Exposure discovery CSIRT-led
Mailgoose
Checks a domain's SPF and DMARC records and validates DKIM through a test email, with a self-hosted portal reusable by other CSIRTs.
By CERT Polska · Poland
Primary sources connect this project to an EU CSIRT as developer or lead.
At a glance
Recorded facts- Response workflow
- Exposure discovery
- Developer or maintainer
- CERT Polska
- Recorded country
- Poland
- Product model
- Open source
- Deployment
- Self-hosted / Public service
- Software license
- BSD-3-Clause
- Upstream status
- Active
- Evidence class
- CSIRT-led
What the sources establish
Origin noteCERT Polska published the former Bezpieczna Poczta code as a white-label tool for other national CSIRTs; Lithuania NCSC runs an instance.
Reported capabilities
- SPF, DMARC and DKIM checks
- Domain and test-email methods
- Reusable CSIRT deployment
Scope and limits
Email-domain protection assessment rather than incident handling. CERT Polska's Polish instance offers public domain and test-email checks; Lithuania NCSC also operates an instance. These are public institutional services, not a general commercial SaaS offering.
Inspect the research evidence 6 source observations
identity / capabilities / deployment
CERT Polska's live Bezpieczna Poczta public interface offers domain checks and test-email checks; its page explains that DKIM requires the test-email route.
Read sourceidentity / origin / country / capabilities
CERT Polska says it developed Bezpieczna Poczta, published white-label Mailgoose for other national CSIRTs, identifies Lithuania NCSC use and describes domain and test-email checks.
Read sourceidentity / capabilities
Upstream README calls Mailgoose a web application for SPF, DMARC and DKIM configuration checks and identifies its Polish institutional instance.
Read sourcelicense
Actual license contains the three BSD-style redistribution conditions and 2023 CERT Polska copyright.
Read sourcedeployment
Upstream quick start documents Docker Compose self-hosting and separate production deployment requirements.
Read sourcemaintenance
Upstream GitHub API reports nonarchived repository with code pushed 2026-10-08; an activity signal, not a support guarantee.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.
From vulnerability finding to verified remediation