Recon Report
Email Spoofability Can you spoof email from this domain?
SPF — Sender Policy Framework
RFC 7208 — Sender Policy Framework
SPF allows domain owners to specify which mail servers are authorized to send email on behalf of their domain. Without SPF, any server can forge the envelope sender.
DKIM — DomainKeys Identified Mail
RFC 6376 — DomainKeys Identified Mail
DKIM provides cryptographic authentication of email messages. Selector names often reveal email providers (e.g., google, selector1 = Microsoft 365).
DMARC — Domain-based Message Authentication
RFC 7489 — DMARC
DMARC ties SPF and DKIM together with a policy that tells receiving servers what to do with unauthenticated mail. p=none is monitoring only — attackers love it.
Transport Security Can you intercept email in transit?
DANE / TLSA
MTA-STS
TLS-RPT
RFC 8460 — SMTP TLS Reporting
TLS-RPT enables reporting of TLS negotiation failures. Without it, STARTTLS downgrade attacks leave no trace.
Brand & Certificate Security Can you fake this brand's identity?
BIMI
CAA — Certificate Authority Authorization
RFC 8659 — CAA
CAA records specify which Certificate Authorities are authorized to issue certificates. Without CAA, an attacker could obtain a valid cert from any CA.
DNS Infrastructure Can you poison the DNS?
DNSSEC
RFC 4033–4035 — DNSSEC
DNSSEC adds cryptographic signatures to DNS responses, preventing cache poisoning and response forgery. Without DNSSEC, an attacker can forge DNS answers.
NS Delegation
DNS Provider
Attack Surface Discovery What can you find from the outside?
Subdomain Discovery (Multi-Source)
| Subdomain |
|---|
map[cert_count:0 cname_chain:[account.microsoft.com.edgekey.net e9412.b.akamaiedge.net] cname_target:e9412.b.akamaiedge.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:accounts.microsoft.com provider:Akamai provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[admin-portal.office.com m365adminportal-prod-defaultgeo.trafficmanager.net bx-0004.bx-msedge.net] cname_target:bx-0004.bx-msedge.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:admin.microsoft.com provider:Azure Traffic Manager provider_category:Cloud source:dns] |
map[cert_count:0 cname_chain:[reroute.microsoft.com reroute443.trafficmanager.net] cname_target:reroute443.trafficmanager.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:alerts.microsoft.com provider:Azure Traffic Manager provider_category:Cloud source:dns] |
map[cert_count:0 cname_chain:[dnmpn.trafficmanager.net dnmpneuw.azurewebsites.net waws-prod-am2-021.vip.azurewebsites.windows.net waws-prod-am2-021.westeurope.cloudapp.azure.com] cname_target:waws-prod-am2-021.westeurope.cloudapp.azure.com first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:assets.microsoft.com provider:Azure provider_category:Cloud source:dns] |
map[cert_count:0 cname_chain:[autodiscover.outlook.com atod-g2.tm-4.office.com] cname_target:atod-g2.tm-4.office.com first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:autodiscover.microsoft.com provider:Microsoft 365 provider_category:Email source:dns] |
map[cert_count:0 cname_chain:[connect.microsoft.akadns.net] cname_target:connect.microsoft.akadns.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:beta.microsoft.com provider:Akamai provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[global-web-build2025-prod.trafficmanager.net build2025-prod-westus.azurewebsites.net waws-prod-bay-227.sip.azurewebsites.windows.net waws-prod-bay-227-9bc4.westus.cloudapp.azure.com] cname_target:waws-prod-bay-227-9bc4.westus.cloudapp.azure.com first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:build.microsoft.com provider:Azure provider_category:Cloud source:dns] |
map[cert_count:0 cname_chain:[officecdnmac.microsoft.com.edgekey.net e8364.dscd.akamaiedge.net] cname_target:e8364.dscd.akamaiedge.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:cdn.microsoft.com provider:Akamai provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[reroute.microsoft.com reroute443.trafficmanager.net] cname_target:reroute443.trafficmanager.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:cloud.microsoft.com provider:Azure Traffic Manager provider_category:Cloud source:dns] |
map[cert_count:0 cname_chain:[developer.microsoft.com.edgekey.net e2921.dscb.akamaiedge.net] cname_target:e2921.dscb.akamaiedge.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:dev.microsoft.com provider:Akamai provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[docs.microsoft.com-c.edgekey.net e13630.dscb.akamaiedge.net] cname_target:e13630.dscb.akamaiedge.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:docs.microsoft.com provider:Akamai provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[ftp.microsoft.akadns.net] cname_target:ftp.microsoft.akadns.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:ftp.microsoft.com provider:Akamai provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[github-microsoft-htf0b3b8bfdbhffv.z01.azurefd.net mr-z01.tm-azurefd.net shed.dual-low.part-0010.t-0009.t-msedge.net part-0010.t-0009.t-msedge.net] cname_target:part-0010.t-0009.t-msedge.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:github.microsoft.com provider:Azure Front Door provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[reroute.microsoft.com reroute443.trafficmanager.net] cname_target:reroute443.trafficmanager.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:help.microsoft.com provider:Azure Traffic Manager provider_category:Cloud source:dns] |
map[cert_count:0 cname_chain:[prdf.aadg.msidentity.com www.tm.f.prd.aadg.trafficmanager.net] cname_target:www.tm.f.prd.aadg.trafficmanager.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:identity.microsoft.com provider:Azure Traffic Manager provider_category:Cloud source:dns] |
map[cert_count:0 cname_chain:[i.microsoft.com.edgekey.net e1693.dscg.akamaiedge.net] cname_target:e1693.dscg.akamaiedge.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:img.microsoft.com provider:Akamai provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[origin.mobile.ms.akadns.net] cname_target:origin.mobile.ms.akadns.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:m.microsoft.com provider:Akamai provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[manage-pe.trafficmanager.net pexsucpna03.centralus.cloudapp.azure.com] cname_target:pexsucpna03.centralus.cloudapp.azure.com first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:manage.microsoft.com provider:Azure provider_category:Cloud source:dns] |
map[cert_count:0 cname_chain:[ashy-meadow-0b28bcb0f.azurestaticapps.net staticwebapps5acb33257c684edeb36f840bde3e7fd2.z01.azurefd.net mr-z01.tm-azurefd.net shed.dual-low.part-0010.t-0009.t-msedge.net part-0010.t-0009.t-msedge.net] cname_target:part-0010.t-0009.t-msedge.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:media.microsoft.com provider:Azure Front Door provider_category:CDN source:dns] |
map[cert_count:0 cname_chain:[origin.mobile.ms.akadns.net] cname_target:origin.mobile.ms.akadns.net first_seen: is_current:true is_wildcard:false issuers:[] last_seen: name:mobile.microsoft.com provider:Akamai provider_category:CDN source:dns] |
Intelligence Metadata Can you verify this independently?
badb5068853ededbd3ed18e158284e359b04f7273863a8e7fc9e6da155c84a9ef90141a5623ab627d7bb6ec6c5fa1fd91eb987357605967a2b2d9e90f411ba4d
