP, IMAP, POP3) and their transport-security configuration.

SMTP / IMAP / POP3 probing
mail-server-checker
STARTTLS / TLS checks
Phase 3

Vulnerability Analysis

Find the weaknesses

Test for open relay, user enumeration, weak or missing authentication policy, and misconfigured SPF/DKIM/DMARC that permit spoofing.

Open-relay detection
smtp-user-enum
email-security-scanner
SPF/DKIM/DMARC analysis
Phase 4

Spoofing & Phishing Validation

Prove the impact

Where authorized, demonstrate spoofing and deliverability gaps that enable phishing — with credential brute-force only against accounts you authorize.

email-spoofing-test
IMAP/POP3/SMTP-auth brute (authorized)
Native phishing (add-on)
Phase 5

Reporting

Make it actionable

Findings prioritised by impact with concrete DNS/server remediation to close spoofing and relay exposure.

Risk-scored findings
Remediation guidance
PDF / web / DOCX reports

Standards we map to

Every finding is tagged against the frameworks your compliance team actually uses.

SPF / DKIM / DMARC (RFC 7208/6376/7489)
NIST SP 800-177
ISO/IEC 27001:2022

A note on authorization

Every active test requires either attested ownership of the target during signup or an explicit written authorization on file. We log every test request against this authorization so there's never any ambiguity about scope — we are bound by the same Computer Misuse legislation our customers are.

Explore other methodologies

Ready to run a Email Security assessment?

Run your first scan in minutes. No credit card required for the free tier.