Email Security Protocols for SOC Teams
Very important stuff. But how do you manage the thousands of reports it generates annually? 😭 Suggestions are welcome.
Thank you LetsDefend 🙂
This is sharing the wrong msg. DKIM and SPF don’t protect against attacks using similar domain names. DMARC checks the envelope sender is the same as the From in Header. DMARC has superior weighting to both the others as the other two must’ve passed beforehand.
If you’re B2B, maybe add a little enforced TLS email encryption and push your suppliers and clients (contractually) to support appropriate versions of TLS.
I actually did a little project on this. Using them to help get a spoofed email through to the inbox.
Sid Ahmed Bennanni thanks to you, I've learnt all this stuff
Chief Security Officer / Chief Information Security Officer / Chief Privacy Officer
4dIf you don't have all three covering your Internet Email and DNS services, you should get this done.