Jump to content

Recommended Posts

Posted

Just a post to note some Google GMail quarantine behaviour...

 

Today I found an email (NOT from Arbor password reset this time...) in my 'User Spoof' quarantine.

 

This quarantine was set up to receive emails based on one 'Safety' setting:

 

image.png.cd84801aff40669d7737ca9ef71b8d2e.png

 

We have a generic 'finance' office email address that only the bursar and BM use and the email got quarantined because another school obviously has a generic 'finance' office email address... :doh:

 

finance@anotherschool.com gets quarantined because we have a finance@myschool.com 'user'...?

 

Is everybody turning these safety settings off, finding a way to bypass them, or just dealing with the quarantines daily?

Posted

For that particular option (spoofing of employee names) I've chosen "Keep email in the inbox and show warning".

 

We sometimes have legitimate exchanges with people's personal email addresses, so having them delivered but with the warning being shown seems to be a decent compromise.

 

Also, there could be legitimate dealings with someone who does actually share a name with an employee.

 

WRT your 'finance' example, might including your school name in the display name would help to avoid the clash (i.e. "St. Smithen's Finance Department" <[email protected]>)?

  • Thanks 1
Posted

Yeah for that particular option, we have "Keep email in the inbox and show warning" ticked. Mainly for the same reasons @jthompson has mentioned. Our staff are usually quite good with reporting dodgy emails, or raising it with myself. So when a warning banner is displayed they are normally very cautious. 

  • Thanks 1
Posted
3 hours ago, jthompson said:

WRT your 'finance' example, might including your school name in the display name would help to avoid the clash (i.e. "St. Smithen's Finance Department" <[email protected]>)?

 

Thanks, but the display name is different to the username, so I think it must be reading the actual name in the username part and then just ignoring the fact that's it's from a completely different domain.

 

I'm not sure if anyone would be fooled into opening an email sent by [email protected] just because we have a user called [email protected]... (maybe with the added banner they'd be cautious), but hey, you never know they might and you can't be too careful, right?!

Posted

The banner is useful, yes, but it also means that if John Doe emails a couple of colleagues (either by honest mistake or indisciplne) from his Hotmail account, then if said colleages start replying, the Hotmail recipient will be highlighted in the recipeints field as a nudge to remove it and replace it with an org address.

  • Thanks 1
Posted

 

On 02/07/2025 at 11:07, jthompson said:

WRT your 'finance' example, might including your school name in the display name would help to avoid the clash (i.e. "St. Smithen's Finance Department" <[email protected]>)?

 

22 hours ago, Koldov said:

 

Thanks, but the display name is different to the username, so I think it must be reading the actual name in the username part and then just ignoring the fact that's it's from a completely different domain.

 

Interesting... so I have a new email in quarantine...

 

Office <[email protected]>

 

The only account we have bearing any resemblance is:

 

School Office - My School <[email protected]>

 

So... this one is based on spoofing part of the display name...?

Posted

Worryingly from my testing emails sent to a group where they spoof a display name don't get any banner applied to them so I'm curious as to whether they would go to quarantine - we use external facing groups for a variety of things.

Posted

I can't see any 'Safety' settings based on Groups apart from this and it is aimed at the Domain rather than the group name. The only ones based on name seem to be for individuals users.

 

image.png.649d9e2ad63b0bc0bc49edbb8adc3e6b.png

Posted
8 minutes ago, Koldov said:

I can't see any 'Safety' settings based on Groups apart from this and it is aimed at the Domain rather than the group name. The only ones based on name seem to be for individuals users.

 

image.png.649d9e2ad63b0bc0bc49edbb8adc3e6b.png

I would expect the setting on protect against spoof of employee names to still take action when emails are sent to a group. Instead it would appear that since the group then becomes the owner/sender of the email internally it gets ignored, potential to be a problem is massive here. Feels like Groups is somewhat underdeveloped and unloved over the years.

  • Like 1
Posted
17 hours ago, Primus said:

Worryingly from my testing emails sent to a group where they spoof a display name don't get any banner applied to them so I'm curious as to whether they would go to quarantine - we use external facing groups for a variety of things.

