Security in Obscurity

An article by Jeff Stein

Effectively Using Email Authentication Standards for Stronger Message Integrity

Cyber Defense Magazine, October 2019

This article was originally published in Cyber Defense Magazine. A copy of the publication can be found here and the individual article can be found here.

---

Abstract

The regularity at which domains are spoofed by malicious senders illustrates the issue and the need for message integrity in email. Where the original SMTP standard is lacking from a security design standpoint, standards are now available to compliment SMTP that provides a more secure messaging experience. Communication can be sent over TLS to provide for encryption and therefore, confidentially of email during transmission.

From a message integrity standpoint, a combination of three email authentication standards, SPF, DKIM, and DMARC provides for a secure implementation of email. The important takeaway from these authentication standards is that while SPF and DKIM can be used independently without DMARC, the overall framework provided by DMARC will yield a more holistic message integrity posture, combining the benefits of all three standards. Leveraging a DMARC strategy will put your business ahead of the curve when it comes to message integrity.


Tags

Security Vulnerabilities IDS/IPS Malware Ethical Hacking Email PowerShell Python Splunk Cloud Script PKI Firewall Router Vulnerability Management