AVAILABLE NOW · v1.0.0

Email Pentest
Sidekick

The most complete email security assessment framework in existence. DMARC-pass attack automation, dark web credential hunting, SPF chain analysis, password spray — one static Debian/Kali binary, zero dependencies.

Rust · static binary Debian / Kali · x86-64 GUI + CLI v1.0.0
12
MODULES
1M+
BUNDLED PASSWORDS
0
DEPENDENCIES
7
DAY FREE TRIAL

What It Does

Built by practitioners. Tested in the field. Everything an email security assessment needs — and nothing that belongs in a SaaS dashboard.

🎯

DMARC-pass delivery — the real attack

Route your email through a provider the target has already authorised — Microsoft 365, Google Workspace, their own ESP. EPS automates the chain: find the stolen credential, test it, relay through it. DKIM signed by Microsoft. SPF passes. DMARC passes. No other tool does this end-to-end.

🔍

Intelligence before the attack

Most tools start at "send email." EPS starts three steps earlier — mapping the full SPF tree, identifying every authorised ESP, hunting for stolen credentials on the dark web and testing them live. By the time you send, you already know whether it'll land.

💥

SMTP password spray with 1M+ wordlists

Ignis-sec wordlist library bundled — 1,048,576 passwords, curated from real-world leaks. Multi-target mode, STARTTLS, configurable delay, stop-on-hit, live credential vault. Hits feed directly into the DMARC-pass relay engine.

🌑

Dark web & HIBP credential hunting

Tor-routed search across dark web paste sites and leak indexes. HIBP stealer log enrichment. Results are automatically tested live against the target mail server — finding credentials is just step one.

🌐

SPF chain walking & permutations

Recursively resolve the full SPF authorisation tree. Every include, redirect, and nested mechanism exposed. Domain permutation generator with live DNS validation surfaces all squatting opportunities.

📄

Professional HTML/PDF report

Risk-scored, colour-coded, client-ready. DMARC posture, credential hits, relay exposure, dark web leaks, header forensics — all in one deliverable. From recon to report in one session, not one week of stitching together five different tools.

// full capability list
$(echo 'DMARC-pass spoofing via stolen M365/Gmail credentials|SMTP AUTH spray with bundled Ignis 1M wordlist|SPF chain walking — full recursive tree|Tor-routed dark web credential search|HIBP stealer log enrichment|Open relay discovery (CIDR scan)|Domain permutation generator + DNS check|DKIM signing with custom private key|Email header forensic analyser|Built-in SMTP capture server|Campaign mode with relay rotation|Professional HTML/PDF pentest report|FOFA/ZoomEye/Censys/Shodan OSINT|Single static binary · no Python · no Docker|GUI (egui) + headless CLI|Debian/Kali native · x86-64' | tr '|' '\n' | while read f; do echo "
$f
"; done)

Two Modes. One Binary.

Desktop GUI for interactive assessments. Headless CLI for scripted pipelines and jump boxes. Both ship in the same static binary.

eps-gui — Email Pentest Sidekick
EPS GUI

Assessment Report — One-click professional HTML/PDF report covering DMARC posture, credential spray hits, relay exposure, dark web leaks, and delivery results.

EPS vs the Market

€199/year. Everything the $15,000 tools don't do.

Capability EPS
€199/yr
GoPhish Pro
~$1,500/yr
swaks
Free
Cobalt Strike
$3,500/yr
KnowBe4
Enterprise
Metasploit Pro
$15,000/yr
DMARC-pass via stolen creds
Dark web credential hunting (Tor)
HIBP stealer log enrichment
SPF chain walking~
SMTP spray (1M+ bundled wordlists)~~
Open relay discovery~~
Domain permutations + DNS check
DKIM signing (own key)~
Email header forensic analyser
Professional HTML/PDF report~
Campaign + phishing mode~
Debian/Kali native · single binary

✓ Full  ·  ~ Partial  ·  ✗ Not available  ·  Pricing from public sources, 2026

Pricing

Online validation on every launch. Machine-fingerprint locked. No seat sharing.

DEMO
FREE
7 days · all modules
  • All modules unlocked
  • 1 machine
  • No commercial use
  • Expires after 7 days
Get Demo Key
TEAM
€499
per year
  • All modules unlocked
  • 3 machines
  • Commercial use
  • Priority support
Purchase →
LIFETIME
€799
one-time
  • All modules unlocked
  • 1 machine
  • Commercial use
  • Lifetime updates
Purchase →

Prices in EUR excluding VAT. Invoice available via portal. Authorised security testing only.

7-Day Full-Access Demo

No credit card. Instant key. You sign — you own the liability.