JJ Prats :unverified: · @jprxts
159 followers · 302 posts · Server infosec.exchange

Quick reminder to make sure your org email gateway is correctly configured. I've come across countless email gateways that are misconfigured, turning them essentially useless.

If your org is using any sort of secure email gateway for email filtering, it is very common for organizations to apply domain-based safelisting for inbound mail (ie when dealing with partners or external child organizations), and whilst domain-based safelisting is already not recommended at all, very often I see orgs safelisting emails "containing" domain.com.

This is a terrible practice since anybody could register dddomain.com, 1domain.com, idomain.com, etc, bypass your very expensive email gateway in just a second and email your entire user base without any email filtering.

If you must safelist an entire domain, make sure you are safelisting something like "Sender Address ends in @domain.com or .domain.com", (if safelisting subdomains), as well as having additional anti-spoofing and domain reputation rules in place to detect any potentially forged emails.

#bec #email #emailgateways

Last updated 2 years ago

Tarnkappe.info · @tarnkappeinfo
1530 followers · 3787 posts · Server social.tchncs.de
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online