Golang tool to check SPF, DKIM, TLSA, and TLS settings for mailservers
Golang tool to check SPF, DKIM, TLSA, and TLS settings for mailservers
用于检查邮件服务器 SPF、DKIM、TLSA 和 TLS 设置的 Golang 工具
mailcheck
mailcheck
mailcheck is a small command-line SMTP/DNS/TLS diagnostic tool written in Go. It checks whether a domain appears correctly configured to receive SMTP mail and can emit Nagios/Icinga-compatible output. mailcheck 是一个用 Go 语言编写的小型命令行 SMTP/DNS/TLS 诊断工具。它用于检查域名是否已正确配置以接收 SMTP 邮件,并能输出兼容 Nagios/Icinga 的结果。
Features include: 功能包括:
- Checks MX records, sorted by preference.
- 检查 MX 记录,并按优先级排序。
- Implicit-MX fallback to A/AAAA when no MX exists.
- 当不存在 MX 记录时,自动回退到 A/AAAA 记录。
- Null MX (RFC 7505) detection.
- 支持 Null MX (RFC 7505) 检测。
- A and AAAA resolution; IPv4/IPv6 selection.
- A 和 AAAA 解析;支持 IPv4/IPv6 选择。
- TCP SMTP connectivity; SMTP greeting and EHLO.
- TCP SMTP 连接性;SMTP 问候语和 EHLO 检查。
- STARTTLS support and negotiation; optional implicit TLS (—implicit-tls, useful for port 465).
- 支持 STARTTLS 及协商;可选隐式 TLS(—implicit-tls,适用于 465 端口)。
- Certificate parsing, hostname/PKIX verification, issuer, dates and expiry.
- 证书解析、主机名/PKIX 验证、颁发者、日期及有效期检查。
- TLS 1.2/1.3 and modern AEAD cipher classification.
- TLS 1.2/1.3 及现代 AEAD 加密套件分类。
- TLSA lookup and certificate/public-key matching for DANE-TA(2) and DANE-EE(3); PKIX usages 0 and 1 are unusable for SMTP (RFC 7672).
- 针对 DANE-TA(2) 和 DANE-EE(3) 的 TLSA 查询及证书/公钥匹配;PKIX 用法 0 和 1 不适用于 SMTP (RFC 7672)。
- DNSSEC indication using the AD bit returned by the selected recursive resolver.
- 利用所选递归解析器返回的 AD 位进行 DNSSEC 指示。
- SPF record discovery and basic syntax/lookup-limit checks.
- SPF 记录发现及基础语法/查询限制检查。
- DMARC record parsing and policy checks, with organizational-domain fallback.
- DMARC 记录解析及策略检查,支持组织域名回退。
- DKIM selector checks, including RSA and Ed25519 public-key validation.
- DKIM 选择器检查,包括 RSA 和 Ed25519 公钥验证。
- Human, JSON and Nagios/Icinga output.
- 支持人类可读、JSON 和 Nagios/Icinga 格式输出。
Build
构建
Requires Go 1.24 or newer. 需要 Go 1.24 或更高版本。
go build -o mailcheck .
# For a Linux install:
# 对于 Linux 安装:
install -m 0755 mailcheck /usr/local/bin/mailcheck
DNSSEC / DANE note
DNSSEC / DANE 注意事项
The program requests EDNS DNSSEC data and reports DNSSEC as secure when the recursive resolver returns the DNS AD (Authenticated Data) bit. It does not implement a complete DNSSEC validator itself. For production DANE monitoring, point —dns at a validating recursive resolver you trust.
该程序会请求 EDNS DNSSEC 数据,并在递归解析器返回 DNS AD(已验证数据)位时报告 DNSSEC 为安全。它本身并未实现完整的 DNSSEC 验证器。对于生产环境的 DANE 监控,请将 --dns 指向您信任的验证型递归解析器。
SPF / DKIM / DMARC scope
SPF / DKIM / DMARC 范围
These checks are deliberately DNS-policy diagnostics, not a complete mail-authentication implementation. SPF checks the record syntax, multiple-record condition, terminal policy, and the ten-DNS-lookup limit at the top level. It does not simulate every possible sender IP through a complete recursive SPF evaluation. 这些检查旨在作为 DNS 策略诊断,而非完整的邮件身份验证实现。SPF 检查记录语法、多记录条件、终止策略以及顶层的十次 DNS 查询限制。它不会通过完整的递归 SPF 评估来模拟每一个可能的发送者 IP。
DKIM requires selectors because DNS does not provide a universal way to enumerate all selectors. The DKIM check validates the public-key encoding and RSA key size / Ed25519 key length, but it does not verify a signed message. DKIM 需要选择器,因为 DNS 没有提供枚举所有选择器的通用方法。DKIM 检查会验证公钥编码和 RSA 密钥大小/Ed25519 密钥长度,但不会验证已签名的消息。
DMARC validates the record and key policy tags but does not evaluate an actual message’s SPF/DKIM alignment. If the domain has no DMARC record, the organizational domain’s record is used (RFC 7489 section 6.6.3), with its sp policy if present.
DMARC 会验证记录和关键策略标签,但不会评估实际邮件的 SPF/DKIM 对齐情况。如果域名没有 DMARC 记录,则会使用组织域名的记录(RFC 7489 第 6.6.3 节),并在存在时使用其 sp 策略。
Security / operational considerations
安全与操作注意事项
The SMTP test performs a real TCP connection to the target’s port 25 (or the explicitly selected port). It does not send mail or authenticate. With —implicit-tls, the greeting and EHLO are checked inside TLS.
SMTP 测试会向目标的 25 端口(或显式选择的端口)发起真实的 TCP 连接。它不会发送邮件或进行身份验证。使用 --implicit-tls 时,问候语和 EHLO 会在 TLS 内部进行检查。
TLS certificate verification is performed separately from the TLS handshake so that a certificate that is not publicly trusted can still be inspected and compared with a DANE TLSA record. This is intentional for SMTP/DANE diagnostics. TLS 证书验证与 TLS 握手是分开执行的,因此即使是不受公共信任的证书,也可以进行检查并与 DANE TLSA 记录进行比较。这是为了 SMTP/DANE 诊断而特意设计的。