enjay Posted July 8, 2021 Posted July 8, 2021 Seemingly with increasing frequency, emails we send to parents are ending up in their junk folders. Is there anything we can do about this? For the sake of this question, let's assume the staff aren't using lots of trigger words like "viagra" in their emails!
ZeroHour Posted July 8, 2021 Posted July 8, 2021 (edited) Who is your mail sent through and how? SPF and DomainKey setup fully? Volume of email sent per day can be a factor but I would be surprised if it was affecting you. If you send from your own in-house smtp/server then it can be factor with ip reputation but through a third party it can be avoided to a point. Edited July 8, 2021 by ZeroHour
chazzy2501 Posted July 8, 2021 Posted July 8, 2021 yeap, check your DMARC stuff as above. disallow smtp forwarders and check your outgoing spam rules. 1
chaplic Posted July 8, 2021 Posted July 8, 2021 If send me an email if you want [email protected] (from the affected system obviously -is this something like parentmail or office365) and I'll take a look
free780 Posted July 8, 2021 Posted July 8, 2021 Get the Header of an affected E-Mail and paste it here. Message Header Analyzer (mha.azurewebsites.net) Check Authentication-Results and see if any have failed.
enjay Posted July 9, 2021 Author Posted July 9, 2021 Get DKIM, SPF and DMARC set up. Those are all acronyms I've never heard before. Is there a dummy's guide or should I just bounce up to our uber-techie support company?
Norphy Posted July 9, 2021 Posted July 9, 2021 There are plenty of how-to guides out there, but if you haven't heard those particular terms before I would pass it up to the support company. Also bear in mind that if you have other services which email on behalf of you (Examples: SurveyMonkey, helpdesk, third party mail filter), they will configuring for it as well.
chazzy2501 Posted July 9, 2021 Posted July 9, 2021 To setup these technologies you'd need to have control of your external DNS These technologies stop people spoofing emails as you and thus getting you on the spam filters bad books. also ask them to sop smtp forwarders for all users. (this stops people having emails automatically forwarded and is used in email attacks)
enjay Posted July 12, 2021 Author Posted July 12, 2021 To setup these technologies you'd need to have control of your external DNS These technologies stop people spoofing emails as you and thus getting you on the spam filters bad books. also ask them to sop smtp forwarders for all users. (this stops people having emails automatically forwarded and is used in email attacks) We have control of our DNS. I can probably disable SMTP forwarding, but I know no-one is using it (we get alerts when anyone creates a forward rule) - would that help? In conversation with our admissions and transition teams, it would appear GMail is worst-affected for treating us as spam.
chaplic Posted July 12, 2021 Posted July 12, 2021 There's no magic here. With the scant information you've provided there's multiple posts that almost certainly nail the issue. 1
paulkerton Posted July 13, 2021 Posted July 13, 2021 it would appear GMail is worst-affected for treating us as spam. Because you don't have DKIM, DMARC and SPF setup. What's happening here is that your email setup is basically presenting itself as a potential threat, so it's being treated as such by email services.
enjay Posted July 13, 2021 Author Posted July 13, 2021 Because you don't have DKIM, DMARC and SPF setup. What's happening here is that your email setup is basically presenting itself as a potential threat, so it's being treated as such by email services. I wonder why this has only just starting being a thing now. DMARC and SPF done, moving on to DKIM now.
localzuk Posted July 13, 2021 Posted July 13, 2021 I wonder why this has only just starting being a thing now. DMARC and SPF done, moving on to DKIM now. SPF/DKIM/DMARC have been around a while, but more and more services are becoming more strict about them. So as time goes on, more email providers reject email without them. Basically a transition period.
enjay Posted July 13, 2021 Author Posted July 13, 2021 SPF/DKIM/DMARC have been around a while, but more and more services are becoming more strict about them. So as time goes on, more email providers reject email without them. Basically a transition period. Which explains why GMail seems worst affected.
