Professional Email Security
Assessment Framework

A modular, open-source email spoofing simulation toolkit for authorized penetration testing and red team operations. Test your organization's defenses with realistic phishing scenarios.

Open Source Apache-2.0 Python 3.8+ Cross-Platform
bash
45+
Built-in Templates
10+
Linux Distros
3
Package Formats
1
Dependency

Everything You Need

A complete toolkit covering the full email security assessment lifecycle.

Email Spoofing Engine

Craft and send spoofed emails with full MIME control. Interactive CLI wizard for sender identity, subject, and body configuration.

Built-in Templates

45+ pre-configured phishing scenarios across corporate, financial, social media, collaboration, cloud, and consumer service attack vectors.

Built-in SMTP Server

Local SMTP relay with MX resolution, TLS support, and authentication. Run on any port for controlled testing.

Audit & Reporting

Automatic JSON logging and structured assessment reports with success rates, risk scores, and remediation guidance.

Custom Templates

Build your own phishing scenarios interactively. Save and reuse custom bodies, subjects, and sender profiles.

Template Preview & Filter

Preview any template before sending and filter the template list by keyword or tag. Remove or edit templates directly from the CLI.

SMTP Profiles

Save named SMTP relay configurations (host, port, credentials, TLS) and reuse them across campaigns with a single --profile flag.

Verbose Diagnostics

Use --verbose to trace every SMTP stage: connection, STARTTLS, authentication, and sending. Diagnose delivery failures with detailed error explanations.

Clean Uninstall

Remove every trace with a single command. Cleans wrappers, project files, venvs, and configuration automatically.

Ready to Test Your Defenses?

MailSpoof is free, open-source, and built for security professionals. Install in seconds and start assessing your email infrastructure.