home.social

#email-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #email-security, aggregated by home.social.

fetched live
  1. Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.

    #Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)

  2. Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.

    #Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)

  3. Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. hackernoon.com/two-thirds-of-t #emailsecurity

  4. Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. hackernoon.com/two-thirds-of-t #emailsecurity

  5. Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. hackernoon.com/two-thirds-of-t #emailsecurity

  6. Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. hackernoon.com/two-thirds-of-t

  7. Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. hackernoon.com/two-thirds-of-t #emailsecurity

  8. People with businesses & others. FIX YOUR EMAILS! DKIM, DMARC, and SPF aren't options... You end up in JUNK, or, in a lot of cases, NEVER SEEN / BLOCKED. Wonder why you never get any replies... Seriously. Fix your domain records. FUCK!

    #Tech #Internet #Email #Security #Junk #Junkmail #EmailSecurity

  9. People with businesses & others. FIX YOUR EMAILS! DKIM, DMARC, and SPF aren't options... You end up in JUNK, or, in a lot of cases, NEVER SEEN / BLOCKED. Wonder why you never get any replies... Seriously. Fix your domain records. FUCK!

    #Tech #Internet #Email #Security #Junk #Junkmail #EmailSecurity

  10. People with businesses & others. FIX YOUR EMAILS! DKIM, DMARC, and SPF aren't options... You end up in JUNK, or, in a lot of cases, NEVER SEEN / BLOCKED. Wonder why you never get any replies... Seriously. Fix your domain records. FUCK!

    #Tech #Internet #Email #Security #Junk #Junkmail #EmailSecurity

  11. People with businesses & others. FIX YOUR EMAILS! DKIM, DMARC, and SPF aren't options... You end up in JUNK, or, in a lot of cases, NEVER SEEN / BLOCKED. Wonder why you never get any replies... Seriously. Fix your domain records. FUCK!

    #Tech #Internet #Email #Security #Junk #Junkmail #EmailSecurity

  12. People with businesses & others. FIX YOUR EMAILS! DKIM, DMARC, and SPF aren't options... You end up in JUNK, or, in a lot of cases, NEVER SEEN / BLOCKED. Wonder why you never get any replies... Seriously. Fix your domain records. FUCK!

    #Tech #Internet #Email #Security #Junk #Junkmail #EmailSecurity

  13. Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
    Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️

    🔗 mashable.com/tech/apple-hide-m

    #TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security

  14. Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
    Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️

    🔗 mashable.com/tech/apple-hide-m

    #TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security

  15. Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
    Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️

    🔗 mashable.com/tech/apple-hide-m

    #TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security

  16. Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
    Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️

    🔗 mashable.com/tech/apple-hide-m

    #TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security

  17. Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
    Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️

    🔗 mashable.com/tech/apple-hide-m

    #TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security

  18. SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.

    Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.

    cryptolab.re/posts/2026/antisp

    #EmailSecurity #DMARC #DKIM #SPF

  19. SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.

    Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.

    cryptolab.re/posts/2026/antisp

    #EmailSecurity #DMARC #DKIM #SPF

  20. SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.

    Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.

    cryptolab.re/posts/2026/antisp

    #EmailSecurity #DMARC #DKIM #SPF

  21. SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.

    Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.

    cryptolab.re/posts/2026/antisp

    #EmailSecurity #DMARC #DKIM #SPF

  22. Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
    With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.

    New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.

    Full post: graylog.org/post/unlock-email-
    #Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife

  23. Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
    With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.

    New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.

    Full post: graylog.org/post/unlock-email-
    #Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife

  24. Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
    With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.

    New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.

