Secure Email Server with Pen Tester
Budget: ₹5,000 – ₹12,000 INR
Email Server Penetration Tester
Position Overview
We are looking for a skilled Penetration Tester with specialized expertise in email server security to conduct thorough assessments of our email infrastructure. The ideal candidate will identify vulnerabilities in SMTP, IMAP, POP3 servers, and associated email security mechanisms.
Key Responsibilities
• Conduct comprehensive penetration testing on email servers (SMTP, IMAP, POP3, Exchange, Postfix, Sendmail)
• Test email authentication mechanisms including SPF, DKIM, DMARC, and DANE implementations
• Identify and exploit vulnerabilities such as open relays, SMTP injection, user enumeration attacks
• Assess email encryption implementations (TLS/SSL, S/MIME, PGP)
• Perform phishing simulation and social engineering tests targeting email users
• Test email gateway security solutions and anti-spam/anti-malware filters
• Evaluate email server configurations for misconfigurations and weak authentication
• Conduct banner grabbing and information disclosure assessments
• Test for email spoofing, header injection, and mail relay vulnerabilities
• Document all findings with actionable remediation recommendations
Required Skills & Qualifications
Core Technical Skills:
• 4+ years of penetration testing experience with strong focus on email infrastructure
• Expert knowledge of SMTP, IMAP, POP3 protocols and their security implications
• Deep understanding of email authentication standards (SPF, DKIM, DMARC, ARC)
• Proficiency with email security testing tools (smtp-user-enum, nmap SMTP scripts, Swaks, telnet)
• Understanding of email-based attack vectors: phishing, spoofing, BEC, malware delivery
Email Security Expertise:
• Knowledge of email filtering bypass techniques
• Understanding of DNS security as it relates to email (MX records, DNSSEC, DANE)
• Familiarity with email compliance requirements (GDPR, HIPAA, SOC 2)
Project Details
• Duration: 2 days
• Commitment: Full-time / Part-time / Contract
• Location: Remote
Deliverables
• Detailed penetration test report with executive summary
• Comprehensive vulnerability findings with risk classifications
• Email security posture assessment
• Proof-of-concept demonstrations for vulnerabilities
• Prioritized remediation plan with technical guidance
• Security best practices documentation for email infrastructure
Position Overview
We are looking for a skilled Penetration Tester with specialized expertise in email server security to conduct thorough assessments of our email infrastructure. The ideal candidate will identify vulnerabilities in SMTP, IMAP, POP3 servers, and associated email security mechanisms.
Key Responsibilities
• Conduct comprehensive penetration testing on email servers (SMTP, IMAP, POP3, Exchange, Postfix, Sendmail)
• Test email authentication mechanisms including SPF, DKIM, DMARC, and DANE implementations
• Identify and exploit vulnerabilities such as open relays, SMTP injection, user enumeration attacks
• Assess email encryption implementations (TLS/SSL, S/MIME, PGP)
• Perform phishing simulation and social engineering tests targeting email users
• Test email gateway security solutions and anti-spam/anti-malware filters
• Evaluate email server configurations for misconfigurations and weak authentication
• Conduct banner grabbing and information disclosure assessments
• Test for email spoofing, header injection, and mail relay vulnerabilities
• Document all findings with actionable remediation recommendations
Required Skills & Qualifications
Core Technical Skills:
• 4+ years of penetration testing experience with strong focus on email infrastructure
• Expert knowledge of SMTP, IMAP, POP3 protocols and their security implications
• Deep understanding of email authentication standards (SPF, DKIM, DMARC, ARC)
• Proficiency with email security testing tools (smtp-user-enum, nmap SMTP scripts, Swaks, telnet)
• Understanding of email-based attack vectors: phishing, spoofing, BEC, malware delivery
Email Security Expertise:
• Knowledge of email filtering bypass techniques
• Understanding of DNS security as it relates to email (MX records, DNSSEC, DANE)
• Familiarity with email compliance requirements (GDPR, HIPAA, SOC 2)
Project Details
• Duration: 2 days
• Commitment: Full-time / Part-time / Contract
• Location: Remote
Deliverables
• Detailed penetration test report with executive summary
• Comprehensive vulnerability findings with risk classifications
• Email security posture assessment
• Proof-of-concept demonstrations for vulnerabilities
• Prioritized remediation plan with technical guidance
• Security best practices documentation for email infrastructure