InspireICT Posted July 1, 2024 Posted July 1, 2024 A number of schools have just received an e-mail from their local authority requesting that they whitelist the local authority's e-mail domain. We know that their e-mail domain has been compromised 3 times in the last 18 months (distribution lists) which resulted in phishing attacks on schools. We've raised concerns about doing this and won't unless explicitly instructed to do so but what are your thoughts?
andy_b Posted July 1, 2024 Posted July 1, 2024 Had the request. Denied the request. Too many phishing emails from legit addresses - had one this morning (from another school).
TechMonkey Posted July 1, 2024 Posted July 1, 2024 Would be a no from me. Not just because of the compromises but because whitelisting is just a lazy solution to the issue.
Michael Posted July 1, 2024 Posted July 1, 2024 I wouldn't whitelist the email domain either, but I would recommend trusting the one email address correspondence was arriving from (only if there was an issue).
jthompson Posted July 1, 2024 Posted July 1, 2024 If their domain is suffering deliverability problems, there may welll be reasons why. Those will be reasons to not allowlist (we should avoid the terms blacklist and whitelist IMHO) their entire domain. Consider instead flagging them for review.
pete Posted July 1, 2024 Posted July 1, 2024 Nope, fix your mail systems. Super-no if they've been compromised 3 times in 18 months to the detriment of local schools.
Roberto Posted July 1, 2024 Posted July 1, 2024 (edited) We know that their e-mail domain has been compromised 3 times in the last 18 months (distribution lists) which resulted in phishing attacks on schools. ? This alone would earn them a two line reply from me: lol. No. You have to consider the risks to your students if they’re a likely attack vector for malware and scammers. Obviously you can’t block or ignore them, but I’d be very unhappy at the idea that their emails don’t need proper scrutiny given what you’ve said! Edited July 1, 2024 by Roberto
Jobos Posted July 1, 2024 Posted July 1, 2024 (edited) I’m surprised the LA actually thought it was a good idea to say that, shocking really. What authority was it? Edited July 1, 2024 by Jobos
dapaulio Posted July 1, 2024 Posted July 1, 2024 Had the request. Denied the request. Too many phishing emails from legit addresses - had one this morning (from another school). I 2nd this. Denied and move on. Too many phishing emails come from “trusted” addresses and la addresses.
XiJ Posted July 1, 2024 Posted July 1, 2024 That’s a horrendous request. So many Phishing attacks come from a compromised address of someone you know / internal. Do the LA not have any cyber security professionals ?
Oaktech Posted July 2, 2024 Posted July 2, 2024 We've had multiple requests for that from several organizations. We've said that'll we'll whitelist individual addresses for safeguarding reasons but everything else goes to quarantine.
DrCheese Posted July 2, 2024 Posted July 2, 2024 Only time I've done this, I've still had a rule in place that checks the whitelisted domains SPF + DMARC rules - It was my compromise for this as at least we could then ensure that it was coming from the whitelisted domain & not someone spoofing it. That said, if they're asking you to do this what's the bet they don't have either in place...
TechMonkey Posted July 2, 2024 Posted July 2, 2024 @DrCheese - I think I may have copied your example that uses " 'Authentication-Results' header contains ''dmarc=pass' or 'dmarc=bestguesspass'' "
mavhc Posted July 2, 2024 Posted July 2, 2024 Send them an email back requesting they secure their email domain. Ask what percentage of users are using MFA, and when it's not 100%, ask why. Also dmarc etc
Michael Posted July 2, 2024 Posted July 2, 2024 The problem with DMARC is that it only goes so far. It stops spoofing, but it doesn't stop the legitimate O365 tenancy being compromised (through whatever means). All emails sent out to schools would of course pass DMARC checks. It's going to be either schools reporting the unusual emails, or O365 security which detects the irregularity of emails being generated and sent. If said LA has been compromised quite frequently, then that would be the obvious place to start to re-gain the trust of schools.
mavhc Posted July 2, 2024 Posted July 2, 2024 Yeah, MFA to counter hacks, dmarc/spf/dkim to counter spoofed email threaten them with freedom of information requests, that's always fun
psydii Posted July 2, 2024 Posted July 2, 2024 (edited) Explain that you can't reasonably be expected to lower your information security posture around email when it is a well known vector for cyber criminals, particularly spoofing/phishing attacks. However you are happy to pro-actively monitor for emails that may be blocked or quarantined and manually release them until such time that your cloud provider's algorithms re-learn that their domain is trustworthy. Edited July 2, 2024 by psydii
CrootUK Posted July 2, 2024 Posted July 2, 2024 We never whitelist email addresses or domains. Snap, neither do we. Majority of my longest standing tickets are awaiting on people to fix spf/dkim/dmarc on there domains. Some are quick, some are slow..
jthompson Posted July 2, 2024 Posted July 2, 2024 Explain that you can't reasonably be expected to lower your information security posture around email when it is a well known vector for cyber criminals, particularly spoofing/phishing attacks. However you are happy to pro-actively monitor for emails that may be blocked or quarantined and manually release them until such time that your cloud provider's algorithms re-learn that their domain is trustworthy. Or just refer them to Google's own guidance for bulk senders, given that Google and Yahoo! made a point last year of requiring DMARC and TLS of bulk senders. https://apps.google.com/supportwidget/articlehome?article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fanswer%2F81126%3Fvisit_id%3D638555207111666668-2699043947&assistant_id=generic-unu&product_context=81126&product_name=UnuFlow&trigger_context=a&fragment=zippy%3D%2Crequirements-for-sending-or-more-messages-per-day%2Crequirements-for-all-senders
dapaulio Posted July 2, 2024 Posted July 2, 2024 Only time a have whitelisted and email domain was an organised timed survey being submitted from one of these companies the school was using. Whitelist in place for no longer than a day. Even then I warned that they sent the survey in batches rather than send all.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now