SlideShare uma empresa Scribd logo
1 de 25
Baixar para ler offline
Your Customers
Need A Hero
Save them from Internet Villains
with DMARC
About the Speaker
• Email’s been my arch nemesis for 14 years
• Implemented DMARC for 128 domains in 7 months
• I’ve been saying, “Email is the worst thing ever”
for 10 years
Agenda
• Our Customers’ inboxes are under attack. They
need a hero.
• How do YOU become a DMARC hero?
• Getting your first victories.
• What will stand in your way?
• Know your weaknesses.
WHO WILL HELP IN OUR HOUR OF NEED?
What is DMARC?
No DMARC, 23
Monitor, 13
Quarantine, 1 Reject, 1
FORTUNE 500
HEALTH CARE SECTOR NOV. 2017
• Email authentication via DNS
• What can it do?
• Email blocking
• DMARC policies can stop bad emails
pretending to be from you.
• Provides insight into BEC
• You can see IPs that are trying
to send emails with your brand.
• Establishes Brand Assurance
• Your customers can be assured
that they’re safe emailing with
you.
To Start, read this:
• https://seanthegeek.net/459/
demystifying-dmarc/
Reject &
Quarantine 10.5%
None 34.9%
Invalid
DMARC 3.6%
No DMARC
51%
TECHNOLOGY INDUSTRY 2019
Source: @Valimail
Source: @AgariInc
But it should be.
• You gain control of your email brand.
• It’s FREE
• It’s easy to start and maintain.
• Marketing teams will see increases in delivery.
So why isn’t DMARC everywhere?
• Email is a utility.
• DMARC’s not a sexy topic.
• And it’s not the squeakiest wheel.
• You need a place to
receive DMARC
Reports: Then the
Telemetry comes to
you!
• Put up the _DMARC
entry in “Monitor”
mode. (p=none)
• Once you know who’s
trying to send email
as your brand, form a
plan.
• Save the metrics for
POV later!
GEAR UP
Where can you analyze your DMARC Reports?
FREE!
Hosted Services
• Postmark; dmarcian; DMARC
Analyzer…
DIY
• Parsedmarc by Sean Whalen
https://domainaware.github.io/
parsedmarc/
BUY A SIDEKICK!
• You can staff-augment to
quickly onboard knowledge
and assist with monitoring
post-implementation.
• Folks like Agari, dmarcian,
Valimail, and Proofpoint (to
name a few) have sidekicks
standing by!
Visit https://dmarc.org/resources/products-and-services/ for more!
Superhero Training Montage
Find your defensively
registered & non
sending domains and
set them to reject!
Your first victories!
Find your most
spoofed domain
and show how
the Reject
posture was
successful.
Work in the
shadows for now.
• No one else sends emails on your behalf?
• Only use one email hosting provider?
• Set up SPF/DKIM and monitor for a month.
• Then you’re ready to p=reject!
• You’re DONE!
You may then safely ignore the rest of this
presentation. Or read on just for fun!
You may be super close to being done!
Case Study: steves.nonsending.domain
Image Source: @proofpoint
The easy part’s over…
• Carefully review telemetry from your
sending domains.
• Enumerate your EaaS vendors – [Engage your
Third-party cyber risk Hero back at the
“Hall of Justice” if you’ve got one]
• Add their SPF & DKIM info to your DNS and
grow stronger
• Use your CNAME Kung–FU for lots of
defensively registered domains
Who are the villains that will stop at nothing
to destroy your initiative?
…the battle’s just begun.
• Multiple DNS TXT records
• More than 10 SPF Lookups
• DKIM Record typos
CONFUZOR
a.com IN TXT v=spf1 –all
a.com IN TXT v=spf1 include:spf.stuff.com ~all
• Tracking down
multi-national or BU EaaS
affiliations
• Tracking down Business
Cycle Specific Emails
THE SNEAK
• EaaS vendors who
issue SOWs or
charge extra to
support DMARC
for your domains.
NICKEL
& DIME
• Bad code that will cause
your DMARC evaluations
to fail.
• Usually DKIM related
• DMARC Telemetry system
Failures
SABOTAGE
• Bad email practices
from within.
YOUR OWN
ORGANIZATION
Where will DMARC not help?
• Misspelled Domains
• Compromised partner email accounts
• LISTSRV & Other assorted email hops
Know Your Weaknesses
What can help you Save the world?
• Centralize your Mail Flow
• Leverage Subdomains or…
• …Use Vanity Domains
Use your powers
• Take an iterative approach. Move domains to reject as
soon as you can; show the benefits when malicious use is
blocked or drops to zero for that domain.
• Headlines in the News: Tell everyone you’re protecting
your members directly, not just mitigating business risks.
• Constant Vigilance: Get DMARC into your standards,
policies, and business use cases. Get your marketing and
corp comm teams familiar with DMARC, why it’s important and
how it benefits their delivery rates.
A Hero’s Work is Never Done
What’s that in the sky?! A bird? A plane?
It’s BIMI!
• After you get to p=reject.
• Your logo will appear next to your
emails in your customers’ inboxes.
• In beta
• Requires rights to use a logo and
(after go-live) a cert to prove that
you own the logo.
• https://authindicators.github.io/rfc
-brand-indicators-for-message-
identification/
• Microsoft is doing their own thing:
• https://business.microsoft.com/
Image Source: Yahoo! Mail
Our Members deserve trustworthy
communications.
Start with the easy wins; iterate; don’t
let up.
Laughing about fictitious comic book
villains will help you have fun
implementing DMARC.
Be the hero!
Email me: info@steveocodez.com
© 2019 Stephen Mitchell and Matthew Bielewicz. Except where
otherwise noted,“Your Customers Need A Hero - Save Them From
Internet Villains With DMARC” is licensed under a Creative Commons
Attribution 4.0 International License.
http://creativecommons.org/licenses/by/4.0/

