Firefox Browser Add-ons
  • Extensions
  • Themes
    • for Firefox
    • Dictionaries & Language Packs
    • Other Browser Sites
    • Add-ons for Android
Log in
Preview of MailFail

MailFail by Hacks and Hops

MailFail identifies and provides commands to exploit a large number of email-related misconfigurations for the current domain and subdomain. The extension's UI popup highlights any misconfigurations in red and links to supporting documentation.

5 (2 reviews)5 (2 reviews)
140 Users140 Users
You’ll need Firefox to use this extension
Download Firefox and get the extension
Download file

Extension Metadata

Screenshots
The popup GUIA DKIM selector uses a weak RSA key that can be cracked and used to sign spoofed emails.A weak DNSKEY algorithm is used.The zone file was enumerated including potentially hidden DKIM and ARC selectors.
About this extension
Code
This addon is free and open-source software (FOSS) all code can be found here: https://github.com/ACK-J/MailFail
Please report your bugs or feature requests in a GitHub issue instead of in a review.

**Test if it works! **
https://m.ail.fail/

This addon checks misconfigurations with the following protocols:
* SPF
* DMARC
* DKIM
* ARC
* BIMI
* MX
* MTA-STS
* DANE
* DNSSEC
* SMTP TLS Reporting
* ADSP
* Mail Channels
* NSEC
* NSEC3
* SRV
* Click HERE to read the specifics.

Why I wrote this addon?
While researching email security for a few months I realized that there was a lot of nuance in how different email security protocols worked. It was very confusing at times and I wanted to organize all the different edge cases into a single tool that could help others identify these misconfigurations without having to read through dozens of RFCs. This extension was supposed to be 100 lines of code written in an afternoon, instead it has reached almost 2,000 lines of code over multiple months.

Donations
  • Monero Address: 89jYJvX3CaFNv1T6mhg69wK5dMQJSF3aG2AYRNU1ZSo6WbccGtJN7TNMAf39vrmKNR6zXUKxJVABggR4a8cZDGST11Q4yS8

Permissions Needed

Display notifications to you
* This is needed so the addon can alert you when a severe misconfiguration is discovered.
Access browser tabs
* This is needed so the addon can display the proper number of misconfigurations on a per-tab basis.

Privacy Warning
  • This extension does not use your computers default DNS and instead uses CloudFlare's 1.1.1.1 over DoH. It also uses duckduckgo's icon API to privately retrieve websites favicon images.
Rated 5 by 2 reviewers
Sign in to rate this extension
There are no ratings yet

Star rating saved

5
2
4
0
3
0
2
0
1
0
Read all 2 reviews
Permissions and dataLearn more

Required permissions:

  • Display notifications to you
  • Access browser tabs
More information
Add-on Links
  • Support site
Version
1.0.21
Size
527.89 KB
Last updated
5 months ago (Mar 4, 2025)
Related Categories
  • Web Development
  • Privacy & Security
License
GNU General Public License v3.0 only
Version History
  • See all versions
Add to collection
Report this add-on
Release notes for 1.0.21
  • updated t=y finding
More extensions by Hacks and Hops
  • There are no ratings yet

  • There are no ratings yet

  • There are no ratings yet

  • There are no ratings yet

  • There are no ratings yet

  • There are no ratings yet

Go to Mozilla’s homepage

Add-ons

  • About
  • Firefox Add-ons Blog
  • Extension Workshop
  • Developer Hub
  • Developer Policies
  • Community Blog
  • Forum
  • Report a bug
  • Review Guide

Browsers

  • Desktop
  • Mobile
  • Enterprise

Products

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • Privacy
  • Cookies
  • Legal

Except where otherwise noted, content on this site is licensed under the Creative Commons Attribution Share-Alike License v3.0 or any later version.