Dateline: April 1, 2015; Berkeley, California – Today major mailbox providers and email senders expressed their frustration that nobody is phishing their customers and domains. The universal adoption of email authentication technologies such as SPF, DKIM, and DMARC, and the sudden elimination of spam, has caused criminals to abandon this once-popular activity. “I guess I […]
Bad Actors: Please Adopt Email Authentication
A recent Trend Micro blog post suggests that the bad actors behind a current ransomware campaign are using email authentication and DMARC to make their messages more effective. One online article citing the post even includes a headline that incorrectly suggests that DMARC somehow enables the malware to bypass filters – which it assuredly does […]
Kaspersky: Phishing attacks on PayPal down due to DMARC
On February 12th Kaspersky Labs published a report titled “Financial cyberthreats in 2014.” This report takes a broad view of malware and email-based attacks on financial institutions and/or their customers. It notes some broad trends, like an almost 6% decrease in phishing attacks against banks, and that the number of malware attacks involving Bitcoin mining […]
Who Is Sending Email As Your Company?
You might expect that the IT department or security team knows who’s sending email using your company’s domains. But for a variety of reasons these groups are often unaware of many legitimate senders — not to mention all the bad actors. Fortunately you can get a more complete view by using DMARC‘s reporting features.
Email Vendors: Time to Build in DMARC
DMARC is extremely useful, yet I’ve heard some vendors are putting their implementations on hold because of the IETF DMARC working group. You really shouldn’t wait though — it’s been in wide use for nearly three years, enterprises are looking at DMARC for B2B traffic, and the working group charter is limited in it’s scope […]