Mais conteúdo relacionado

Semelhante a Your Customers Need A Hero - Save Them From Internet Villains With DMARC

Annual Scary Episode on What's Scaring Us for 2016
Annual Scary Episode on What's Scaring Us for 2016Annual Scary Episode on What's Scaring Us for 2016
Annual Scary Episode on What's Scaring Us for 2016HighRoad Solution
 
OWASP ATL - Social Engineering Technical Controls Presentation
OWASP ATL - Social Engineering Technical Controls PresentationOWASP ATL - Social Engineering Technical Controls Presentation
OWASP ATL - Social Engineering Technical Controls PresentationOWASP Atlanta
 
Jak ochránit vaší značku a doménu s technologií DMARC
Jak ochránit vaší značku a doménu s technologií DMARCJak ochránit vaší značku a doménu s technologií DMARC
Jak ochránit vaší značku a doménu s technologií DMARCMailkit
 
.NET Developer Days 2015, PL: Defensive programming, resilience patterns & an...
.NET Developer Days 2015, PL: Defensive programming, resilience patterns & an....NET Developer Days 2015, PL: Defensive programming, resilience patterns & an...
.NET Developer Days 2015, PL: Defensive programming, resilience patterns & an...Daniel Fisher
 
MD DevdDays 2016: Defensive programming, resilience patterns & antifragility
MD DevdDays 2016: Defensive programming, resilience patterns & antifragilityMD DevdDays 2016: Defensive programming, resilience patterns & antifragility
MD DevdDays 2016: Defensive programming, resilience patterns & antifragilityDaniel Fisher
 
LCMC: Overcoming the barriers to deliverability
LCMC: Overcoming the barriers to deliverabilityLCMC: Overcoming the barriers to deliverability
LCMC: Overcoming the barriers to deliverabilityBlueHornet
 
2015 - Basta! 2015, DE: Defensive programming, resilience patterns & antifrag...
2015 - Basta! 2015, DE: Defensive programming, resilience patterns & antifrag...2015 - Basta! 2015, DE: Defensive programming, resilience patterns & antifrag...
2015 - Basta! 2015, DE: Defensive programming, resilience patterns & antifrag...Daniel Fisher
 
NRWConf, DE: Defensive programming, resilience patterns & antifragility
NRWConf, DE: Defensive programming, resilience patterns & antifragilityNRWConf, DE: Defensive programming, resilience patterns & antifragility
NRWConf, DE: Defensive programming, resilience patterns & antifragilityDaniel Fisher
 
An Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsAn Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsGabriella Davis
 
