Jump to content

Recommended Posts

Posted
A number of schools have just received an e-mail from their local authority requesting that they whitelist the local authority's e-mail domain. We know that their e-mail domain has been compromised 3 times in the last 18 months (distribution lists) which resulted in phishing attacks on schools. We've raised concerns about doing this and won't unless explicitly instructed to do so but what are your thoughts?
Posted

Had the request. Denied the request.

 

Too many phishing emails from legit addresses - had one this morning (from another school).

Posted
I wouldn't whitelist the email domain either, but I would recommend trusting the one email address correspondence was arriving from (only if there was an issue).
Posted

If their domain is suffering deliverability problems, there may welll be reasons why. Those will be reasons to not allowlist (we should avoid the terms blacklist and whitelist IMHO) their entire domain.

 

Consider instead flagging them for review.

Posted

Nope, fix your mail systems.

 

Super-no if they've been compromised 3 times in 18 months to the detriment of local schools.

Posted (edited)
We know that their e-mail domain has been compromised 3 times in the last 18 months (distribution lists) which resulted in phishing attacks on schools. ?

 

This alone would earn them a two line reply from me:

 

lol.

No.

 

You have to consider the risks to your students if they’re a likely attack vector for malware and scammers. Obviously you can’t block or ignore them, but I’d be very unhappy at the idea that their emails don’t need proper scrutiny given what you’ve said!

Edited by Roberto
Posted (edited)

I’m surprised the LA actually thought it was a good idea to say that, shocking really.

 

What authority was it?

Edited by Jobos
Posted
Had the request. Denied the request.

 

Too many phishing emails from legit addresses - had one this morning (from another school).

 

I 2nd this. Denied and move on. Too many phishing emails come from “trusted” addresses and la addresses.

Posted

That’s a horrendous request. So many Phishing attacks come from a compromised address of someone you know / internal.

 

Do the LA not have any cyber security professionals ?

Posted

We've had multiple requests for that from several organizations.

 

We've said that'll we'll whitelist individual addresses for safeguarding reasons but everything else goes to quarantine.

Posted

Only time I've done this, I've still had a rule in place that checks the whitelisted domains SPF + DMARC rules - It was my compromise for this as at least we could then ensure that it was coming from the whitelisted domain & not someone spoofing it.

That said, if they're asking you to do this what's the bet they don't have either in place...

Posted

Send them an email back requesting they secure their email domain. Ask what percentage of users are using MFA, and when it's not 100%, ask why.

 

Also dmarc etc

Posted

The problem with DMARC is that it only goes so far. It stops spoofing, but it doesn't stop the legitimate O365 tenancy being compromised (through whatever means). All emails sent out to schools would of course pass DMARC checks. It's going to be either schools reporting the unusual emails, or O365 security which detects the irregularity of emails being generated and sent.

 

If said LA has been compromised quite frequently, then that would be the obvious place to start to re-gain the trust of schools.

Posted

Yeah, MFA to counter hacks, dmarc/spf/dkim to counter spoofed email

 

threaten them with freedom of information requests, that's always fun

Posted (edited)
Explain that you can't reasonably be expected to lower your information security posture around email when it is a well known vector for cyber criminals, particularly spoofing/phishing attacks. However you are happy to pro-actively monitor for emails that may be blocked or quarantined and manually release them until such time that your cloud provider's algorithms re-learn that their domain is trustworthy. Edited by psydii
Posted
We never whitelist email addresses or domains.

 

Snap, neither do we. Majority of my longest standing tickets are awaiting on people to fix spf/dkim/dmarc on there domains. Some are quick, some are slow..

Posted
Explain that you can't reasonably be expected to lower your information security posture around email when it is a well known vector for cyber criminals, particularly spoofing/phishing attacks. However you are happy to pro-actively monitor for emails that may be blocked or quarantined and manually release them until such time that your cloud provider's algorithms re-learn that their domain is trustworthy.

 

Or just refer them to Google's own guidance for bulk senders, given that Google and Yahoo! made a point last year of requiring DMARC and TLS of bulk senders.

 

https://apps.google.com/supportwidget/articlehome?article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fanswer%2F81126%3Fvisit_id%3D638555207111666668-2699043947&assistant_id=generic-unu&product_context=81126&product_name=UnuFlow&trigger_context=a&fragment=zippy%3D%2Crequirements-for-sending-or-more-messages-per-day%2Crequirements-for-all-senders

Posted
Only time a have whitelisted and email domain was an organised timed survey being submitted from one of these companies the school was using. Whitelist in place for no longer than a day. Even then I warned that they sent the survey in batches rather than send all.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...