    Full post: graylog.org/post/unlock-email-
    #Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife

  25. 🚀 Wow, #DKIM2 and #DMARCbis have "landed" like a spaceship nobody asked for, and Stalwart is apparently fluent in their alien language! 🤖 Meanwhile, mere mortals are left sifting through a jumble of buzzwords and tech jargon, wondering why email security always feels like deciphering a tech bro's gibberish bingo card. 🎉
    stalw.art/blog/dkim2-dmarcbis/ #emailsecurity #techjargon #cybersecurity #HackerNews #ngated

  26. 🚀 Wow, #DKIM2 and #DMARCbis have "landed" like a spaceship nobody asked for, and Stalwart is apparently fluent in their alien language! 🤖 Meanwhile, mere mortals are left sifting through a jumble of buzzwords and tech jargon, wondering why email security always feels like deciphering a tech bro's gibberish bingo card. 🎉
    stalw.art/blog/dkim2-dmarcbis/ #emailsecurity #techjargon #cybersecurity #HackerNews #ngated

  27. 🚀 Wow, #DKIM2 and #DMARCbis have "landed" like a spaceship nobody asked for, and Stalwart is apparently fluent in their alien language! 🤖 Meanwhile, mere mortals are left sifting through a jumble of buzzwords and tech jargon, wondering why email security always feels like deciphering a tech bro's gibberish bingo card. 🎉
    stalw.art/blog/dkim2-dmarcbis/ #emailsecurity #techjargon #cybersecurity #HackerNews #ngated

  28. Your email account is the key to almost everything.

    If someone gains access to it, they can often reset passwords for many of your other accounts.

    That's why securing your email should be one of the first things you do.

    📖 Lesson 6: error-404.cc/en/digital-privac

    #DigitalHygiene #Privacy #OnlineSafety #EmailSecurity #mastodon #Fediverse #infosec

  29. Your email account is the key to almost everything.

    If someone gains access to it, they can often reset passwords for many of your other accounts.

    That's why securing your email should be one of the first things you do.

    📖 Lesson 6: error-404.cc/en/digital-privac

    #DigitalHygiene #Privacy #OnlineSafety #EmailSecurity #mastodon #Fediverse #infosec

  30. Your email account is the key to almost everything.

    If someone gains access to it, they can often reset passwords for many of your other accounts.

    That's why securing your email should be one of the first things you do.

    📖 Lesson 6: error-404.cc/en/digital-privac

    #DigitalHygiene #Privacy #OnlineSafety #EmailSecurity #mastodon #Fediverse #infosec

  31. Ich habe ein kleines Thunderbird-Add-on gebaut: External Mail Guard.

    Es markiert externe oder nicht eindeutig verifizierte Absender automatisch mit dem Tag „external“ und zeigt beim Öffnen eine Warnung an. Hilfreich gegen Phishing, Spoofing und versehentliche Verwechslungen zwischen internen und externen Mails.

    Läuft lokal in Thunderbird, ohne Tracking, ohne Telemetrie.

    Feedback willkommen:
    addons.thunderbird.net/de/thun

    #Thunderbird #OpenSource #EmailSecurity #Phishing #Privacy

  32. FBI IC3 reported $2.77B in business email compromise losses in 2024

    BEC works because attackers impersonate trusted domains

    DMARC at enforcement makes exact-domain spoofing fail

    it doesn't stop all BEC

    lookalike domains and compromised accounts are separate problems

    but it eliminates the most common vector

    every dollar spent on DMARC monitoring returns multiples in prevented impersonation

    dmarcguard.io/learn/dmarc/

    #DMARC #EmailSecurity #BEC #FraudPrevention

  33. FBI IC3 reported $2.77B in business email compromise losses in 2024

    BEC works because attackers impersonate trusted domains

    DMARC at enforcement makes exact-domain spoofing fail

    it doesn't stop all BEC

    lookalike domains and compromised accounts are separate problems

    but it eliminates the most common vector

    every dollar spent on DMARC monitoring returns multiples in prevented impersonation

    dmarcguard.io/learn/dmarc/

    #DMARC #EmailSecurity #BEC #FraudPrevention

  34. 30.4% adoption vs. 12.8% enforcement: the DMARC gap

    of 5.5M domains I scanned, 30.4% have a DMARC record

    only 12.8% are at p=quarantine or p=reject

    that means 57.9% of domains "doing DMARC" aren't actually enforcing it

    they're collecting reports they probably aren't reading, some aren't even monitoring it at all!

    a DMARC record at p=none is a monitoring declaration, not a security control

    dmarcguard.io/research/email-a

    #DMARC #EmailSecurity #CyberResearch

  35. 30.4% adoption vs. 12.8% enforcement: the DMARC gap

    of 5.5M domains I scanned, 30.4% have a DMARC record

    only 12.8% are at p=quarantine or p=reject

    that means 57.9% of domains "doing DMARC" aren't actually enforcing it

    they're collecting reports they probably aren't reading, some aren't even monitoring it at all!