Fighting Email Abuse with DMARC
Fighting Email Abuse with DMARCFighting Email Abuse with DMARC
Fighting Email Abuse with DMARCKurt Andersen
 
Neuailes Global Technologies Pvt Ltd
Neuailes Global Technologies Pvt LtdNeuailes Global Technologies Pvt Ltd
Neuailes Global Technologies Pvt LtdShankar Suman
 
GoDMARC - Block Email Phishing
GoDMARC - Block Email PhishingGoDMARC - Block Email Phishing
GoDMARC - Block Email PhishingTarun Arora
 
Using DMARC to Improve Your Email Reputation
Using DMARC to Improve Your Email ReputationUsing DMARC to Improve Your Email Reputation
Using DMARC to Improve Your Email ReputationTerry Zink
 
Using Return Path Data to Protect Your Brand: Security Breakout Session - NYC
Using Return Path Data to Protect Your Brand: Security Breakout Session - NYCUsing Return Path Data to Protect Your Brand: Security Breakout Session - NYC
Using Return Path Data to Protect Your Brand: Security Breakout Session - NYCReturn Path
 
India VMUG Email Deliverability Deck.pptx
India VMUG Email Deliverability Deck.pptxIndia VMUG Email Deliverability Deck.pptx
India VMUG Email Deliverability Deck.pptxDarshil35
 
Safeguard Your Brand: Introducing yourDMARC's Advanced Email Security Solutions
Safeguard Your Brand: Introducing yourDMARC's Advanced Email Security SolutionsSafeguard Your Brand: Introducing yourDMARC's Advanced Email Security Solutions
Safeguard Your Brand: Introducing yourDMARC's Advanced Email Security SolutionsyourDMARC
 

Semelhante a Your Customers Need A Hero - Save Them From Internet Villains With DMARC (20)

Annual Scary Episode on What's Scaring Us for 2016
Annual Scary Episode on What's Scaring Us for 2016Annual Scary Episode on What's Scaring Us for 2016
Annual Scary Episode on What's Scaring Us for 2016
 
OWASP ATL - Social Engineering Technical Controls Presentation
OWASP ATL - Social Engineering Technical Controls PresentationOWASP ATL - Social Engineering Technical Controls Presentation
OWASP ATL - Social Engineering Technical Controls Presentation
 
Jak ochránit vaší značku a doménu s technologií DMARC
Jak ochránit vaší značku a doménu s technologií DMARCJak ochránit vaší značku a doménu s technologií DMARC
Jak ochránit vaší značku a doménu s technologií DMARC
 
.NET Developer Days 2015, PL: Defensive programming, resilience patterns & an...
.NET Developer Days 2015, PL: Defensive programming, resilience patterns & an....NET Developer Days 2015, PL: Defensive programming, resilience patterns & an...
.NET Developer Days 2015, PL: Defensive programming, resilience patterns & an...
 
Don't Get Phished!
Don't Get Phished!Don't Get Phished!
Don't Get Phished!
 
DMARC Overview
DMARC OverviewDMARC Overview
DMARC Overview
 
MD DevdDays 2016: Defensive programming, resilience patterns & antifragility
MD DevdDays 2016: Defensive programming, resilience patterns & antifragilityMD DevdDays 2016: Defensive programming, resilience patterns & antifragility
MD DevdDays 2016: Defensive programming, resilience patterns & antifragility
 
LCMC: Overcoming the barriers to deliverability
LCMC: Overcoming the barriers to deliverabilityLCMC: Overcoming the barriers to deliverability
LCMC: Overcoming the barriers to deliverability
 
2015 - Basta! 2015, DE: Defensive programming, resilience patterns & antifrag...
2015 - Basta! 2015, DE: Defensive programming, resilience patterns & antifrag...2015 - Basta! 2015, DE: Defensive programming, resilience patterns & antifrag...
2015 - Basta! 2015, DE: Defensive programming, resilience patterns & antifrag...
 
