Golang tool to check SPF, DKIM, TLSA, and TLS settings for mailservers

Golang tool to check SPF, DKIM, TLSA, and TLS settings for mailservers

用于检查邮件服务器 SPF、DKIM、TLSA 和 TLS 设置的 Golang 工具

mailcheck

mailcheck

mailcheck is a small command-line SMTP/DNS/TLS diagnostic tool written in Go. It checks whether a domain appears correctly configured to receive SMTP mail and can emit Nagios/Icinga-compatible output. mailcheck 是一个用 Go 语言编写的小型命令行 SMTP/DNS/TLS 诊断工具。它用于检查域名是否已正确配置以接收 SMTP 邮件,并能输出兼容 Nagios/Icinga 的结果。

Features include: 功能包括:

  • Checks MX records, sorted by preference.
  • 检查 MX 记录,并按优先级排序。
  • Implicit-MX fallback to A/AAAA when no MX exists.
  • 当不存在 MX 记录时,自动回退到 A/AAAA 记录。
  • Null MX (RFC 7505) detection.
  • 支持 Null MX (RFC 7505) 检测。
  • A and AAAA resolution; IPv4/IPv6 selection.
  • A 和 AAAA 解析;支持 IPv4/IPv6 选择。
  • TCP SMTP connectivity; SMTP greeting and EHLO.
  • TCP SMTP 连接性;SMTP 问候语和 EHLO 检查。
  • STARTTLS support and negotiation; optional implicit TLS (—implicit-tls, useful for port 465).
  • 支持 STARTTLS 及协商;可选隐式 TLS(—implicit-tls,适用于 465 端口)。
  • Certificate parsing, hostname/PKIX verification, issuer, dates and expiry.
  • 证书解析、主机名/PKIX 验证、颁发者、日期及有效期检查。
  • TLS 1.2/1.3 and modern AEAD cipher classification.
  • TLS 1.2/1.3 及现代 AEAD 加密套件分类。
  • TLSA lookup and certificate/public-key matching for DANE-TA(2) and DANE-EE(3); PKIX usages 0 and 1 are unusable for SMTP (RFC 7672).
  • 针对 DANE-TA(2) 和 DANE-EE(3) 的 TLSA 查询及证书/公钥匹配;PKIX 用法 0 和 1 不适用于 SMTP (RFC 7672)。
  • DNSSEC indication using the AD bit returned by the selected recursive resolver.
  • 利用所选递归解析器返回的 AD 位进行 DNSSEC 指示。
  • SPF record discovery and basic syntax/lookup-limit checks.
  • SPF 记录发现及基础语法/查询限制检查。
  • DMARC record parsing and policy checks, with organizational-domain fallback.
  • DMARC 记录解析及策略检查,支持组织域名回退。
  • DKIM selector checks, including RSA and Ed25519 public-key validation.
  • DKIM 选择器检查,包括 RSA 和 Ed25519 公钥验证。
  • Human, JSON and Nagios/Icinga output.
  • 支持人类可读、JSON 和 Nagios/Icinga 格式输出。

Build

构建

Requires Go 1.24 or newer. 需要 Go 1.24 或更高版本。

go build -o mailcheck .
# For a Linux install:
# 对于 Linux 安装:
install -m 0755 mailcheck /usr/local/bin/mailcheck

DNSSEC / DANE note

DNSSEC / DANE 注意事项

The program requests EDNS DNSSEC data and reports DNSSEC as secure when the recursive resolver returns the DNS AD (Authenticated Data) bit. It does not implement a complete DNSSEC validator itself. For production DANE monitoring, point —dns at a validating recursive resolver you trust. 该程序会请求 EDNS DNSSEC 数据,并在递归解析器返回 DNS AD(已验证数据)位时报告 DNSSEC 为安全。它本身并未实现完整的 DNSSEC 验证器。对于生产环境的 DANE 监控,请将 --dns 指向您信任的验证型递归解析器。

SPF / DKIM / DMARC scope

SPF / DKIM / DMARC 范围

These checks are deliberately DNS-policy diagnostics, not a complete mail-authentication implementation. SPF checks the record syntax, multiple-record condition, terminal policy, and the ten-DNS-lookup limit at the top level. It does not simulate every possible sender IP through a complete recursive SPF evaluation. 这些检查旨在作为 DNS 策略诊断,而非完整的邮件身份验证实现。SPF 检查记录语法、多记录条件、终止策略以及顶层的十次 DNS 查询限制。它不会通过完整的递归 SPF 评估来模拟每一个可能的发送者 IP。

DKIM requires selectors because DNS does not provide a universal way to enumerate all selectors. The DKIM check validates the public-key encoding and RSA key size / Ed25519 key length, but it does not verify a signed message. DKIM 需要选择器,因为 DNS 没有提供枚举所有选择器的通用方法。DKIM 检查会验证公钥编码和 RSA 密钥大小/Ed25519 密钥长度,但不会验证已签名的消息。

DMARC validates the record and key policy tags but does not evaluate an actual message’s SPF/DKIM alignment. If the domain has no DMARC record, the organizational domain’s record is used (RFC 7489 section 6.6.3), with its sp policy if present. DMARC 会验证记录和关键策略标签,但不会评估实际邮件的 SPF/DKIM 对齐情况。如果域名没有 DMARC 记录,则会使用组织域名的记录(RFC 7489 第 6.6.3 节),并在存在时使用其 sp 策略。

Security / operational considerations

安全与操作注意事项

The SMTP test performs a real TCP connection to the target’s port 25 (or the explicitly selected port). It does not send mail or authenticate. With —implicit-tls, the greeting and EHLO are checked inside TLS. SMTP 测试会向目标的 25 端口(或显式选择的端口)发起真实的 TCP 连接。它不会发送邮件或进行身份验证。使用 --implicit-tls 时,问候语和 EHLO 会在 TLS 内部进行检查。

TLS certificate verification is performed separately from the TLS handshake so that a certificate that is not publicly trusted can still be inspected and compared with a DANE TLSA record. This is intentional for SMTP/DANE diagnostics. TLS 证书验证与 TLS 握手是分开执行的,因此即使是不受公共信任的证书,也可以进行检查并与 DANE TLSA 记录进行比较。这是为了 SMTP/DANE 诊断而特意设计的。