@lacspace/mail-auth
Email authentication-result parsing and phishing/impersonation heuristics for webmail warning banners. RFC 8601 Authentication-Results parser (SPF, DKIM, DMARC, ARC, Received-SPF fallback, trusted authserv-id selection so forged lower headers are ignored) plus assessRisk(): DMARC/SPF/DKIM failures, reply-to mismatch, display-name address tricks, known-contact impersonation, lookalike domains (edit distance, homoglyph skeletons, punycode, mixed scripts, subdomain/hyphen/TLD tricks), free-mail brand claims, payment-change and credential-lure wording in English and Nepali, deceptive links. Plain-English reasons, 0-100 score, none/low/high level. Zero dependencies, isomorphic.
npm i @lacspace/mail-authUsage
import { parseAuthenticationResults, assessRisk } from "@lacspace/mail-auth";
const auth = parseAuthenticationResults(
{ authenticationResults: headers.getAll("Authentication-Results"), receivedSpf: headers.getAll("Received-SPF") },
{ trustedAuthservIds: ["mx1.yourmail.com"] }, // only YOUR server's header
);
// { spf: "pass", dkim: "pass", dmarc: "fail", dmarcPolicy: "reject", headerFrom: "lacsp4ce.com", authservId: "mx1.yourmail.com", … }
const risk = assessRisk({
from: { name: "Lacspace Billing", address: "billing@lacsp4ce.com" },
replyTo: [{ address: "lacspace.billing@gmail.com" }],
subject: "[EXTERNAL] Updated bank details",
snippet: "Our bank details have changed, please pay the attached invoice urgently.",
auth,
recipientDomain: "lacspace.com",
knownContacts: addressBook, // [{ name, address }]
links, // [{ href, text }] from your HTML sanitizer
});
// { level: "high", score: 100, reasons: [
// "The sender's address (billing@lacsp4ce.com) looks like lacspace.com but is a different domain.",
// "It failed lacsp4ce.com's anti-forgery check (DMARC), so it may not really be from them.",
// "It urgently asks for a payment or new bank details. Confirm with the sender by phone before paying.",
// … ], signals: [{ code: "lookalike.from", weight: 50, detail: "lacspace.com" }, …] }Exports 14
FREE_MAIL_DOMAINSRISK_THRESHOLDSSIGNAL_WEIGHTSassessRiskdecodePunycodeeditDistancehasMixedScriptisFreeMailisWholeScriptConfusablelookalikeOfparseAuthenticationResultsregistrableDomainskeletontoUnicodeDomainKeywords
More in Mail Kit
Compose bulletproof, responsive, dark-mode HTML emails from simple blocks, plus 13 ready-made transactional templates (OTP, verify, password-reset, magic-link, receipt, order, shipping, invitation, digest, announcement). Ships plaintext generation, preheaders and {{var}} i18n interpolation. Zero-dependency, isomorphic.
@lacspace/email-validateSmart, network-free email validation — RFC-5322 syntax (incl. quoted local parts & IP-literal domains), disposable/temp-mail & role-account detection, free-provider flags, Gmail normalization and 'did you mean?' typo suggestions. Zero-dependency, isomorphic.
@lacspace/email-verifyBest-effort email deliverability for Node — syntax + disposable/role, MX lookup with priority ranking, an optional SMTP RCPT probe (no mail sent), catch-all detection, a 0-100 confidence score, and de-duped batch verification. All DNS/SMTP injectable; zero npm dependencies.
@lacspace/mailerA tiny zero-dependency SMTP client for Node — send email over raw net/tls with STARTTLS & AUTH, plus a fluent MIME builder (inline images, attachments, alternatives), RFC 5322 address + RFC 2047 helpers, batch send with retry, and no-network test transports. Provider presets (Hostinger, Gmail, Outlook, Zoho…) make setup one line.
@lacspace/imapZero-dependency IMAP4rev1 client for Node (RFC 3501 + IDLE, MOVE, UIDPLUS, CONDSTORE, SPECIAL-USE, LIST-EXTENDED, LITERAL+, SASL-IR, QUOTA, ID). Implicit TLS and STARTTLS with verification on, LOGIN / PLAIN / XOAUTH2 / OAUTHBEARER, streaming byte-accurate parser, async-iterable FETCH, envelopes with RFC 2047 decoding, BODYSTRUCTURE trees shared with @lacspace/mime, modified UTF-7 mailbox names, special-use detection (incl. Gmail XLIST and localised names), IDLE with NOOP fallback. Works with Hostinger (Dovecot), Gmail, Outlook/Exchange, GoDaddy.
@lacspace/mimeIsomorphic RFC 5322 / RFC 2045-2049 MIME parser and builder for webmail. parseMime() turns raw mail (string or bytes) into from/to/cc/subject/date/text/html/attachments/inline cid images/priority/List-Unsubscribe one-click and the part tree; handles nested multipart (mixed, alternative, related, report, signed), message/rfc822 forwards, base64 and quoted-printable (tolerant), RFC 2047 encoded words (split multibyte, adjacent whitespace), RFC 2231 parameters, 30+ charsets and malformed input without ever throwing. parseBodyStructure() parses IMAP BODYSTRUCTURE (literals, extension data) into the same tree with IMAP partIds, plus findTextParts / listAttachments / decodePart for lazy fetching. buildMime() writes CRLF messages with encoded-word headers, QP/base64 bodies, mixed/alternative/related nesting, Message-ID generation and header-injection guards; replyHeaders() / forwardSubject() for threading. Pairs with @lacspace/imap and @lacspace/mailer. Zero dependencies; Node 18+, edge runtimes and browsers.