An interactive lab to understand email authentication, replay attacks, and defenses.
DomainKeys Identified Mail adds a cryptographic signature to outgoing emails. The sending server signs with a private key; the receiving server verifies using the public key published in DNS.
An attacker intercepts a legitimately signed email and resends it later. Since standard DKIM has no expiry, the signature stays valid forever — the replayed email passes verification.
Strict timestamp expiry checks the t= tag in the DKIM signature.
If the signature is older than the allowed window (5s in this lab), the
server rejects it.
Step 1: Generate a signed email.
Step 2: Wait a few seconds (simulating interception).
Step 3: Replay it and observe the result.
Try both Vulnerable and Secure modes!
Configure the simulation, then generate a DKIM-signed email. In a real attack, this email would be intercepted in transit.
The attacker has the signed email from Step 1. They now replay it to the victim's mail server. Will the server accept or reject it?
Scan a real domain's DNS records to check its DKIM, DMARC, and SPF configuration for weaknesses.