A comprehensive tool for discovering subdomains using OSINT and performing SPF shadow record analysis.
- Queries crt.sh, VirusTotal, SecurityTrails, and subdomain.center
- Validates subdomains
- Performs SPF record lookups and classification
- Exports data to CSV
- Interactive CLI menu
- Performs DMARC Scanning
- Performs DKIM Scanning
- Performs SPF Vulnerability Scans
- Virustotal and SecurityTrails API keys are encourged, but not required.
git clone https://github.com/chillyilly/spfshadow.git
cd spfshadow
pip install bs4 requests dnspythonpython3 spfshadow.py