All work

DNS Intelligence

An SPF record that needs more than 10 DNS lookups fails, and nested includes hide the real count. So I built a scanner that counts the way mail servers do, then a watch that tells you before it breaks.

Role
Built and run it, end to end
Stack
Node.js, Express, SQLite, Docker on Coolify
Status
Live, free plus Pro and Team plans

The problem

Email authentication fails quietly. An SPF record can include another, which includes another; past 10 DNS lookups the whole record fails for every receiver, and most checks only count the top level. A certificate expires on a Saturday. DMARC sits at p=none for years.

What it does

How it is built

  1. Browser or APIrate limited, CORS allowlist
  2. Expressone process
  3. ProbesDNS, TLS, HTTP via an SSRF guard
  4. SQLitewatches, users, hashed tokens
  5. Schedulerdaily checks and email alerts

Hardening it

  1. 62 to 0

    One triage pass took open code-scanning alerts from 62 to 0, every dismissal written down.

  2. SSRF

    Every outbound hop checked against private, loopback and link-local ranges, including IPv4-mapped IPv6 in every written form.

  3. Secrets

    Session and API tokens stored only as hashes, with a migration for existing rows. Sign-in links built only from the configured URL, never from request headers.

  4. Release bar

    Signed commits, required checks, CodeQL and Scorecard on every change; Dependabot with a 7-day cooldown and every Action pinned to a commit.

Got a production problem worth solving?