⚠
DMARC Attack Simulator
Configured Policy Preview
v=DMARC1; p=none; pct=100; aspf=r; adkim=r
Monitoring only — all emails delivered, no action taken
Attack Type
Spoofed Sender — From domain mismatch
Display Name Spoof + Reply-To Hijack
Unsigned Email — No DKIM signature
Legitimate Email — For comparison
Expected outcome
SPF/DKIM alignment fails — DMARC enforcement depends on current policy
Attack Origin
— Anonymous (no location) —
Moscow, Russia
Beijing, China
Pyongyang, North Korea
Lagos, Nigeria
Bucharest, Romania
Tehran, Iran
Minsk, Belarus
São Paulo, Brazil
From Name
From Email
To Email
Subject
Body
Dear Customer, We have detected unusual activity on your PayPal account. Your account has been temporarily limited. Please verify your information immediately to restore full access. PayPal Security Team
Policy Lab
Configure how a receiving mail server would evaluate this email
DMARC Policy (p=)
none — monitor only
quarantine — send to spam
reject — block completely
Enforcement Percentage (pct=)
100
Percentage of failing emails the policy applies to
SPF Alignment (aspf=)
r — Relaxed
s — Strict
Relaxed allows org domain match. Strict requires exact match.
DKIM Alignment (adkim=)
r — Relaxed
s — Strict
▶ LAUNCH ATTACK
// Attack Log — dmarcpoc.xyz
Clear log
[ ]
No attacks launched yet.
Configure your payload and hit LAUNCH ATTACK.
Results appear here in real time.
Transmitting payload...
Policy stage:
p=none
p=quarantine
p=reject