← All cheat sheets

SMTP-USER-ENUM

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

smtp-user-enum is a tool for enumerating valid email addresses and
usernames on SMTP servers. It uses VRFY, EXPN, and RCPT TO commands
to check if users exist on the mail server.

BASIC USAGE#

smtp-user-enum -M <method> -U <userlist> -t <target>
                                 # Enumerate users

METHODS#

smtp-user-enum -M VRFY -U users.txt -t <target>
                                 # VRFY method (verify user)
smtp-user-enum -M EXPN -U users.txt -t <target>
                                 # EXPN method (expand mailing list)
smtp-user-enum -M RCPT -U users.txt -t <target>
                                 # RCPT TO method (recipient check)

OPTIONS#

smtp-user-enum -M <method>       # Enumeration method
smtp-user-enum -U <file>         # Username wordlist file
smtp-user-enum -u <user>         # Single username to check
smtp-user-enum -t <target>       # Target SMTP server
smtp-user-enum -T <file>         # Target list file
smtp-user-enum -p <port>         # SMTP port (default: 25)
smtp-user-enum -D <domain>       # Domain for RCPT TO method
smtp-user-enum -f <from>         # MAIL FROM address for RCPT
smtp-user-enum -w <timeout>      # Timeout per connection

EXAMPLES#

# VRFY method against single server
smtp-user-enum -M VRFY -U /usr/share/wordlists/users.txt -t 192.168.1.1

# RCPT TO method with domain
smtp-user-enum -M RCPT -U users.txt -D example.com -t 192.168.1.1

# Check single user
smtp-user-enum -M VRFY -u admin -t 192.168.1.1

# Multiple targets
smtp-user-enum -M VRFY -U users.txt -T smtp_servers.txt

# Custom port and timeout
smtp-user-enum -M VRFY -U users.txt -t 192.168.1.1 -p 587 -w 10

# RCPT TO with custom sender
smtp-user-enum -M RCPT -U users.txt -D example.com -f test@attacker.com -t 192.168.1.1

SMTP COMMANDS EXPLAINED#

# VRFY <user>
# - Asks server to verify if user exists
# - Server responds with 250 (exists) or 550 (not found)

# EXPN <list>
# - Asks server to expand a mailing list
# - Returns members of the list
# - Often disabled on modern servers

# RCPT TO:<user@domain>
# - Simulates sending mail to a user
# - Server responds with 250 (accepted) or 550 (rejected)
# - Most reliable method on modern servers

RESPONSE CODES#

# 250 = User exists (valid)
# 251 = User not local, will forward
# 252 = Cannot verify, will attempt delivery
# 550 = User not found (invalid)
# 551 = User not local
# 553 = Invalid mailbox name

WORDLISTS#

/usr/share/wordlists/metasploit/unix_users.txt
/usr/share/seclists/Usernames/Names/names.txt
/usr/share/seclists/Usernames/top-usernames-shortlist.txt
/usr/share/wordlists/smtp-users.txt

NOTES#

- VRFY and EXPN are often disabled on modern servers
- RCPT TO is usually the most reliable method
- May trigger security alerts on target systems
- Some servers accept all RCPT TO (catch-all) - false positives
- Perl-based tool
- Useful for building target email lists
- Combine results with phishing campaigns
- Port 587 (submission) may also respond to enumeration