Logo Lanfrica
  • Accueil
  • Atlas
  • Analyses
  • Documentation
  • Sign in

© 2026 Lanfrica. Tous droits réservés. Tous les droits d'auteur des ressources affichées sur le site Web Lanfrica appartiennent aux détenteurs de droits d'auteur d'origine, sauf indication contraire explicite.

Mastertactician23/email-auth-phishing-auditor

Domaine:

peace and securitydigital infrastructure

Type de record:

softwaretools
Créateur:
Mas
Hôte:
Live DNS-based SPF/DKIM/DMARC domain auditor (PCI DSS 10.4.1.1 aligned) paired with a phishing header analyser — tested against real domains and East African fintech phishing patterns # Email Authentication & Phishing Defense Auditor ### A domain email authentication auditor (real live DNS queries against SPF/DKIM/DMARC) paired with a phishing header analyser — scored against PCI DSS 10.4.1.1 and tested against East African fintech-relevant phishing patterns **Author:** Kofi Asibey-Kitiabi **GitHub:** Mastertactician23 **LinkedIn:** asibey-kitiabi **Date:** July 2026 **Status:** Completed **Difficulty:** Advanced --- ## Why This Project > *"90%+ of successful cyberattacks begin with a phishing email."* — CISA > *"41% of banking institutions still lack DMARC protection, despite PCI DSS v4.0 Requirement 10.4.1.1 now mandating anti-phishing mechanisms for any organisation handling card data — enforced starting 2026."* > *"Only 18.4% of domains with DMARC configured actually enforce a policy (p=reject); the vast majority remain stuck in monitoring-only mode indefinitely."* — EasyDMARC, 2026 Phishing is the single most statistically significant attack vector across every threat report referenced throughout this portfolio — the M-Pesa credential theft and BEC scenarios simulated in the File Integrity Monitor project both began with a phishing email in their real-world basis. This project builds the defensive side: a tool that audits whether a domain's email is actually protected, and a tool that analyses a suspicious email to determine whether it's spoofed. **The most important distinction from every other project in this portfolio: the domain auditor's "real-world test" is not simulated.** It performs genuine, live DNS TXT record queries against real domains on the public internet — the exact same read-only, publicly-permitted methodology used by commercial tools like MXToolbox, EasyDMARC, and PowerDMARC. --- ## Table of Contents 1. Project Overview 2. Domain Authentication Auditor 3. Phishing Header Analyzer 4. Tools & Technologies 5. How to Run It 6. Real-World Domain Test Results 7. Phishing Scenario Results 8. PCI DSS & CISA Alignment 9 …

Visit

github.com

Similaires

Ezekiel-Yuhana/Phishing-Email-DetectionA Tri-Class Multilingual Phishing Email Dataset for Low-Resource Languages EvaluationCombating Phishing in Kenya: A Supervised Learning Model for Enhanced Email Security in Kenyan Financial InstitutionsMastertactician23/transaction-anomaly-detectornzivo/mpesa-authIan12571/Campus-Secure-Auth-

Ezekiel-Yuhana/Phishing-Email-Detection

AN AI-BASED CYBER ANALYTICS SYSTEM FOR PHISHING EMAIL DETECTION USING MACHINE LEARNING, CASE STUDY:

A Tri-Class Multilingual Phishing Email Dataset for Low-Resource Languages Evaluation

Combating Phishing in Kenya: A Supervised Learning Model for Enhanced Email Security in Kenyan Financial Institutions

Purpose: Phishing is a serious cybercrime problem that puts people and organizations at risk all aro

Mastertactician23/transaction-anomaly-detector

Python-based financial transaction anomaly detection engine — 11 fraud rules mapped to East African

nzivo/mpesa-auth

# M-Pesa Authenticator Service A secure, production-ready service for processing M-Pesa B2C (Busine

Ian12571/Campus-Secure-Auth-

A robust campus security authentication system designed to ensure seamless access control and safegu