Jump to content

Recommended Posts

Posted

Good morning,

 

Probably not quite the right place for this post but one of our staff recently received an e-mail reporting to be from an internal account\address that was deleted sometime ago and I'm wondering if I've maybe got a bigger security issue here with an external threat actor or spoofing?

 

Thanks

Posted
look in the header, where did it originate? Do you have SPF and DKIM set up? DKIM should stop the spoofing mail being seen as legitimate as the sender.
Posted

@djm968 @KK20

 

Apologies for the delay in reply, I've got a copy of the message now so I can try and run a trace or look at the header.

 

I don't know if I've got SPF or DKIM setup, we use Office 365 but I guess I would need to check this with LGfL as our DNS and mail filtering is with them.

  • 2 weeks later...
Posted

@Olliedawg

 

Finally got around to changing the DMARC record to exactly what @Michael had put and had a nice notification from NCSC informing me there was no longer an issue so I guess there was something in it, not that NCSC was alerting with the record the way I had it which is interesting.

 

Now for MTA-STS...

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...