In this module, we will learn how to perform phishing campaigns like Red Team Operators.

Check TXT Records

we will check the TXT record to see if there was security protection that will prevent us from performing Phishing campaigns.

dig +short TXT microsoft.com

Untitled

Now let’s search for the security records.

Untitled

Note that the SPF is on the Domain.

Now What is the SPF !!

HAHA Time to search.

SPF Is Used in sender identity verification.

Untitled

To make it easier you can think about the SPF as a guard that protects the mail from being spoofed

But what is email spoofing !!

Untitled

Email spoofing is the forgery of an email header.

  1. The email appears to be from the original source