Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Evaluate your domain's resilience against envelope and header spoofing by deeply validating SPF, DKIM, and DMARC alignments in accordance with RFC 7208, RFC 6376, and RFC 7489. Pinpoint policy gaps, cryptographic failures, and identifier misalignments to prevent exact-domain impersonation attacks.
Evaluate your domain's resilience against envelope and header spoofing by deeply validating SPF, DKIM, and DMARC alignments in accordance with RFC 7208, RFC 6376, and RFC 7489. Pinpoint policy gaps, cryptographic failures, and identifier misalignments to prevent exact-domain impersonation attacks.
Threat actors routinely exploit the SMTP protocol's inherent lack of sender authentication (RFC 5321) by manipulating the MailFrom envelope sender and the RFC 5322 From header. Implementing SPF provides path-based authorization, while DKIM provides cryptographic non-repudiation of message bodies and headers via RSA or Ed25519 signatures. However, true anti-spoofing requires DMARC (RFC 7489) to bind the authenticated identity from SPF or DKIM to the visible From header. Without a comprehensive, strictly enforced DMARC policy (p=reject or p=quarantine), organizations remain vulnerable to Business Email Compromise (BEC), spear-phishing, and domain reputation degradation, fundamentally undermining zero-trust email architectures.
Permissive DMARC Policies: Deploying DMARC with a 'p=none' policy perpetually without migrating to enforcement, neutralizing actual spoofing protection.
DNS Record Resolution: We perform deep DNS lookups to extract TXT records associated with SPF, DMARC, and DKIM selectors for the specified domain.
Syntax and Policy Validation: Each record is parsed against its respective RFC standard (e.g., RFC 7208 for SPF, RFC 7489 for DMARC) to identify syntax errors, unknown modifiers, or policy weaknesses.
Alignment Verification: We simulate the authentication process, evaluating strict (adkim=s, aspf=s) versus relaxed alignment between the envelope/signing domains and the visible header domain.
Cryptographic Key Assessment: If a DKIM selector is provided, we fetch the public key, validating its length, type (RSA/Ed25519), and revocation status.
Evaluates domain-level DMARC records for enforcement policies (p=, sp=), strict/relaxed alignment tags (adkim, aspf), and reporting configurations (rua, ruf) to ensure RFC 7489 compliance.
Parses the SPF macro language to recursively count DNS lookups, ensuring the critical 10-lookup threshold (RFC 7208) is not exceeded, while checking for obsolete mechanisms like ptr.
Inspects published DKIM public keys for cryptographic strength, identifying weak 1024-bit RSA keys and validating syntax for both RSA and Ed25519 (RFC 8463) algorithms.
Verifies that the prerequisite authenticated foundation (DMARC at enforcement) is established before Brand Indicators for Message Identification (BIMI) can be successfully implemented.
Simulates the binding process between authenticated domains (from SPF and DKIM) and the author domain (RFC 5322 From) to detect structural misalignments.
Analyzes the explicit or implicit subdomain policies (sp=) to ensure organizational domains do not inadvertently expose unauthenticated subdomains to threat actors.
Run a comprehensive cryptographic and policy analysis to lock down your email infrastructure.