MX Inspector
lupaxa-mx-inspector looks up a domain's MX hosts, SPF, and published
DMARC TXT record, then decodes the policy into a table or JSON and
scores spoofing posture. An optional --probe greets each MX over SMTP
to fingerprint mail software.
Authorised use only
--probe opens an SMTP session to the target MX hosts. Use it only on
systems you are allowed to test.
Install the package for the library API and the mx-inspector console
command:
You can also run python -m lupaxa.mx_inspector.
What it does
- Queries
MXrecords for the domain (priority and host) - Queries apex
TXTfor SPF (v=spf1) - Queries
_dmarc.<domain>for a TXT record - Scores spoofing posture (
open/monitoring/enforcing/locked down) - Lists MX, then SPF, then every known DMARC tag; posture is a table footer
- Unpublished tags stay in the table as
missing(JSON usesnull) - Colours the table on a TTY (
--no-colororNO_COLORto disable) - Optionally greets each MX (
--probe: banner + EHLO only) --port(default 25) and--timeout(default 5 seconds) control the probe- Prints a human-readable table, or JSON with
--format json - Exposes the same lookups, score, and probe helpers as library functions
Next steps
- Getting started — install and first run
- Usage — CLI flags, probe options, and the library API
- Reference — tags, JSON fields, errors, and exit codes
- Examples — table, JSON, probe, and library recipes