email-security-anti-phishing

Audit email authentication protocols and map phishing TTPs to compliance framework gaps.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill email-security-anti-phishing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: email-security-anti-phishing
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/email-security-anti-phishing
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill email-security-anti-phishing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Traditional email security tools and compliance frameworks (NIST 800-53, ISO 27001, SOC 2) are built for pre-2024 threat landscapes and fail to address mid-2026 AI-augmented phishing threats including voice-cloned vishing, deepfake video BEC, hyperpersonalized LLM-generated lures, and unenforced email authentication protocols that leave organizations exposed to billions in annual BEC losses.

Core Features & Use Cases

  • Comprehensive Email Authentication Audit: Assess SPF, DKIM, DMARC, BIMI, ARC, MTA-STS, and TLSRPT deployment and enforcement status across all owned sending domains, with a 90-day migration plan to DMARC p=reject.
  • Compliance Gap Analysis: Map modern phishing TTPs (T1566.*, T1078) to gaps in global regulatory frameworks including NIST, ISO, NIS2, UK CAF, AU Essential 8, and NYDFS to expose paper compliance versus real protection.
  • End-to-End Anti-Phishing Assessment: Run a 10-step procedure covering phishing-resistant MFA rollout, BEC playbook validation, deepfake-aware policy creation, vendor email risk monitoring, and continuous DMARC report monitoring.
  • Use Case: A mid-sized multinational enterprise uses this skill to identify that 40% of privileged users rely on phishable TOTP MFA, their primary sending domain is stuck at DMARC p=none, and their BEC playbook lacks out-of-band verification protocols, then generates a prioritized remediation queue aligned to real exploit risk rather than framework deadlines.

Quick Start

Use the email-security-anti-phishing skill to run a full email security and anti-phishing assessment for your organization and generate a prioritized remediation plan.

Frequently Asked Questions about email-security-anti-phishing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit DMARC enforcement and identify compliance gaps for NIST 800-53 or ISO 27001?

To audit DMARC enforcement and identify compliance gaps, this Skill maps modern phishing TTPs to NIST 800-53, ISO 27001, and SOC 2 frameworks, exposing paper compliance versus real protection against AI-augmented phishing and BEC threats.

What is phishing-resistant MFA rollout planning and how does it mitigate BEC risk?

Phishing-resistant MFA rollout planning identifies privileged users relying on phishable TOTP MFA and generates a prioritized remediation queue. This BEC risk mitigation planning replaces vulnerable authentication with stronger controls aligned to real exploit risk.

How do I create a deepfake-aware policy and validate my BEC playbook?

Creating a deepfake-aware policy and validating a BEC playbook involves running a 10-step anti-phishing assessment that covers out-of-band verification protocols and deepfake business email compromise threats generated by AI voice and video cloning.

Does this anti-phishing assessment support multi-region organizations needing NIS2 and NYDFS compliance?

Yes, this anti-phishing assessment supports multi-region organizations by mapping offensive TTPs to D3FEND defensive controls and highlighting compliance gaps across global regulatory frameworks including NIS2, UK CAF, AU Essential 8, and NYDFS.

What is the best way to migrate sending domains to DMARC p=reject enforcement?

The best way to migrate sending domains to DMARC p=reject enforcement is using the comprehensive email authentication audit, which assesses SPF, DKIM, BIMI, and MTA-STS deployment and outputs a 90-day migration plan.