Jump to content

Recommended Posts

Posted

Seemingly with increasing frequency, emails we send to parents are ending up in their junk folders. Is there anything we can do about this?

 

For the sake of this question, let's assume the staff aren't using lots of trigger words like "viagra" in their emails!

Posted (edited)

Who is your mail sent through and how?

SPF and DomainKey setup fully?

Volume of email sent per day can be a factor but I would be surprised if it was affecting you. If you send from your own in-house smtp/server then it can be factor with ip reputation but through a third party it can be avoided to a point.

Edited by ZeroHour
Posted
Get DKIM, SPF and DMARC set up.

 

Those are all acronyms I've never heard before. Is there a dummy's guide or should I just bounce up to our uber-techie support company?

Posted

There are plenty of how-to guides out there, but if you haven't heard those particular terms before I would pass it up to the support company.

 

Also bear in mind that if you have other services which email on behalf of you (Examples: SurveyMonkey, helpdesk, third party mail filter), they will configuring for it as well.

Posted

To setup these technologies you'd need to have control of your external DNS :) These technologies stop people spoofing emails as you and thus getting you on the spam filters bad books.

 

also ask them to sop smtp forwarders for all users. (this stops people having emails automatically forwarded and is used in email attacks)

Posted
To setup these technologies you'd need to have control of your external DNS :) These technologies stop people spoofing emails as you and thus getting you on the spam filters bad books.

 

also ask them to sop smtp forwarders for all users. (this stops people having emails automatically forwarded and is used in email attacks)

 

We have control of our DNS. I can probably disable SMTP forwarding, but I know no-one is using it (we get alerts when anyone creates a forward rule) - would that help?

 

In conversation with our admissions and transition teams, it would appear GMail is worst-affected for treating us as spam.

Posted
it would appear GMail is worst-affected for treating us as spam.

 

Because you don't have DKIM, DMARC and SPF setup.

What's happening here is that your email setup is basically presenting itself as a potential threat, so it's being treated as such by email services.

Posted
Because you don't have DKIM, DMARC and SPF setup.

What's happening here is that your email setup is basically presenting itself as a potential threat, so it's being treated as such by email services.

 

I wonder why this has only just starting being a thing now. DMARC and SPF done, moving on to DKIM now.

Posted
I wonder why this has only just starting being a thing now. DMARC and SPF done, moving on to DKIM now.

SPF/DKIM/DMARC have been around a while, but more and more services are becoming more strict about them. So as time goes on, more email providers reject email without them. Basically a transition period.

Posted
SPF/DKIM/DMARC have been around a while, but more and more services are becoming more strict about them. So as time goes on, more email providers reject email without them. Basically a transition period.

 

Which explains why GMail seems worst affected.

Posted (edited)
I wonder why this has only just starting being a thing now. DMARC and SPF done, moving on to DKIM now.

Becuase everyone has seen what's happened with the phishing campaigns at schools over the pandemic period, and has started to set them up, basically.

 

Think about signing up for NCSC Mail Check too: https://www.ncsc.gov.uk/information/mailcheck

 

Which explains why GMail seems worst affected.

Well, certainly Google are more vocal about setting them up than Microsoft are, which probably means Gmail organisations are probably more likely to have them switched on. We know Exchange isn't exactly famed for it's security.

Edited by paulkerton
Posted
We know Exchange isn't exactly famed for it's security.

 

 

au contraire! Exchange is very famous for its security. Its been in the news and everything!

  • Thanks 2
  • 2 weeks later...
Posted
Okay, so I've done all the DMARC, SPF and DKIM. One thing I still don't understand - how does any of this make our mail servers more secure/trustworthy? If an account is compromised someone could still log in remotely and send loads of emails, so what have I actually achieved?
Posted (edited)
Okay, so I've done all the DMARC, SPF and DKIM. One thing I still don't understand - how does any of this make our mail servers more secure/trustworthy? If an account is compromised someone could still log in remotely and send loads of emails, so what have I actually achieved?

They authenticate and validate that the email is coming from your server and isn't being spoofed from elsewhere. The three of them together verify that the email from yourschool.org is coming from the server it is supposed to at the receivers end. If your email is tagged with I'm from serverx.org and your policy says so, my server receiving your message can check that it is, so it's more trustworthy.

Think of it like this - if you leave your house, someone could still kick the window in to use your phone, but you still lock the windows and doors when you leave to make it more difficult for them to just walk in unaided, don't you?

Edited by paulkerton
  • Thanks 1
Posted

These technologies don't mitigate against that scenario, no. But what they do is help prevent people from sending fraudulent email from another SMTP server pretending it's you. The SMTP protocol is ancient and wasn't really built and designed with a network the scale of the Internet in mind. It's trivial to set up an SMTP server and send an email with any old address as the sender. What SPF/DKIM/DMARC do is define what network address ranges are allowed to send as you and if recipient email servers are set up correctly, if they get an email from an IP Address outside of that range they reject it.

 

It's not foolproof and they're not supposed to be an ultimate solution to everything, but they're an important part of your email security toolkit.

  • Thanks 2
Posted (edited)
Think of it like this - if you leave your house, someone could still kick the window in to use your phone, but you still lock the windows and doors when you leave to make it more difficult for them to just walk in unaided, don't you?

 

I think the metaphor here is:

 

You go out for the day. Someone breaks into your house and pretends to be you. A milkman knocks on the door and asks the person there if they're interested in milk delivery. The person at the house pretending to be you says "Yes".

 

If the milkman has SPF/DKIM/DMARC, he says "Great, can I have some ID please?". The person at the door either dithers and says "no", or the ID that he has doesn't match, it either isn't his or the address on his ID is wrong. The milkman says "LOL NO" and moves on.

 

If the milkman doesn't have SPF/DKIM/DMARC, he takes the person at the house at his word and signs the household up for the service.

 

The milkman checking for ID doesn't stop the vagrant from breaking into your house, but it does stop him from signing you up for a service you don't want. If you want to stop people from breaking into your house, you buy a stronger lock. Or an Alsatian.

 

/edit this was started before I noticed @enjay said "Thanks" :)

Edited by Norphy

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...