websec-wykyk1
v1.0.0
Published
Email security posture checker for SPF, DMARC, and DKIM DNS records
Maintainers
Readme
websec-wykyk
Email security posture checker for SPF, DMARC, and DKIM DNS records. Zero runtime dependencies — it uses Node's built-in dns module only.
Install
npm install websec-wykykOr run it directly without installing:
npx websec-wykyk example.comCLI usage
websec-wykyk example.com
websec-wykyk example.com --selectors google,default
websec-wykyk example.com --jsonExit code is 0/2 for a passing/failing grade respectively (grade F exits 2), and 1 on a usage or lookup error — useful for CI gating.
Programmatic usage
const { checkEmailSecurity } = require('websec-wykyk');
const report = await checkEmailSecurity('example.com', {
selectors: ['google', 'default'], // optional, only needed for DKIM
});
console.log(report.grade, report.score);
console.log(report.findings);Report shape
{
domain: string,
score: number, // 0-100
grade: 'A' | 'B' | 'C' | 'D' | 'F',
findings: Array<{ severity: 'critical' | 'high' | 'medium' | 'low' | 'info', message: string }>,
spf: { found, record, mechanisms, allQualifier, lookupCount, warnings, errors },
dmarc: { found, record, tags, warnings, errors },
dkim: { found, checkedSelectors, matches, warnings, errors },
}Individual checks are also exported:
const { checkSPF, checkDMARC, checkDKIM } = require('websec-wykyk');What it checks
SPF
- Record presence and uniqueness (multiple SPF TXT records cause a PermError)
- The
allmechanism qualifier (-all,~all,?all,+all) - The RFC 7208 10-DNS-lookup limit
DMARC
- Record presence at
_dmarc.<domain> - Enforcement policy (
p=nonevsquarantine/reject) pctcoverage,ruaaggregate reporting, and subdomain policy (sp)
DKIM
- Best-effort lookup against common selectors (
default,google,selector1,selector2,k1,dkim,mail,smtp) or a selector list you supply with--selectors/options.selectors. - DKIM selectors are not discoverable via DNS alone, so a "not found" result on the common-selector pass is informational, not a confirmed failure — pass known selectors for a definitive check.
Scoring
Starts at 100 and deducts points per issue (SPF/DMARC missing or unenforced weigh heaviest). This is a heuristic for quick triage, not a substitute for a full email-authentication audit.
Publishing this package
npm login
npm publishBump version in package.json first (npm version patch|minor|major).
Testing
npm testLicense
MIT
