{"id":3360,"date":"2018-05-25T01:46:45","date_gmt":"2018-05-25T01:46:45","guid":{"rendered":"http:\/\/pariswells.com\/blog\/?p=3360"},"modified":"2018-05-28T02:27:44","modified_gmt":"2018-05-28T02:27:44","slug":"mimecast-impersonation-protection-not-working","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/random\/mimecast-impersonation-protection-not-working","title":{"rendered":"Mimecast Impersonation Protection not working"},"content":{"rendered":"<p>Recently a email\u00a0came in from a third party which wasn&#8217;t blocked by the\u00a0Impersonation Protection<\/p><p>Administration &gt; Gateway &gt; Policies &gt; Impersonation Protection Definitions\u00a0\u00a0<\/p><h2>Default\u00a0Impersonation Protection for Mimecast\u00a0<\/h2><ul><li>Similar Internal Domain (Similarity Distance 2 )\u00a0<\/li><li>Newly Observed Domain ( Checked )\u00a0<\/li><li>Internal User Name ( Checked )\u00a0<\/li><li>Reply-to Address Mismatch ( Uncheck )\u00a0<\/li><li>Targeted Threat Dictionary ( Checked )\u00a0<\/li><li>Mimecast Threat Dictionary ( Checked )\u00a0<\/li><li>Number of Hits : 2<\/li><li>Ignore Signed Messages ( Unchecked )\u00a0<\/li><\/ul><p>For executives, particularly those who are disclosed on the company website I recommend implementing a hit score of 1 on emails with their name as a display name.\u00a0<br \/><br \/><\/p><h2>Exec Impersonation Protection<\/h2><ul><li>Similar Internal Domain\u00a0 ( Checked )\u00a0<\/li><li>Newly Observed Domain\u00a0 ( Checked )\u00a0<\/li><li>Internal User name\u00a0 ( Checked )\u00a0<\/li><li>Number of Hits: 1\u00a0<\/li><\/ul><p><br \/>Administration &gt; Gateway &gt; Policies &gt; Impersonation Protection &gt; New Policy\u00a0<\/p><p><br \/>Selection Option: Choose the new definition that was just created\u00a0<br \/>Addresses based on: Both\u00a0<br \/>Applies from: Header Display Name\u00a0<br \/>Specifically: INSERT NAME\u00a0<br \/>Applies To: Internal Addresses\u00a0<br \/>Save and Exit\u00a0<br \/><br \/>I would advise that display name checks are in place all high profile targets, particularly those disclosed on the company website or other public sources. You also may want to consider alternative spellings. An individual policy is required for each display name.\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>Recently a email\u00a0came in from a third party which wasn&#8217;t blocked by the\u00a0Impersonation ProtectionAdministration &gt; Gateway &gt; Policies &gt; Impersonation Protection Definitions\u00a0\u00a0Default\u00a0Impersonation Protection for Mimecast\u00a0Similar Internal Domain [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[2500,1797,1410],"class_list":["post-3360","post","type-post","status-publish","format-standard","hentry","category-random","tag-impersonation-protection","tag-mimecast","tag-policy"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/3360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=3360"}],"version-history":[{"count":3,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/3360\/revisions"}],"predecessor-version":[{"id":3364,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/3360\/revisions\/3364"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=3360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=3360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=3360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}