Exposure discovery CSIRT-led

Mailgoose

Checks a domain's SPF and DMARC records and validates DKIM through a test email, with a self-hosted portal reusable by other CSIRTs.

By CERT Polska · Poland

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Exposure discovery
Developer or maintainer
CERT Polska
Recorded country
Poland
Product model
Open source
Deployment
Self-hosted / Public service
Software license
BSD-3-Clause
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

CERT Polska published the former Bezpieczna Poczta code as a white-label tool for other national CSIRTs; Lithuania NCSC runs an instance.

Reported capabilities

  • SPF, DMARC and DKIM checks
  • Domain and test-email methods
  • Reusable CSIRT deployment

Scope and limits

Email-domain protection assessment rather than incident handling. CERT Polska's Polish instance offers public domain and test-email checks; Lithuania NCSC also operates an instance. These are public institutional services, not a general commercial SaaS offering.

Inspect the research evidence 6 source observations
  1. identity / capabilities / deployment

    CERT Polska's live Bezpieczna Poczta public interface offers domain checks and test-email checks; its page explains that DKIM requires the test-email route.

    Read source
  2. identity / origin / country / capabilities

    CERT Polska says it developed Bezpieczna Poczta, published white-label Mailgoose for other national CSIRTs, identifies Lithuania NCSC use and describes domain and test-email checks.

    Read source
  3. identity / capabilities

    Upstream README calls Mailgoose a web application for SPF, DMARC and DKIM configuration checks and identifies its Polish institutional instance.

    Read source
  4. license

    Actual license contains the three BSD-style redistribution conditions and 2023 CERT Polska copyright.

    Read source
  5. deployment

    Upstream quick start documents Docker Compose self-hosting and separate production deployment requirements.

    Read source
  6. maintenance

    Upstream GitHub API reports nonarchived repository with code pushed 2026-10-08; an activity signal, not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.

From vulnerability finding to verified remediation