Jump to content

DKIM - would you expect the norm for it to be configured?


Recommended Posts

Posted
As a default position would you expect DKIM to be have been set up and configured by your IT provider. It would appear following a cyber security certification, run by our IT provider that it has not been the case before. Whilst not directly charging for the update, they are indirectly, by using time we have allocated once a quarter onsite IT Technician time we have. I would have thought it should have been covered when we onboarded. I also don't agree it needs to be done during our 'on-site' time. I don't have the details, but apparently MailChimp use by our fund raising team came up in discussion - ring an bells for anyone?
Posted

If it’s purely DKIM it shouldn’t take long at all (in work time say 30 mins tops) then replication time for DNS etc but that’s just left overnight etc

 

The only long bit is finding out who sends emails from your domain to add the record in (assuming that’s the mail chimp convo)

 

Or do you mean full DMARC etc?

 

Steve

  • Thanks 1
Posted
Isn't there some recommendation about cycling DKIM keys periodically (like, ev 6mo or something)? Perhaps that might making it more than just an onboarding task.
  • Thanks 1
Posted (edited)

I think Google and Yahoo pretty much pushed every other mail provider to set up a DKIM record for the domain that use their systems support. O365 is relatively straight forward to set up but you need the initial rotation. and from what i remember about g-mail based dkim set up this already meets the standard but only generated one record (note only set up one domain over a year ago).

 

You could potentially set this up yourself if you have permissions to Domains DNS records and admin access to your email system the additional DMARC and SPF records are what you need to be aware of if previously not been set use p=none, p=quarantine, as the last switch and various tools can be used to trace the source of your emails such as mail chimp and arbor.

 

As a former support provider this work was covered under any agreement except onsite technician time

Edited by akidosaint
Posted (edited)
If it’s purely DKIM it shouldn’t take long at all (in work time say 30 mins tops) then replication time for DNS etc but that’s just left overnight etc

 

The only long bit is finding out who sends emails from your domain to add the record in (assuming that’s the mail chimp convo)

 

Or do you mean full DMARC etc?

 

Steve

Purely DKIM as far as I am aware, DMARC and SPF already configured, but unfortunately I don't have access to check myself and getting the info would take a little effort, which as we have a technician visiting next week, I can check.

I'm not sure I follow you on the bit about sending emails - could you add more details,

Edited by Ditto
Posted
Isn't there some recommendation about cycling DKIM keys periodically (like, ev 6mo or something)? Perhaps that might making it more than just an onboarding task.

I'll raise that with the technician too. Out of interest, how does that work on a live system - presumably timing is relevant?

Posted
I think Google and Yahoo pretty much pushed every other mail provider to set up a DKIM record for the domain that use their systems support. O365 is relatively straight forward to set up but you need the initial rotation. and from what i remember about g-mail based dkim set up this already meets the standard but only generated one record (note only set up one domain over a year ago).

 

You could potentially set this up yourself if you have permissions to Domains DNS records and admin access to your email system the additional DMARC and SPF records are what you need to be aware of if previously not been set use p=none, p=quarantine, as the last switch and various tools can be used to trace the source of your emails such as mail chimp and arbor.

 

As a former support provider this work was covered under any agreement except onsite technician time

I guess my thinking was it should have been dealt with as part of the on-boarding process. Our outsourced provider market themselves as leader in the cyber-security space. My feeling is they preach at a much higher level than they deliver. Apparent I'm told this topic came up as a part of there own cyber-security certification - at bronze level. This is apparently a process before we target Cyber Security Essentials. Their certification would have costs associated. My gripe is it appears we are incurring expenses on stuff that shouls have been covered 3 years ago. They pointed the charity at NCSC for free cyber security training. This DKIM topic is mentioned on NCSC at https://www.ncsc.gov.uk/collection/email-security-and-anti-spoofing. They've not even adhered to NCSC basic recommendations from 2019.

Posted
I'll raise that with the technician too. Out of interest, how does that work on a live system - presumably timing is relevant?

 

Roughly/from memory (i'm not an expert but I did 365 keys a couple of months ago, following instructions)..

 

There are two keys.

 

If you assume that key1 is live, when you rotate the keys it rotates key2 and publishes it, then after the expiry date of key1, key2 becomes live. At which point you can cycle key1.

 

Ish...

  • Thanks 1
Posted (edited)
Purely DKIM as far as I am aware, DMARC and SPF already configured, but unfortunately I don't have access to check myself and getting the info would take a little effort, which as we have a technician visiting next week, I can check.

