DKIM Replay Attack Lab

An interactive lab to understand email authentication, replay attacks, and defenses.

DKIM

DomainKeys Identified Mail adds a cryptographic signature to outgoing emails. The sending server signs with a private key; the receiving server verifies using the public key published in DNS.

Replay Attack

An attacker intercepts a legitimately signed email and resends it later. Since standard DKIM has no expiry, the signature stays valid forever — the replayed email passes verification.

The Defense

Strict timestamp expiry checks the t= tag in the DKIM signature. If the signature is older than the allowed window (5s in this lab), the server rejects it.

Lab Steps

Step 1: Generate a signed email.
Step 2: Wait a few seconds (simulating interception).
Step 3: Replay it and observe the result.
Try both Vulnerable and Secure modes!

1 Configuration

Configure the simulation, then generate a DKIM-signed email. In a real attack, this email would be intercepted in transit.

Used for simulation. Also used for real DNS checks below.
Intercepted Email (Raw Source)
Awaiting interception... Click "Intercept & Sign Email" to generate a DKIM-signed message.
2 Attack Simulation Zone

The attacker has the signed email from Step 1. They now replay it to the victim's mail server. Will the server accept or reject it?

Attacker
Victim Mail Server

Server Verdict:

WAITING

Victim's Inbox
No messages yet.
Rejected / Quarantine
No messages yet.
3 Domain Vulnerability Scanner

Scan a real domain's DNS records to check its DKIM, DMARC, and SPF configuration for weaknesses.