✉ MailFail Extension (Firefox) and other resources m.ail.fail/ 🔗 Jack's list of DKIM selectors - github.com/ACK-J/MailFail/blob/main/DKIM_Selectors.txt - 🔗 Download the extension - addons.mozilla.org/en-US/firefox/addon/mailfail/ - 🔗 github repository - github.com/ACK-J/MailFail/ - 🔗 Reconstruct private keys from the two prime numbers - gist.github.com/ACK-J/487d0de5737458d953ca818a0645b09b - 🔗 Send DKIM signed emails script with a private key - gist.github.com/ACK-J/76585af46375641ec841cb6b77d345c3 - 🔗 Here's a bonus that wasn't in the presentation - Python script that takes in a list of domains and checks them for DMARC misconfigurations - gist.github.com/ACK-J/8a189bafbb54e00fb1b3f3e22dcd81c9 - 🛝 Webcast Slides - www.blackhillsinfosec.com/wp-content/uploads/2024/06/SLIDES_BHIS_MAILFAIL.pdf /// 🔗 Register for webcasts, summits, and workshops - blackhillsinfosec.zoom.us/ze/hub/stadium
Jack did great -- having someone technical give the webinar is fantastic. We got a good (review for me) technical explanation of SPF/DKIM/DMARC and why they really aren't that great. I'll stay tuned for more on the strength of this presentation --- the inclusion of misuse cases was one of the strongest points.