Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


1101

3122 posts

Uber Geek


#277351 9-Oct-2020 14:13
Send private message

Hi . A general question about spam filtering services

 

spoofed emails : is it too much too expect spoofed emails to be blocked by profession spam blocking systems/services ?
Specifically emails spoofed to look like they came from within the companies domain

 

eg
email spoofed to look like it came from within the company
From in outlook show as from (say) theboss@company.co.nz
Headers : from shows 'theboss@company.co.nz' , but ACTUAL sender in the headers shows (say) mrhacker@clickmeplease.com

Ignoring spf filtering ....
can/should a spam filter detect spoofed emails pretending to be from the domain(exchange server IP)  but came from somewhere else
Not expecting every spoofed email to be blocked, I would have expected the domains email adress to be protected from spoofing when this shows in the headers

Is there more to it than what Im thinking ?


Create new topic
Andib
1364 posts

Uber Geek

ID Verified
Trusted

  #2581929 9-Oct-2020 14:25
Send private message

Yes and no, There are some legitimate reasons to spoof an email (marketing departments seem to love to using a 3rd party sender to bulk email but insist it comes from the corporate domain and not a sub domain). This is why DKIM / SPF / DMARC are important to prove what is genuine and what isn't.

 

I know filtering services like Office365 ATP & Mimecast both offer anti-spoofing protections that work pretty well in the situations you've described however there will always be some that fall through the cracks.





<# 
       .DISCLAIMER
       Anything I post is my own and not the views of my past/present/future employer.
#>




K8Toledo
1014 posts

Uber Geek


  #2581963 9-Oct-2020 15:34
Send private message

Who is your email provider?


BlakJak
1275 posts

Uber Geek

Trusted

  #2582144 9-Oct-2020 22:19
Send private message

1101:

Hi . A general question about spam filtering services

 

spoofed emails : is it too much too expect spoofed emails to be blocked by profession spam blocking systems/services ?
Specifically emails spoofed to look like they came from within the companies domain

 

eg
email spoofed to look like it came from within the company
From in outlook show as from (say) theboss@company.co.nz
Headers : from shows 'theboss@company.co.nz' , but ACTUAL sender in the headers shows (say) mrhacker@clickmeplease.com

Ignoring spf filtering ....
can/should a spam filter detect spoofed emails pretending to be from the domain(exchange server IP)  but came from somewhere else
Not expecting every spoofed email to be blocked, I would have expected the domains email adress to be protected from spoofing when this shows in the headers

Is there more to it than what Im thinking ?

 

 

Remember that SPF is only enforced on the envelope, that is, the details exchanged during the SMTP transaction. The details that appear in the headers can (and are) be engineered to differ from the envelope.

 

 

The Envelope consists of the input for the MAIL FROM: SMTP command, which is usually the sender email address, and the RCPT TO: instruction, which is the list of all the relevant recipients for that server.

 

This is how BCC works - RCPT TO specifies the recipient, but the recipient's email address otherwise appears nowhere in the message (ala the headers), except where added by the recipients own mail platform.

 

 

So SPF alone - assuming the domain being forged actually publishes an SPF record that also includes a hardfail instruction - won't protect you if they engineer the envelope differention during transmission.

 

 

Agree with the assertion that DKIM and DMARC are worthy additions that'll help.

 

 

But at the end of the day spammers find that even where the sender address isn't forged, people will fall for things, so this is only incremental in value.

 

One tip: Outlook will show the sender email address, in addition to the name, if the email comes from outside.

 





No signature to see here, move along...

Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.