SMTP-USER-ENUM
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
smtp-user-enum is a tool for enumerating valid email addresses and usernames on SMTP servers. It uses VRFY, EXPN, and RCPT TO commands to check if users exist on the mail server.
BASIC USAGE#
smtp-user-enum -M <method> -U <userlist> -t <target>
# Enumerate users
METHODS#
smtp-user-enum -M VRFY -U users.txt -t <target>
# VRFY method (verify user)
smtp-user-enum -M EXPN -U users.txt -t <target>
# EXPN method (expand mailing list)
smtp-user-enum -M RCPT -U users.txt -t <target>
# RCPT TO method (recipient check)
OPTIONS#
smtp-user-enum -M <method> # Enumeration method smtp-user-enum -U <file> # Username wordlist file smtp-user-enum -u <user> # Single username to check smtp-user-enum -t <target> # Target SMTP server smtp-user-enum -T <file> # Target list file smtp-user-enum -p <port> # SMTP port (default: 25) smtp-user-enum -D <domain> # Domain for RCPT TO method smtp-user-enum -f <from> # MAIL FROM address for RCPT smtp-user-enum -w <timeout> # Timeout per connection
EXAMPLES#
# VRFY method against single server smtp-user-enum -M VRFY -U /usr/share/wordlists/users.txt -t 192.168.1.1 # RCPT TO method with domain smtp-user-enum -M RCPT -U users.txt -D example.com -t 192.168.1.1 # Check single user smtp-user-enum -M VRFY -u admin -t 192.168.1.1 # Multiple targets smtp-user-enum -M VRFY -U users.txt -T smtp_servers.txt # Custom port and timeout smtp-user-enum -M VRFY -U users.txt -t 192.168.1.1 -p 587 -w 10 # RCPT TO with custom sender smtp-user-enum -M RCPT -U users.txt -D example.com -f test@attacker.com -t 192.168.1.1
SMTP COMMANDS EXPLAINED#
# VRFY <user> # - Asks server to verify if user exists # - Server responds with 250 (exists) or 550 (not found) # EXPN <list> # - Asks server to expand a mailing list # - Returns members of the list # - Often disabled on modern servers # RCPT TO:<user@domain> # - Simulates sending mail to a user # - Server responds with 250 (accepted) or 550 (rejected) # - Most reliable method on modern servers
RESPONSE CODES#
# 250 = User exists (valid) # 251 = User not local, will forward # 252 = Cannot verify, will attempt delivery # 550 = User not found (invalid) # 551 = User not local # 553 = Invalid mailbox name
WORDLISTS#
/usr/share/wordlists/metasploit/unix_users.txt /usr/share/seclists/Usernames/Names/names.txt /usr/share/seclists/Usernames/top-usernames-shortlist.txt /usr/share/wordlists/smtp-users.txt
NOTES#
- VRFY and EXPN are often disabled on modern servers - RCPT TO is usually the most reliable method - May trigger security alerts on target systems - Some servers accept all RCPT TO (catch-all) - false positives - Perl-based tool - Useful for building target email lists - Combine results with phishing campaigns - Port 587 (submission) may also respond to enumeration