Jump to content

Recommended Posts

Posted (edited)

A few weeks ago I setup DMARC with p=none

 

I have manually been uploading the reports to MX tool box. Luckily we don't have that many.

 

I just uploaded a DMARC Aggregate Report and it lists 39 fails from an IP.

 

I just checked the IP and its some company in America (I'm in the UK)

 

So, just a few basic questions.

 

Does this mean DMARC has done its job and flagged someones IP address as sending emails out as though they are the school? Or does this mean they received emails that they rejected?

 

What do I do next? Do I just keep reading the reports until I am happy nothing we are sending gets flagged as failed, then at that point move to p=quarantine or p=reject?

 

Or should I panic?

Edited by TwistedHelixis
Posted
You haven’t indicated a wish so receiving mail servers will make their own mind up. In my experience, you tend to get some background noise of spoofers using your domain especially if you are a well known domain, but a repeated attempt from the US sounds legit, if poorly setup. Could you track emails to you from these IP addresses to see if it gives a clue.
Posted

Thanks for replying.

 

Sorry, I'm very much learning all of this as I go.

 

You haven’t indicated a wish so receiving mail servers will make their own mind up.

Do you mean quarantine or reject?

 

you tend to get some background noise of spoofers using your domain especially if you are a well known domain

Can't imagine we are well known, we are just small primary school in the UK.

 

but a repeated attempt from the US sounds legit

When you say legit, do you mean this sounds like someone spoofing our domain?

 

Could you track emails to you from these IP addresses to see if it gives a clue.

How would I do this? I don't think these emails are getting sent to our email inbox. Are they not getting sent from a spoofer's email system, to a third party email inbox, which has then flagged this and sent me an email of the spoofer IP in my DMARC reported? Or have I got this completely wrong?

Posted
Watching closely. Our MSP have DMARC=none, but are far as I can tell have never done any monitoring. What I do know is the charity use MailChimp - could something similar be the cause of the America based emails?
Posted
What I do know is the charity use MailChimp - could something similar be the cause of the America based emails?

Thanks, perhaps this is the case.

 

The IP listed in the report is 50.31.43.182

When I do a 'who is' lookup, it lists Twilio SendGrid

Twilio SendGrid seem to offer a range of email services. Not sure why anyone at our school would need to be using this.

 

So, what I first need to workout.... is the IP 50.31.43.182 the email sender or recipient. How do I find that out?

Posted

I am also helping to set up DMARC at a friends school. I just asked them to check their reports. They also have the failed IP 50.31.43.182 listed.

 

So it is starting to seem more likely that this is some kind of school used email system, which is good.

 

In the report it does list that the report was supplied from Enterprise Outlook, so I am guessing the emails are getting sent from 50.31.43.182 to people in Outlook.

 

The only systems I can think of that might send emails for the school are Arbor and parentMail, but they are both external UK companies.

 

1) If it is a legitimate school emailing system, how on earth do I workout what school system is sending these emails?

2) If I do workout which system is causing the failed logs, how do I go about fixing this?

Posted
Chances are a legit system is sending some emails to your mail server, so look at incoming emails with a from address of your domain.

I will take a look later when I get a few some time, but tbh this has confused me now.

 

Please let me know if I am totally wrong on this, but from what I can tell the emails are coming from an American server ( 50.31.43.182) and getting sent to a bunch of outlook users, but all the emails are being sent from the American server using our UK school @ domain in the from address.

Then the Outlook servers are seeing an issue with those emails DMARC settings and sending me an email to let me know they have received emails from someone that might not be us.

 

Are you saying that all these emails get sent to our server too?

 

FYI our school is 100% Google and do not use Outlook.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...