    a DMARC record at p=none is a monitoring declaration, not a security control

    dmarcguard.io/research/email-a

    #DMARC #EmailSecurity #CyberResearch

  36. RFC 6376 doesn't mandate rotation frequency, but best practice is every 6-12 months

    unlike passwords, DKIM keys don't get brute-forced

    they get extracted from breached servers or leaked configs

    rotation limits the blast radius

    the process:

    1. publish new selector
    2. update ESP signing config
    3. verify via DMARC reports
    4. remove old selector after TTL expiry

    DMARCguard flags selectors that haven't rotated in 12+ months

    dmarcguard.io/learn/dkim/

    #DMARC #EmailSecurity #DKIM

  37. RFC 6376 doesn't mandate rotation frequency, but best practice is every 6-12 months

    unlike passwords, DKIM keys don't get brute-forced

    they get extracted from breached servers or leaked configs

    rotation limits the blast radius

    the process:

    1. publish new selector
    2. update ESP signing config
    3. verify via DMARC reports
    4. remove old selector after TTL expiry

    DMARCguard flags selectors that haven't rotated in 12+ months

    dmarcguard.io/learn/dkim/

    #DMARC #EmailSecurity #DKIM

  38. NIS2 + DANE: the compliance angle nobody's discussing

    NIS2 requires "appropriate and proportionate" measures for network and information system security, including encryption in transit

    DANE (RFC 7672) provides cryptographic verification that your mail server's TLS certificate is authentic

    for organizations in-scope for NIS2, DANE isn't optional hardening

    It's a defensible technical measure for transport security

    dmarcguard.io/learn/dane/

    #DMARC #EmailSecurity #NIS2 #DANE

  39. NIS2 + DANE: the compliance angle nobody's discussing

    NIS2 requires "appropriate and proportionate" measures for network and information system security, including encryption in transit

    DANE (RFC 7672) provides cryptographic verification that your mail server's TLS certificate is authentic

    for organizations in-scope for NIS2, DANE isn't optional hardening

    It's a defensible technical measure for transport security

    dmarcguard.io/learn/dane/

    #DMARC #EmailSecurity #NIS2 #DANE

  40. thank you to everyone who's tested the tools

    thousands of domain checks through our free tools in the past few weeks

    every check that surfaces a misconfigured SPF record or a missing DMARC policy is a small win

    some of you have emailed me directly with questions

    if you've been using the tools and found value, I'd genuinely appreciate you sharing them with a colleague who manages domains

    dmarcguard.io/tools/

    #DMARC #EmailSecurity #BootstrappedStartup #Community

  41. thank you to everyone who's tested the tools

    thousands of domain checks through our free tools in the past few weeks

    every check that surfaces a misconfigured SPF record or a missing DMARC policy is a small win

    some of you have emailed me directly with questions

    if you've been using the tools and found value, I'd genuinely appreciate you sharing them with a colleague who manages domains

    dmarcguard.io/tools/

    #DMARC #EmailSecurity #BootstrappedStartup #Community

  42. domains with SPF+DKIM+DMARC at enforcement see 2.7x better inbox delivery compared to unauthenticated domains

    this number is aggregated across deliverability studies and consistent with what I see in report data

    mailbox providers use authentication signals in their spam scoring

    full auth doesn't guarantee the inbox, but missing auth almost guarantees the spam folder

    dmarcguard.io/tools/domain-hea

    #DMARC #EmailSecurity #EmailDeliverability #InboxPlacement

  43. domains with SPF+DKIM+DMARC at enforcement see 2.7x better inbox delivery compared to unauthenticated domains

    this number is aggregated across deliverability studies and consistent with what I see in report data

    mailbox providers use authentication signals in their spam scoring

    full auth doesn't guarantee the inbox, but missing auth almost guarantees the spam folder

    dmarcguard.io/tools/domain-hea

    #DMARC #EmailSecurity #EmailDeliverability #InboxPlacement