logo

Offensive SPF: How to Automate Anti-Phishing Reconnaissance Using Sender Policy Framework

ID: 3330bc1d-0d0d-5859-9f9f-6b8b21a55753

STIX ID: report--3330bc1d-0d0d-5859-9f9f-6b8b21a55753

Feed Name: Black Hills Infosec Blog

Date Published: 2018-06-28

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive Summary:** This blog post describes a proof-of-concept defensive/offensive technique called AutoRecon that uses the SPF 'exists' macro to induce DNS queries containing the originating IP of unauthenticated mail; a dedicated BIND9 service logs those queries and a script enriches them (e.g., via Shodan) and triggers alerts or blocking actions. The post includes configuration steps, example SPF and zone files, operational cautions (legal and mail-delivery risks), and ideas for extending the system with Nmap, Fail2Ban, and automation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.