I'm not sure I follow you on the bit about sending emails - could you add more details,

 

Use MXtoolbox to check spf and DMARC records.

Edited by akidosaint
Posted
if its of any use, i used this in the past to check the status of domains

 

https://www.learndmarc.com/

 

Thanks for this - I will ask the technician to have a go. I suspect the tool on NCSC is similar. I ran that one myself at it reported:

 

DMARC policy in place, but policy is set to 'none' (p=none). It points out this fake (spoof) emails are likely to be delivered.

 

Should I be kicking up a big fuss with our provider, or could there be other protections in place that mitigate this.

 

Other items reported:

SPF - all good

DKIM and PTR not assessed ( as just the domain provided, not an email sent).

TLS - all good

MTA-STS - not configured, meaning email privacy at higher risk due to possibility of downgrade - must admit I've not come across this setting before.

Posted
Once you've been monitoring your mail security and your happy you have got any systems that email as your domain configured correctly so they are all secured, you should get it switched to a stronger dkim setting to either quarantine or reject.
  • Thanks 1
Posted
Once you've been monitoring your mail security and your happy you have got any systems that email as your domain configured correctly so they are all secured, you should get it switched to a stronger dkim setting to either quarantine or reject.

Unfortunately I can not do that personally, I have no access and it's not my role. But, it should be something done by our IT service provider. Trouble is, I have enough knowledge and experience to hold them to account, especially when they propose work that is chargeable beyond standard support. My view is after 2+ years this should have been done ages ago. Unfortunately my line manager suggested he has 20% of my knowledge, and that could be an over estimated. On more than one occasion, he has said he just has to accept what they say, which is understandable to a point, but I know that can leave us exposed and not just from unnecessary project expense. Their sales pitch was that they would be our IT department. I feel they have fallen short in this role in several areas. 1st line support is very good, but elsewhere not so much.

Posted
Id expect DKIM and DMARC to be included on any onboarding or managed service being provided as a part of the initial setup and argue that it is basic security measures that should be taking place. I remember setting ours up and using Office 365 and Cloudflare for our domain it taking less than 30 minutes, most of that time was waiting for DNS propagation.Rotation of DKIM keys Id see as a chargeable/on-going routine maintenance for security. I would also class the DMARC as not setup if the policy is still set to 'none' as it will still deliver the spoofed emails. Id expect it to be 'quarantine' as a minimum.
  • Thanks 1
Posted

I decided to communicate with the IT providers solution architect directly and got a very thorough reply. In essence the statement on DMARC was p=none is their default policy for al lclients, in part as additional costs would be incurred to setup monitoring tools and implementation work to have p=quarantine or p=reject. It was stated that DMARC policy is something that has been discussed internally and with other clients. At this point it was advised p=none is OK and no need to do anything currently. It was acknowledge that the likes of gmail had tightened up in this area, but that tightening was restricted to having a policy, rather than none at all, hence p=none. It was also stated with that policy in place, we were less likely to find emails 'junked' at the receiving end.

 

Although there is no proposal to use them, it was suggested products like EASYDmarc, DMarian or DMARC analyzer. It was explained this is an area that is more important to high volume marketing emails, especially if related to revenue streams. This may be applicable for us as we do a marketing team (they call themselves Engagement, formerly known as Development!). This might link in to chatter I have heard about MailChimp, but i don't yet have the details. What was added, was if the policy was changed from none whilst they could set this up (chargeable) they would, they don't offer a monitoring solution so that would need need to be assigned to someone internally. It's fair to say we probably don't have anyone suitable to do that, certainly no one is likely to volunteer!

 

I raised the topic of MTA-STS. The view from the IT Provider was it is something that is becoming more prevalent in use. Something that could be turned on, but would equally need setup and then internal monitoring. It was stated that outgoing emails would be at least TLS 1.2, but we have no way of knowing if the same if the case for incoming emails. It was stated that if incoming data was highly sensitive (it absolutely is) then deploying MTA-SYS does need serious consideration. They have few clients with it enabled, but we probably, with the nature of the data that comes in, should look in to it carefully.