NRWConf, DE: Defensive programming, resilience patterns & antifragility
NRWConf, DE: Defensive programming, resilience patterns & antifragilityNRWConf, DE: Defensive programming, resilience patterns & antifragility
NRWConf, DE: Defensive programming, resilience patterns & antifragility
 
An Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsAn Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation Requirements
 
Fighting Email Abuse with DMARC
Fighting Email Abuse with DMARCFighting Email Abuse with DMARC
Fighting Email Abuse with DMARC
 
Neuailes Global Technologies Pvt Ltd
Neuailes Global Technologies Pvt LtdNeuailes Global Technologies Pvt Ltd
Neuailes Global Technologies Pvt Ltd
 
Getting into the Inbox
Getting into the InboxGetting into the Inbox
Getting into the Inbox
 
GoDMARC - Block Email Phishing
GoDMARC - Block Email PhishingGoDMARC - Block Email Phishing
GoDMARC - Block Email Phishing
 
Using DMARC to Improve Your Email Reputation
Using DMARC to Improve Your Email ReputationUsing DMARC to Improve Your Email Reputation
Using DMARC to Improve Your Email Reputation
 
Using Return Path Data to Protect Your Brand: Security Breakout Session - NYC
Using Return Path Data to Protect Your Brand: Security Breakout Session - NYCUsing Return Path Data to Protect Your Brand: Security Breakout Session - NYC
Using Return Path Data to Protect Your Brand: Security Breakout Session - NYC
 
India VMUG Email Deliverability Deck.pptx
India VMUG Email Deliverability Deck.pptxIndia VMUG Email Deliverability Deck.pptx
India VMUG Email Deliverability Deck.pptx
 
Safeguard Your Brand: Introducing yourDMARC's Advanced Email Security Solutions
Safeguard Your Brand: Introducing yourDMARC's Advanced Email Security SolutionsSafeguard Your Brand: Introducing yourDMARC's Advanced Email Security Solutions
Safeguard Your Brand: Introducing yourDMARC's Advanced Email Security Solutions
 
Deliverability
DeliverabilityDeliverability
Deliverability
 

Último

Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Callshivangimorya083
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Standkumarajju5765
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.soniya singh
 
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...SofiyaSharma5
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Servicegwenoracqe6
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Delhi Call girls
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024APNIC
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...Diya Sharma
 
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663Call Girls Mumbai
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445ruhi
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)Delhi Call girls
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...singhpriety023
 

Último (20)

Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
 
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
 
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
 
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
✂️ 👅 Independent Andheri Escorts With Room Vashi Call Girls 💃 9004004663
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
 
@9999965857 🫦 Sexy Desi Call Girls Laxmi Nagar 💓 High Profile Escorts Delhi 🫶
@9999965857 🫦 Sexy Desi Call Girls Laxmi Nagar 💓 High Profile Escorts Delhi 🫶@9999965857 🫦 Sexy Desi Call Girls Laxmi Nagar 💓 High Profile Escorts Delhi 🫶
@9999965857 🫦 Sexy Desi Call Girls Laxmi Nagar 💓 High Profile Escorts Delhi 🫶
 