 Good spot. I hadn't noticed that before, but then we have no groups that externals can send to.

 

Worth noting that whilst there's no banner on the incoming group message, I'm testing it here and seeing a yellow warning banner when composing a reply.

 

"Be cautious about sharing sensitive information. [email protected] is outside your organisation and isn't in your contacts."

Whether that banner is a result of the same option in Admin, and whether it would be shown if the sender was in my contacts, IDK yet. I suspect the address in the To field of the reply would by underlined in yellow regardless, but that's quite a subtle visual cue just on it's own.

Posted

Now I understand why Egress messages get caught in the quarantine, they are also spoofing the user as it comes from the platform using the username... originally I thought it was something to do with the attachment and couldn't work out why my attachment allow rule wasn't working!

 

Found in the header:

 

[email protected]

 

Looks like as everybody is already doing this (and as it seems it isn't causing any issues), I'm going to have to relax my security settings a bit!

Posted

I've relaxed the security setting to 'keep in inbox but display a warning', however I'm a bit underwhelmed by the 'warning'... should it have anything else apart from a tiny yellow blob that says 'External'...? My users are going to need something more than that!

 

image.thumb.png.13f88b82a2da45886448d492f6cec460.png

 

I was expecting something a bit more like this (from a Google Image search), am I missing something...?

 

image.png.c07b045d313d055f9e25472a12fa74d3.png

 

Or are these emails actually NOT being quarantined for the reason I think...?

Posted (edited)

Thanks, I take it you have this setting enabled...?

 

image.png.79350f8d338c7248293f6e92912854b5.png

 

YMMV, but I have read if you add the sender to your contacts it helps (but I can't add user@arbor password reset, to every individual users address book)... 

 

Also, I turned that setting off once (unticked the box and saved), then I sent a password reset email from Arbor.. this (obviously) came through no problem.

 

Then I turned the setting back on and resent the password reset email.... and it came through no problem!

 

Now, none of the accounts I tested it with have a problem getting the password reset emails, the only time I can test it is with a GMail account I haven't tested it with before, because the first time it will quarantine, then after I change the settings to get it through, it will never have a problem even if I change the settings back to quarantine!

Edited by Koldov
Posted

Yeah there's literally no problem getting the emails to us, I've tested the headers in MX Toolbox and they're all ticked green. All the DNS stuff checks out as well, we've put everything they've told us into the DNS at our domain hosts.

 

Just once they hit GMail... BAM!

 

Quarantine...

 

I've ticked that setting in Google Admin and set-up a specific quarantine for it, so I know that is what is sending it there, I've also turned that setting off only and the emails get through.

 

I can't seem to bypass it with any kind of allow rule as it's not spam/phishing etc. As it's a 'user spoof' that setting kicks in before any of that. 

Posted
36 minutes ago, Koldov said:

Thanks, I take it you have this setting enabled...?

 

image.png.79350f8d338c7248293f6e92912854b5.png

 

 

Nope (but do have DKIM etc set up). I think it's because it's me via SendGrid. I just had a quick look at the settings, and it mainly looked at default level. I was surprised I could see as much as I could as we're on the cheapskate tier.

Posted

Yeah, all the report/password reset emails etc. are via SendGrid I think.

 

All those 'safety' settings are available in the Google cheapskate tier (I know because we're on it too), but I was so paranoid when I first created our GSuite, that I went through every setting and adjusted it for maximum security, only it looks like I've sacrificed usability...  :doh:

 

It's a 'known issue' at Arbor and I do know it's been posted about on here, but only once I think. Probably because everyone else has it on defaults too!

 

Maybe I should have just left everything on default as well... would have saved some headaches!

Posted

I have noticed that I get very little in the way of dodgy mails at my Google schools, whereas at my MS school it's just as well that I can create rules in Exchange.

  • Like 1
Posted

Yeah I have to say, we appear to be fairly spam/phishing/malware free as far as I know 🤞 but I had just put that down to my super strict security/safety settings... 

 

Maybe I should revisit a few of them and set them to defaults, lighten up, relax and stop being such a blocker... 🙄

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...