Posted
I decided to communicate with the IT providers solution architect directly and got a very thorough reply. In essence the statement on DMARC was p=none is their default policy for al lclients, in part as additional costs would be incurred to setup monitoring tools and implementation work to have p=quarantine or p=reject. It was stated that DMARC policy is something that has been discussed internally and with other clients. At this point it was advised p=none is OK and no need to do anything currently. It was acknowledge that the likes of gmail had tightened up in this area, but that tightening was restricted to having a policy, rather than none at all, hence p=none. It was also stated with that policy in place, we were less likely to find emails 'junked' at the receiving end.

 

Although there is no proposal to use them, it was suggested products like EASYDmarc, DMarian or DMARC analyzer. It was explained this is an area that is more important to high volume marketing emails, especially if related to revenue streams. This may be applicable for us as we do a marketing team (they call themselves Engagement, formerly known as Development!). This might link in to chatter I have heard about MailChimp, but i don't yet have the details. What was added, was if the policy was changed from none whilst they could set this up (chargeable) they would, they don't offer a monitoring solution so that would need need to be assigned to someone internally. It's fair to say we probably don't have anyone suitable to do that, certainly no one is likely to volunteer!

 

I raised the topic of MTA-STS. The view from the IT Provider was it is something that is becoming more prevalent in use. Something that could be turned on, but would equally need setup and then internal monitoring. It was stated that outgoing emails would be at least TLS 1.2, but we have no way of knowing if the same if the case for incoming emails. It was stated that if incoming data was highly sensitive (it absolutely is) then deploying MTA-SYS does need serious consideration. They have few clients with it enabled, but we probably, with the nature of the data that comes in, should look in to it carefully.

 

Did ChatGPT write those responses? I certainly wouldn't be running with p=none other than when first testing an implementation.

 

MTA-STS again needs some care with setup but is absolutely something we run across all our schools.

  • Thanks 1
Posted

ChatGPT? Well it's hard to be sure! It was my words but heavily influenced but what was the written in the email to me. I really appreciate the feedback and a second perspective.

 

I will relay the thoughts back, and any others posted. I also note what NCSC advise. Does anyone know if Cyber Essentials gets in to this low a detail.

 

Broadening out on this topic, here is background info that perhaps makes it clearer the challenge in hand:

 

My line manager who ultimately has been lumbered with IT responsibility for the organisation has no enterprise IT experience. When the out-sourced IT company was appointed, the said they'd be 'our IT department' and advise best practice. But they haven't delivered that. The LM has on more than one occasion said to me they have no choice but to accept what they tell him as fact as has no means to validate it. It's the IT provider is paid to do. If I wasn't there to dig deeper, then that wouldn't happen. There has been a little bit of talk about recruiting an IT manager. Basically my LM had IT dumped on them as a role. They don't won't that role, and it wasn't in their role originally AFAIK. To give an idea of the level of knowledge, the visiting OT technician was to so a new Windows install on an older laptop that was playing up. Early on, the install stopped as it couldn't see a drive. So that was abandoned for the they. I said as a first step I'd be stepping in to the BIOS to check settings. My LM admitted he had no idea what I was talking about. So, given how much time is burnt between me, another colleague and my LM, I think a dedicate IT manager, with the right level of knowledge could help. I don't think it needs a full time role, but I do think it could lead to tension between the IT provider and us. A big advantage I see is the P/T manager would be working for the charity with the goal of getting the right decisions and directions made. At the end of the day, the IT provider is there to make a profit. I've also suggested we have an IT Manager, possibly full time and ditch the outsource. That won't get off the ground though. A bit like consultancy services being brought in, the SLT seem to think expertise needs to be outsourced as it is an area that they personally don't really understand. But I can see an internal IT manager providing a better experience than this outsources solution. They'd never look to out-source the work of our front line team, but it's because that's their backgrounds mostly. The next few weeks/months will be interesting to see how thing pan out, in part as budgeting cycles are underway.

Posted

Circling back on the ChatGPT question, I did two things with the original reply.

1. I asked for it to be rewritten in the style of a car dealer.

2. I asked it to give it's view on the original reply being ChatGPT generated.

 

The reply was "The language and structure of the original text are fairly typical of technical explanations generated by AI models like ChatGPT – clear, somewhat verbose, and structured to walk through the reasoning behind a phased approach.

 

The rewritten text, with its analogies and informal tone, is a departure from the typical style, adding personality and a sales-like pitch reminiscent of a car dealer, which is less common in default AI responses unless specifically prompted."

 

I do find the concept of AI systems self-analyzing interesting. "AI navel-gazing" - the concept just amuses me!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...