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
 

Your Customers Need A Hero - Save Them From Internet Villains With DMARC

  • 1. Your Customers Need A Hero Save them from Internet Villains with DMARC
  • 2. About the Speaker • Email’s been my arch nemesis for 14 years • Implemented DMARC for 128 domains in 7 months • I’ve been saying, “Email is the worst thing ever” for 10 years
  • 3. Agenda • Our Customers’ inboxes are under attack. They need a hero. • How do YOU become a DMARC hero? • Getting your first victories. • What will stand in your way? • Know your weaknesses.
  • 4.
  • 5. WHO WILL HELP IN OUR HOUR OF NEED?
  • 6. What is DMARC? No DMARC, 23 Monitor, 13 Quarantine, 1 Reject, 1 FORTUNE 500 HEALTH CARE SECTOR NOV. 2017 • Email authentication via DNS • What can it do? • Email blocking • DMARC policies can stop bad emails pretending to be from you. • Provides insight into BEC • You can see IPs that are trying to send emails with your brand. • Establishes Brand Assurance • Your customers can be assured that they’re safe emailing with you. To Start, read this: • https://seanthegeek.net/459/ demystifying-dmarc/ Reject & Quarantine 10.5% None 34.9% Invalid DMARC 3.6% No DMARC 51% TECHNOLOGY INDUSTRY 2019 Source: @Valimail Source: @AgariInc
  • 7. But it should be. • You gain control of your email brand. • It’s FREE • It’s easy to start and maintain. • Marketing teams will see increases in delivery. So why isn’t DMARC everywhere? • Email is a utility. • DMARC’s not a sexy topic. • And it’s not the squeakiest wheel.
  • 8. • You need a place to receive DMARC Reports: Then the Telemetry comes to you! • Put up the _DMARC entry in “Monitor” mode. (p=none) • Once you know who’s trying to send email as your brand, form a plan. • Save the metrics for POV later! GEAR UP
  • 9. Where can you analyze your DMARC Reports? FREE! Hosted Services • Postmark; dmarcian; DMARC Analyzer… DIY • Parsedmarc by Sean Whalen https://domainaware.github.io/ parsedmarc/ BUY A SIDEKICK! • You can staff-augment to quickly onboard knowledge and assist with monitoring post-implementation. • Folks like Agari, dmarcian, Valimail, and Proofpoint (to name a few) have sidekicks standing by! Visit https://dmarc.org/resources/products-and-services/ for more!
  • 10. Superhero Training Montage Find your defensively registered & non sending domains and set them to reject! Your first victories! Find your most spoofed domain and show how the Reject posture was successful. Work in the shadows for now.
  • 11. • No one else sends emails on your behalf? • Only use one email hosting provider? • Set up SPF/DKIM and monitor for a month. • Then you’re ready to p=reject! • You’re DONE! You may then safely ignore the rest of this presentation. Or read on just for fun! You may be super close to being done!
  • 13. The easy part’s over… • Carefully review telemetry from your sending domains. • Enumerate your EaaS vendors – [Engage your Third-party cyber risk Hero back at the “Hall of Justice” if you’ve got one] • Add their SPF & DKIM info to your DNS and grow stronger • Use your CNAME Kung–FU for lots of defensively registered domains
  • 14. Who are the villains that will stop at nothing to destroy your initiative? …the battle’s just begun.
  • 15. • Multiple DNS TXT records • More than 10 SPF Lookups • DKIM Record typos CONFUZOR a.com IN TXT v=spf1 –all a.com IN TXT v=spf1 include:spf.stuff.com ~all
  • 16. • Tracking down multi-national or BU EaaS affiliations • Tracking down Business Cycle Specific Emails THE SNEAK
  • 17. • EaaS vendors who issue SOWs or charge extra to support DMARC for your domains. NICKEL & DIME
  • 18. • Bad code that will cause your DMARC evaluations to fail. • Usually DKIM related • DMARC Telemetry system Failures SABOTAGE
  • 19. • Bad email practices from within. YOUR OWN ORGANIZATION
  • 20. Where will DMARC not help? • Misspelled Domains • Compromised partner email accounts • LISTSRV & Other assorted email hops Know Your Weaknesses What can help you Save the world? • Centralize your Mail Flow • Leverage Subdomains or… • …Use Vanity Domains Use your powers
  • 21. • Take an iterative approach. Move domains to reject as soon as you can; show the benefits when malicious use is blocked or drops to zero for that domain. • Headlines in the News: Tell everyone you’re protecting your members directly, not just mitigating business risks. • Constant Vigilance: Get DMARC into your standards, policies, and business use cases. Get your marketing and corp comm teams familiar with DMARC, why it’s important and how it benefits their delivery rates. A Hero’s Work is Never Done
  • 22. What’s that in the sky?! A bird? A plane? It’s BIMI! • After you get to p=reject. • Your logo will appear next to your emails in your customers’ inboxes. • In beta • Requires rights to use a logo and (after go-live) a cert to prove that you own the logo. • https://authindicators.github.io/rfc -brand-indicators-for-message- identification/ • Microsoft is doing their own thing: • https://business.microsoft.com/ Image Source: Yahoo! Mail
  • 23. Our Members deserve trustworthy communications. Start with the easy wins; iterate; don’t let up. Laughing about fictitious comic book villains will help you have fun implementing DMARC.
  • 24. Be the hero! Email me: info@steveocodez.com
  • 25. © 2019 Stephen Mitchell and Matthew Bielewicz. Except where otherwise noted,“Your Customers Need A Hero - Save Them From Internet Villains With DMARC” is licensed under a Creative Commons Attribution 4.0 International License. http://creativecommons.org/licenses/by/4.0/