paulkerton Posted July 13, 2021 Posted July 13, 2021 (edited) I wonder why this has only just starting being a thing now. DMARC and SPF done, moving on to DKIM now. Becuase everyone has seen what's happened with the phishing campaigns at schools over the pandemic period, and has started to set them up, basically. Think about signing up for NCSC Mail Check too: https://www.ncsc.gov.uk/information/mailcheck Which explains why GMail seems worst affected. Well, certainly Google are more vocal about setting them up than Microsoft are, which probably means Gmail organisations are probably more likely to have them switched on. We know Exchange isn't exactly famed for it's security. Edited July 13, 2021 by paulkerton
enjay Posted July 13, 2021 Author Posted July 13, 2021 Think about signing up for NCSC Mail Check too: https://www.ncsc.gov.uk/information/mailcheck That's on my summer holiday list, too.
psydii Posted July 13, 2021 Posted July 13, 2021 We know Exchange isn't exactly famed for it's security. au contraire! Exchange is very famous for its security. Its been in the news and everything! 2
enjay Posted July 27, 2021 Author Posted July 27, 2021 Okay, so I've done all the DMARC, SPF and DKIM. One thing I still don't understand - how does any of this make our mail servers more secure/trustworthy? If an account is compromised someone could still log in remotely and send loads of emails, so what have I actually achieved?
paulkerton Posted July 27, 2021 Posted July 27, 2021 (edited) Okay, so I've done all the DMARC, SPF and DKIM. One thing I still don't understand - how does any of this make our mail servers more secure/trustworthy? If an account is compromised someone could still log in remotely and send loads of emails, so what have I actually achieved? They authenticate and validate that the email is coming from your server and isn't being spoofed from elsewhere. The three of them together verify that the email from yourschool.org is coming from the server it is supposed to at the receivers end. If your email is tagged with I'm from serverx.org and your policy says so, my server receiving your message can check that it is, so it's more trustworthy. Think of it like this - if you leave your house, someone could still kick the window in to use your phone, but you still lock the windows and doors when you leave to make it more difficult for them to just walk in unaided, don't you? Edited July 27, 2021 by paulkerton 1
Norphy Posted July 27, 2021 Posted July 27, 2021 These technologies don't mitigate against that scenario, no. But what they do is help prevent people from sending fraudulent email from another SMTP server pretending it's you. The SMTP protocol is ancient and wasn't really built and designed with a network the scale of the Internet in mind. It's trivial to set up an SMTP server and send an email with any old address as the sender. What SPF/DKIM/DMARC do is define what network address ranges are allowed to send as you and if recipient email servers are set up correctly, if they get an email from an IP Address outside of that range they reject it. It's not foolproof and they're not supposed to be an ultimate solution to everything, but they're an important part of your email security toolkit. 2
enjay Posted July 27, 2021 Author Posted July 27, 2021 Thanks @paulkerton and @Norphy that makes sense.
Norphy Posted July 27, 2021 Posted July 27, 2021 (edited) Think of it like this - if you leave your house, someone could still kick the window in to use your phone, but you still lock the windows and doors when you leave to make it more difficult for them to just walk in unaided, don't you? I think the metaphor here is: You go out for the day. Someone breaks into your house and pretends to be you. A milkman knocks on the door and asks the person there if they're interested in milk delivery. The person at the house pretending to be you says "Yes". If the milkman has SPF/DKIM/DMARC, he says "Great, can I have some ID please?". The person at the door either dithers and says "no", or the ID that he has doesn't match, it either isn't his or the address on his ID is wrong. The milkman says "LOL NO" and moves on. If the milkman doesn't have SPF/DKIM/DMARC, he takes the person at the house at his word and signs the household up for the service. The milkman checking for ID doesn't stop the vagrant from breaking into your house, but it does stop him from signing you up for a service you don't want. If you want to stop people from breaking into your house, you buy a stronger lock. Or an Alsatian. /edit this was started before I noticed @enjay said "Thanks" Edited July 27, 2021 by Norphy
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now