{"id":1908,"date":"2016-03-08T10:46:30","date_gmt":"2016-03-08T10:46:30","guid":{"rendered":"http:\/\/pariswells.com\/blog\/?p=1908"},"modified":"2022-08-26T22:34:16","modified_gmt":"2022-08-26T22:34:16","slug":"stopping-fraudlent-spoof-emails-spam","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/random\/stopping-fraudlent-spoof-emails-spam","title":{"rendered":"Stopping Fraudlent Spoof Emails SPAM"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-1909 img-responsive\" src=\"\/\/pariswells.com\/blog\/wp-content\/uploads\/2016\/03\/43443044-7237-11e5-9c63-d2a8b639876f_Phishing-email-1-620x3571-300x173.png\" alt=\"Scam\" width=\"300\" height=\"173\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2016\/03\/43443044-7237-11e5-9c63-d2a8b639876f_Phishing-email-1-620x3571-300x173.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2016\/03\/43443044-7237-11e5-9c63-d2a8b639876f_Phishing-email-1-620x3571.png 620w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>There&#8217;s been a new recent wave of spoof emails sent to companies , usually emailed to financial personnel&#8217;s pretending to be from the CEO to get quick funds paid and withdrawn.<\/p><p>Spoofing an email address isn&#8217;t hard and with the correct background check , spammers get the correct email and sometimes signature of the &#8220;CEO&#8221;.<\/p><p><strong>How do we stop this?<\/strong><\/p><ol><li>To start with\u00a0SPF, DKIM, DMARC records should all be added to the domain to verify the sender to check they are allowed to send from the company domain<\/li><li>You should definitely have an incoming spam filter before Microsoft Exchange , depending if this is a Barracudo box\u00a0\/ Post fix \/ Microsoft Frontbridge you should be able to enable a Rule to SPF check for only your domain. Enabling this for all domains will starting to spam lots of incoming email due to people not having SPF records<\/li><li>Create a quarantine in Exchaneg \u00a0&#8211; From EMC &gt; Organization Configuration &gt; Hub Transport &gt; Transport Rules create a new transport rule that says:<br \/>From users that are outside the organization<br \/>And when the from address matches text patterns yourdomain.com<br \/>Forward the message to quarantine@yourdomain.com for moderation<br \/>Now, if you have other SMTP servers in or out of your org that send on behalf of your domain, you&#8217;ll need to create an exception by adding:<br \/>Except when the message header received matches text patterns smtp.yourdomain.com or smtp.theirdomain.com<br \/><br \/><\/li><\/ol><p>You can also tighten down SPF to only allow specific email address to send from third party services instead of whole domain : <a href=\"https:\/\/www.jamieweb.net\/blog\/using-spf-macros-to-solve-the-operational-challenges-of-spf\/\">https:\/\/www.jamieweb.net\/blog\/using-spf-macros-to-solve-the-operational-challenges-of-spf\/<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>There&#8217;s been a new recent wave of spoof emails sent to companies , usually emailed to financial personnel&#8217;s pretending to be from the CEO to get quick [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[1222,1223,1375,916,1224],"class_list":["post-1908","post","type-post","status-publish","format-standard","hentry","category-random","tag-dkim","tag-dmarc","tag-scam","tag-spam","tag-spf"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/1908","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=1908"}],"version-history":[{"count":2,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/1908\/revisions"}],"predecessor-version":[{"id":6060,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/1908\/revisions\/6060"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=1908"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=1908"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=1908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}