Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Network Email Security

ASecurity

Email security review: dissect phishing samples (headers, URLs, attachments), assess a domain's spoofability via SPF/DKIM/DMARC alignment, recognize BEC patterns, and audit tenant anti-phishing controls incl. OAuth consent abuse. Load on phishing email analysis, .eml header review, "can this domain be spoofed", DMARC/SPF checks, or BEC investigation. Signals: Received chain, Authentication-Results, dmarc p=none, ~all vs -all, reply-to mismatch, lookalike domains.

20 stars
0 votes
0 copies
0 views
Added 10/5/2026
securityrustgogitsecurity

Works with

cli

Security Analysis

A100/100

Scanned 10/5/2026

$npx -y skills add NoorQureshi/SploitAgent --skill network-email-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Network Email Security?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Network Email Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-network-email-security/badge)](https://www.skillsdirectory.com/skills/noorqureshi-network-email-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: network-email-security
description: >
  Email security review: dissect phishing samples (headers, URLs, attachments), assess a domain's
  spoofability via SPF/DKIM/DMARC alignment, recognize BEC patterns, and audit tenant anti-phishing
  controls incl. OAuth consent abuse. Load on phishing email analysis, .eml header review,
  "can this domain be spoofed", DMARC/SPF checks, or BEC investigation. Signals: Received chain,
  Authentication-Results, dmarc p=none, ~all vs -all, reply-to mismatch, lookalike domains.
domain: network
type: checklist
stability: learning
modes: [pentest, bugbounty, defense]
severity: high
mitre: [T1566, T1566.002, T1078]
cwe: [CWE-290]
tools: [dig, nslookup, urlscan]
schema_version: 1
---

# Email security & phishing analysis

## When it applies
Two authorized jobs (`tradecraft-scope-roe`): **(a) defensive** — dissect a reported phishing
email or BEC attempt, extract IOCs, and recommend tenant controls (`defense-*` context); **(b)
offensive** — assess whether an in-scope domain can be spoofed (SPF/DKIM/DMARC posture) as
findings for a report. Sending simulated phishing is a separate, **pentest-only** track — load
`social-eng-methodology` first and never run it against a bug-bounty target. Never re-deliver
malicious samples to real users, and never mass-test third-party domains.

## Why it works
Spoofing succeeds when a domain's authentication records are missing, weak (`~all`, `p=none`), or
misaligned — the receiving server then has no cryptographic reason to reject a forged `From`. And
even with perfect auth, the *display name* and *Reply-To* are unauthenticated, which is what BEC
abuses. Reading full original headers exposes the truth the mail client hides.

## Method
1. **Full original headers** ("show original" / view source). Read the `Received` chain
   bottom-up — only the hops added by *your* infrastructure are trustworthy; early hops are
   sender-supplied. Check `From` vs `Return-Path` vs `Reply-To` consistency and the
   `Authentication-Results` header added by the receiving server.
2. **Auth records of the sender domain:**
   ```
   dig TXT example.com                 # SPF — note -all (hard fail) vs ~all (soft) vs missing;
                                       # >10 DNS lookups voids the record entirely
   dig TXT _dmarc.example.com          # DMARC — p=none only monitors; also check sp= (subdomains)
                                       # and rua (reporting); note relaxed vs strict alignment
   dig TXT <selector>._domainkey.example.com   # DKIM — selectors come from the DKIM-Signature header
   ```
3. **Content & URLs.** Defang and detonate links in a sandbox (urlscan.io), not in a browser.
   Compare link text vs href; check lookalike/punycode domains against the real brand.
4. **Attachments.** Static analysis / sandbox only — never open on a live host; route through
   `defense-malware-triage`.
5. **BEC pattern check.** Display-name impersonation of an exec, urgency + payment/wire/gift-card
   framing, `Reply-To` redirected to a free-mail or lookalike domain, thread hijacking.
6. **Tenant control review** (defensive engagements): anti-phishing policy, external-sender
   tagging, MFA coverage, and OAuth app consent grants — consent phishing rides legitimate
   identity providers, so audit authorized third-party apps (ties into `web-account-takeover`).
7. **Weaponize the IOCs** — sender addresses, reply-to, URLs/domains, attachment hashes feed
   `defense-detection-engineering` / `defense-threat-hunting` so the finding becomes a detection.

## Gotchas
- **`p=none` is not protection** — it only reports; likewise `~all` lets spoofed mail through as
  "soft fail". Only `-all` + `p=reject` (or `quarantine`) actually blocks.
- **Subdomains are separate** — without `sp=` in the DMARC record, `mail.example.com` may be
  spoofable when `example.com` isn't.
- **Display-name spoofing passes every check** — auth validates the domain, not the human name.
  The real signal is the `From` address domain and `Reply-To`.
- **Missing DKIM selector** — you can't query DKIM without the selector; pull it from the
  `DKIM-Signature` header's `s=` tag, or try common ones (`google`, `selector1`, `default`).
- **Forwarded mailing lists break SPF legitimately** — don't flag a false positive; alignment and
  DKIM survival matter more there.
- **Never click or detonate outside a sandbox**, and never send test phishing to third parties
  without explicit written authorization.

## Verify success
A written verdict per domain (SPF policy, DKIM validity, DMARC enforcement + alignment, spoofable
yes/no with the exact gap), plus — for sample analysis — a complete IOC list and concrete tenant
recommendations, each traceable to a header line or DNS record.

## References
RFC 7208 (SPF) / 6376 (DKIM) / 7489 (DMARC); urlscan.io; M365/Google anti-phishing policy docs.

---
_Portions adapted from [reverse-skill](https://github.com/zhaoxuya520/reverse-skill) by zhaoxuya520, MIT License._

Attribution

NoorQureshiNoorQureshi
View sourceSee grades on GitHubMore from NoorQureshi →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes
View all in security →