{"id":11896,"date":"2022-09-14T14:31:54","date_gmt":"2022-09-14T14:31:54","guid":{"rendered":"https:\/\/thebusinessculture.co.uk\/hey\/?post_type=know-how&#038;p=11896"},"modified":"2022-09-20T16:27:30","modified_gmt":"2022-09-20T16:27:30","slug":"your-email-may-not-be-as-secure-as-you-think","status":"publish","type":"know-how","link":"https:\/\/thebusinessculture.co.uk\/hey\/know-how\/your-email-may-not-be-as-secure-as-you-think\/","title":{"rendered":"Your email may not be as secure as you think"},"content":{"rendered":"<p>A couple of weeks ago we checked the DNS records of every member who has their email address listed on the Business Culture site. We wanted to see how well protected the businesses are locally and the level of security knowledge in the area. Due to DNS being public records we can check legally we decided to see how well protected your email domain really is. The reasoning being, if this isn\u2019t set up correctly, what else isn\u2019t?<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-11897\" src=\"https:\/\/thebusinessculture.co.uk\/hey\/wp-content\/uploads\/2022\/09\/email-security-320x190.png\" alt=\"\" width=\"320\" height=\"190\"><\/p>\n<p>We\u2019ll keep this as simple as possible.<\/p>\n<p>&nbsp;<\/p>\n<p>What is the threat\/danger of not having this implemented \u2013 the danger is domain email spoofing. We\u2019ve all heard of spoofing but what actually is it?<\/p>\n<p>&nbsp;<\/p>\n<p>In its simplest term, it\u2019s the impersonation of you or your business from a third party bad actor\/hacker. Email is a great universal tool but it\u2019s based on very old standards that haven\u2019t changed in decades. Anybody can send an email purporting to be from you. It\u2019s extremely easy to compose that email as if it has come from anyone. There\u2019s nothing that can be done from someone sending that email unfortunately. We do, however, have systems in place to prevent the email being delivered. Unfortunately without those mechanisms in place those emails tend to get through.<\/p>\n<p>&nbsp;<\/p>\n<p>We\u2019re going to get a bit acronymy here but don\u2019t worry what they stand for. There are three technologies that are needed to prevent your domain being spoofed.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>SPF<\/strong> \u2013 A list of locations that are authorised to send emails from you. Usually this is all set up for you when you first create your shiny new email account and if you don\u2019t move from one hosting company to another, it usually is ok. There are <strong>14 businesses<\/strong> on here that don\u2019t have an SPF record. Looking at a trend, they seem to be design and creative businesses. This makes sense as they\u2019ve probably moved hosting platforms at least once as that\u2019s common in that industry.<\/p>\n<p>If you have no SPF record, you often find yourself going straight into other people\u2019s spam\/junk folder or just not getting through. That\u2019s because the recipient email server doesn\u2019t like this so marks it as potentially unsafe. Even if you\u2019ve sent emails to that recipient for years, you can find yourself hitting their spam filter if your SPF record is missing or it\u2019s incorrect.<\/p>\n<p>&nbsp;<\/p>\n<p>Before we move on to the other two technologies, as mentioned, around <strong>10% of businesses<\/strong> on here have no SPF record at all. We can\u2019t determine without receiving an email from you if the ones that do have a record are even correct so there are at least 10% of businesses on here alone with an issue in this area.<\/p>\n<p>To keep you in further suspense and surprise you even more, out of every business on here, <strong>only 3<\/strong> of you have a fully correct configuration, that\u2019s all three technologies seemingly configured correctly. There are another 13 businesses that have made the effort to implement everything but haven\u2019t done it quite right.<\/p>\n<p>So, the below two technologies are only correctly implemented in around <strong>4% of businesses<\/strong> in this community.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>DKIM<\/strong> \u2013 This adds crypto security to your email. It authenticates that email is coming from who it says it\u2019s coming from. It also prevents any tampering of your email from a threat actor intercepting it in transit. MS365 and Google Workspace do use this to sign your email against their servers but that isn\u2019t enough to protect your domain yourself.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>DMARC<\/strong> \u2013 This, in the simplest explanation, is the technology that ties together the previous two. This is the one that one 4% of you have set up correctly. Unfortunately 13 of you have this enabled but have set the parameter to none rather than reject or quarantine which makes it completely ineffective (unless you\u2019re in initial implementation for the first two weeks or so).<\/p>\n<p>When an email server receives an email from anyone, it checks if SPF and DKIM are configured. If neither are, it doesn\u2019t like it but may still send it on as spam. What the server will check for also, is DMARC. This is the mechanism that tells the receiving end what to do with the email if SPF and DKIM fail. If configured correctly it will either drop the email completely or quarantine it. What it also does is report on that for you but that\u2019s a bit beyond what this post is for.<\/p>\n<p>&nbsp;<\/p>\n<p>So you\u2019ve got this far and you\u2019re maybe thinking this is so bleak because you\u2019re all smaller businesses and bigger business have this covered as standard. You\u2019d be wrong. We checked some of Hull\u2019s biggest businesses and found a similar trend.<\/p>\n<p>&nbsp;<\/p>\n<p>There\u2019s no reason to not have these mechanisms in place. They\u2019re just DNS records and don\u2019t cost any money to implement if you were to do them yourselves or shouldn\u2019t be an expensive proposition to go to your MSP or even come to us.<\/p>\n<p>&nbsp;<\/p>\n<p>We will be running through all this in the training we\u2019re offering to members where we can demonstrate this rather than just bombard you with a wall of text.<\/p>\n<p>&nbsp;<\/p>\n<p>Please, ask your managed IT service provider to investigate this for you. If you don\u2019t have one, you can email <a href=\"mailto:support@heysec.co.uk\">support@heysec.co.uk<\/a> and we can assist at a special BCH rate.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A couple of weeks ago we checked the DNS records of every member who has their email address listed on the Business Culture site. We wanted to see how well protected the businesses","protected":false},"author":12313218,"featured_media":11958,"template":"","know_how_category":[],"class_list":["post-11896","know-how","type-know-how","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/know-how\/11896","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/know-how"}],"about":[{"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/types\/know-how"}],"author":[{"embeddable":true,"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/users\/12313218"}],"version-history":[{"count":6,"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/know-how\/11896\/revisions"}],"predecessor-version":[{"id":11959,"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/know-how\/11896\/revisions\/11959"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/media\/11958"}],"wp:attachment":[{"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/media?parent=11896"}],"wp:term":[{"taxonomy":"know_how_category","embeddable":true,"href":"https:\/\/thebusinessculture.co.uk\/hey\/wp-json\/wp\/v2\/know_how_category?post=11896"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}