Emails
Chrome extension
Google Dork
Find email adresses
Mail is used on different sites like twitter, etc.
Social MediaOpsec / Anonymity
OpSec / AnonymityEmail Spoofing
Check SPF, DKIM, DMARC
Strict DMARC policy (such as “p=reject”) is not defined.
MailSecOps


Online Tool - Spoof Mail
DMARC-SPF-Checker
With Gophish


With Social-Engineer Toolkit
In this example, we use brevo as a smtp relay server. The mail received will be of the form username_spoofed@smtp_relay_domain rather than username_spoofed@domain_spoofed, as brevo modifies the domain name for security reasons.
https://www.youtube.com/watch?v=lR_Ck3-_AGQ







Email Security Checklist
Resources
Open Relay
SMTP (25, 465)Google Account - GHunt
Extract email from commit history in GitHub repos
Interesting Books
Interesting BooksOpen Source Intelligence Techniques Learn how to gather data using OSINT tools and strategies.
Last updated
