MailFail: Spoof Emails in Seconds | Jack Hyland @WildWestHackinFest
MailFail: Spoof Emails in Seconds | Jack Hyland  @WildWestHackinFest
Uploaded June 2025 | Updated September 2026, 2 weeks ago
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com

🔗 Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com

Join me as we delve into the intricacies and quirks of email, uncovering both its complexities and its absurdities.
After spending several months delving into the relevant RFCs relating to Email (SMTP) ,
I gained a comprehensive understanding of how to abuse the email ecosystem.
In this presentation, I will get you up to speed with a browser extension called MailFail
so that you can quickly identify and exploit email misconfigurations.

This talk is a continuation of the webcast "MailFail: Who's Spoofing your Email, and How are they Doing it?".
Please watch the original webcast if you need a refresher on the basics of bypassing SPF, DKIM and DMARC:
youtube.com/watch?v=UbdMAmsWus8&themeRefresh=1

00:00 - Welcome, intro, whoami
00:30 - Resources and Links
00:34 - Previous Webcast on MailFail
youtube.com/watch?v=UbdMAmsWus8
00:49 - Previous Webcast on MailFail
01:47 - What you will learn from this talk
02:42 - Try to Phish me!
03:40 - What does the MAILFAIL extension do?
04:44 - Showing what the extension does (NOT a DEMO)
06:11 - SMPT Open Relays
09:04 - Cracking DKIM Keys
10:17 - CADO Number Field Sieve (NFS)
13:36 - FInding SPF/DMARC Misconfigurations
17:46 - Spoofing emails using Microsoft and CloudShell
18:55 - Spoofing Misconfig DMARC to Outlook Inbox
20:25 - DMARC Hierarchy of Stupidity
22:52 - Epoicgames.com example
23:44 - Portal.Azure.com Cloud Shell
23:52 - New IP Adress generated on window refresh
24:29 - 50/50 Chance of bypassing DMARC
25:10 - SPF/DMARC Domain Takeover
25:48 - DMARC RUA/RUF DMARC Reporting
27:17 - Little DEMO
28:39 - Microsoft Direct Send
32:18 - NSEC Walking
36:10 - NSEC3 Cracking
40:21 - Reply-To
42:33 - OSINT and OPSEC and DMARC.live
43:17 - Conclusion
43:33 - References
43:51 - Q&A - Does the SSL flag need to be there?


///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe

///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections

///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response

///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com

///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training

///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
MailFail: Spoof Emails in Seconds | Jack HylandWorkshop: Open-Source Intelligence (OSINT) | Joe Gray | WWHF 2023Ethics on the Line  Balancing Social Engineering Success with Target Protection | Jennifer IsacoffRATs & Ladders: Climbing from Access to Control | Nevan Beal & Jason RathbunPWN Free or Die Hard: The YOLO Index and Tactical Risk in Red Team | Alethe DenisFusing Reverse Shells And Kernel Exploits For Fun and Profit | Aleksa ZatezaloA Journey from Alert1 to P1: Cat Pic Graffiti and Phishing Payloads | Cary HooperAnalysis without Paralysis: Mastering the Art of Investigation | Terryn ValikodathImmunity, Free Speech & the (Potential) Death of  Internet: Section 230 | Kelli Tarala | WWHF 2023Two Cyber Guys And an Al Walk Into a Bar | Derek Banks, Joff ThyerExfiltrate and Command Network Nodes Like a Ghost! | Momen Eldawakhly | WWHF 2023TOOL: Adam and Eve | Darryl Baker
Wild West Hackin Fest |

MailFail: Spoof Emails in Seconds | Jack Hyland

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER