#email-security — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #email-security, aggregated by home.social.
-
Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.
#Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)
-
Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.
#Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)
-
Microsofts utvecklare försöker nu hitta en lösning på problemet.#Windows #OperatingSystems #EmailSecurity #CommunicationsSecurity #NetworkSecurity #Security
Bugg i Exchange Online kan göra att dina mejl hamnar i karantän -
Microsofts utvecklare försöker nu hitta en lösning på problemet.#Windows #OperatingSystems #EmailSecurity #CommunicationsSecurity #NetworkSecurity #Security
Bugg i Exchange Online kan göra att dina mejl hamnar i karantän -
Apple says a July 3 patch fully closes the Hide My Email vulnerability that exposed real iCloud+ addresses for over a year after disclosure.
#Apple #iCloud #HideMyEmail #Privacy #EmailSecurity #InfoSec
-
Apple says a July 3 patch fully closes the Hide My Email vulnerability that exposed real iCloud+ addresses for over a year after disclosure.
#Apple #iCloud #HideMyEmail #Privacy #EmailSecurity #InfoSec
-
Apple says a July 3 patch fully closes the Hide My Email vulnerability that exposed real iCloud+ addresses for over a year after disclosure.
#Apple #iCloud #HideMyEmail #Privacy #EmailSecurity #InfoSec
-
Apple says a July 3 patch fully closes the Hide My Email vulnerability that exposed real iCloud+ addresses for over a year after disclosure.
#Apple #iCloud #HideMyEmail #Privacy #EmailSecurity #InfoSec
-
Apple says a July 3 patch fully closes the Hide My Email vulnerability that exposed real iCloud+ addresses for over a year after disclosure.
#Apple #iCloud #HideMyEmail #Privacy #EmailSecurity #InfoSec
-
Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. https://hackernoon.com/two-thirds-of-the-top-million-domains-can-still-be-spoofed #emailsecurity
-
Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. https://hackernoon.com/two-thirds-of-the-top-million-domains-can-still-be-spoofed #emailsecurity
-
Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. https://hackernoon.com/two-thirds-of-the-top-million-domains-can-still-be-spoofed #emailsecurity
-
Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. https://hackernoon.com/two-thirds-of-the-top-million-domains-can-still-be-spoofed #emailsecurity
-
Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. https://hackernoon.com/two-thirds-of-the-top-million-domains-can-still-be-spoofed #emailsecurity
-
Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️🔗 https://mashable.com/tech/apple-hide-my-email-major-vulnerability-leaks-email-addresses
#TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security
-
Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️🔗 https://mashable.com/tech/apple-hide-my-email-major-vulnerability-leaks-email-addresses
#TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security
-
Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️🔗 https://mashable.com/tech/apple-hide-my-email-major-vulnerability-leaks-email-addresses
#TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security
-
Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️🔗 https://mashable.com/tech/apple-hide-my-email-major-vulnerability-leaks-email-addresses
#TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security
-
Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️🔗 https://mashable.com/tech/apple-hide-my-email-major-vulnerability-leaks-email-addresses
#TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security
-
https://www.europesays.com/dk/128576/ Fastmail opens Amsterdam data centre for EU email users #Amsterdam #Australian #BigTech #BusinessContinuity #Cybersecurity #Data/Privacy #DataCenters(DC) #DataHosting #DataLocalisation #DataProtection #DataResidency #DataSovereignty #DataStrategy #DataTransfer #DevOps #DigitalSovereignty #EmailSecurity #EuropeanUnion(EU) #GeneralDataProtectionRegulation(GDPR) #India #InformationGovernance #ITDepartment #ITGovernance #Netherlands
-
SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.
Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.
https://cryptolab.re/posts/2026/antispoofing-email-spf-dkim-dmarc-guide/
-
SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.
Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.
https://cryptolab.re/posts/2026/antispoofing-email-spf-dkim-dmarc-guide/
-
SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.
Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.
https://cryptolab.re/posts/2026/antispoofing-email-spf-dkim-dmarc-guide/
-
SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.
Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.
https://cryptolab.re/posts/2026/antispoofing-email-spf-dkim-dmarc-guide/
-
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.
Full post: https://graylog.org/post/unlock-email-threat-visibility-with-mimecast-and-graylog/
#Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife -
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.
Full post: https://graylog.org/post/unlock-email-threat-visibility-with-mimecast-and-graylog/
#Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife -
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.
Full post: https://graylog.org/post/unlock-email-threat-visibility-with-mimecast-and-graylog/
#Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife -
New by me: CybersecKyle Security How-To Series: Power User and Small Team, Part 2 - Email Security with SPF, DKIM, and DMARC
#Cybersecurity #InfoSec #EmailSecurity #DMARC #CybersecKyleHowTo
-
New by me: CybersecKyle Security How-To Series: Power User and Small Team, Part 2 - Email Security with SPF, DKIM, and DMARC
#Cybersecurity #InfoSec #EmailSecurity #DMARC #CybersecKyleHowTo
-
New by me: CybersecKyle Security How-To Series: Power User and Small Team, Part 2 - Email Security with SPF, DKIM, and DMARC
#Cybersecurity #InfoSec #EmailSecurity #DMARC #CybersecKyleHowTo
-
🚀 Wow, #DKIM2 and #DMARCbis have "landed" like a spaceship nobody asked for, and Stalwart is apparently fluent in their alien language! 🤖 Meanwhile, mere mortals are left sifting through a jumble of buzzwords and tech jargon, wondering why email security always feels like deciphering a tech bro's gibberish bingo card. 🎉
https://stalw.art/blog/dkim2-dmarcbis/ #emailsecurity #techjargon #cybersecurity #HackerNews #ngated -
🚀 Wow, #DKIM2 and #DMARCbis have "landed" like a spaceship nobody asked for, and Stalwart is apparently fluent in their alien language! 🤖 Meanwhile, mere mortals are left sifting through a jumble of buzzwords and tech jargon, wondering why email security always feels like deciphering a tech bro's gibberish bingo card. 🎉
https://stalw.art/blog/dkim2-dmarcbis/ #emailsecurity #techjargon #cybersecurity #HackerNews #ngated -
🚀 Wow, #DKIM2 and #DMARCbis have "landed" like a spaceship nobody asked for, and Stalwart is apparently fluent in their alien language! 🤖 Meanwhile, mere mortals are left sifting through a jumble of buzzwords and tech jargon, wondering why email security always feels like deciphering a tech bro's gibberish bingo card. 🎉
https://stalw.art/blog/dkim2-dmarcbis/ #emailsecurity #techjargon #cybersecurity #HackerNews #ngated -
Why DMARC's new "NP" tag can fail with DNSSEC
https://dmarcwise.io/blog/dmarc-np-incompatibility-with-dnssec
#HackerNews #DMARC #DNSSEC #NPtag #cybersecurity #emailsecurity
-
Why DMARC's new "NP" tag can fail with DNSSEC
https://dmarcwise.io/blog/dmarc-np-incompatibility-with-dnssec
#HackerNews #DMARC #DNSSEC #NPtag #cybersecurity #emailsecurity
-
Why DMARC's new "NP" tag can fail with DNSSEC
https://dmarcwise.io/blog/dmarc-np-incompatibility-with-dnssec
#HackerNews #DMARC #DNSSEC #NPtag #cybersecurity #emailsecurity
-
Your email account is the key to almost everything.
If someone gains access to it, they can often reset passwords for many of your other accounts.
That's why securing your email should be one of the first things you do.
📖 Lesson 6: https://error-404.cc/en/digital-privacy-security/start-here/lesson-6-email-security/
#DigitalHygiene #Privacy #OnlineSafety #EmailSecurity #mastodon #Fediverse #infosec
-
Your email account is the key to almost everything.
If someone gains access to it, they can often reset passwords for many of your other accounts.
That's why securing your email should be one of the first things you do.
📖 Lesson 6: https://error-404.cc/en/digital-privacy-security/start-here/lesson-6-email-security/
#DigitalHygiene #Privacy #OnlineSafety #EmailSecurity #mastodon #Fediverse #infosec
-
Your email account is the key to almost everything.
If someone gains access to it, they can often reset passwords for many of your other accounts.
That's why securing your email should be one of the first things you do.
📖 Lesson 6: https://error-404.cc/en/digital-privacy-security/start-here/lesson-6-email-security/
#DigitalHygiene #Privacy #OnlineSafety #EmailSecurity #mastodon #Fediverse #infosec
-
Ich habe ein kleines Thunderbird-Add-on gebaut: External Mail Guard.
Es markiert externe oder nicht eindeutig verifizierte Absender automatisch mit dem Tag „external“ und zeigt beim Öffnen eine Warnung an. Hilfreich gegen Phishing, Spoofing und versehentliche Verwechslungen zwischen internen und externen Mails.
Läuft lokal in Thunderbird, ohne Tracking, ohne Telemetrie.
Feedback willkommen:
https://addons.thunderbird.net/de/thunderbird/addon/external-mail-guard/ -
FBI IC3 reported $2.77B in business email compromise losses in 2024
BEC works because attackers impersonate trusted domains
DMARC at enforcement makes exact-domain spoofing fail
it doesn't stop all BEC
lookalike domains and compromised accounts are separate problems
but it eliminates the most common vector
every dollar spent on DMARC monitoring returns multiples in prevented impersonation
-
FBI IC3 reported $2.77B in business email compromise losses in 2024
BEC works because attackers impersonate trusted domains
DMARC at enforcement makes exact-domain spoofing fail
it doesn't stop all BEC
lookalike domains and compromised accounts are separate problems
but it eliminates the most common vector
every dollar spent on DMARC monitoring returns multiples in prevented impersonation
-
30.4% adoption vs. 12.8% enforcement: the DMARC gap
of 5.5M domains I scanned, 30.4% have a DMARC record
only 12.8% are at p=quarantine or p=reject
that means 57.9% of domains "doing DMARC" aren't actually enforcing it
they're collecting reports they probably aren't reading, some aren't even monitoring it at all!
a DMARC record at p=none is a monitoring declaration, not a security control
-
30.4% adoption vs. 12.8% enforcement: the DMARC gap
of 5.5M domains I scanned, 30.4% have a DMARC record
only 12.8% are at p=quarantine or p=reject
that means 57.9% of domains "doing DMARC" aren't actually enforcing it
they're collecting reports they probably aren't reading, some aren't even monitoring it at all!
a DMARC record at p=none is a monitoring declaration, not a security control
-
RFC 6376 doesn't mandate rotation frequency, but best practice is every 6-12 months
unlike passwords, DKIM keys don't get brute-forced
they get extracted from breached servers or leaked configs
rotation limits the blast radius
the process:
1. publish new selector
2. update ESP signing config
3. verify via DMARC reports
4. remove old selector after TTL expiryDMARCguard flags selectors that haven't rotated in 12+ months
-
RFC 6376 doesn't mandate rotation frequency, but best practice is every 6-12 months
unlike passwords, DKIM keys don't get brute-forced
they get extracted from breached servers or leaked configs
rotation limits the blast radius
the process:
1. publish new selector
2. update ESP signing config
3. verify via DMARC reports
4. remove old selector after TTL expiryDMARCguard flags selectors that haven't rotated in 12+ months
-
NIS2 + DANE: the compliance angle nobody's discussing
NIS2 requires "appropriate and proportionate" measures for network and information system security, including encryption in transit
DANE (RFC 7672) provides cryptographic verification that your mail server's TLS certificate is authentic
for organizations in-scope for NIS2, DANE isn't optional hardening
It's a defensible technical measure for transport security
-
NIS2 + DANE: the compliance angle nobody's discussing
NIS2 requires "appropriate and proportionate" measures for network and information system security, including encryption in transit
DANE (RFC 7672) provides cryptographic verification that your mail server's TLS certificate is authentic
for organizations in-scope for NIS2, DANE isn't optional hardening
It's a defensible technical measure for transport security
-
thank you to everyone who's tested the tools
thousands of domain checks through our free tools in the past few weeks
every check that surfaces a misconfigured SPF record or a missing DMARC policy is a small win
some of you have emailed me directly with questions
if you've been using the tools and found value, I'd genuinely appreciate you sharing them with a colleague who manages domains
-
thank you to everyone who's tested the tools
thousands of domain checks through our free tools in the past few weeks
every check that surfaces a misconfigured SPF record or a missing DMARC policy is a small win
some of you have emailed me directly with questions
if you've been using the tools and found value, I'd genuinely appreciate you sharing them with a colleague who manages domains
-
domains with SPF+DKIM+DMARC at enforcement see 2.7x better inbox delivery compared to unauthenticated domains
this number is aggregated across deliverability studies and consistent with what I see in report data
mailbox providers use authentication signals in their spam scoring
full auth doesn't guarantee the inbox, but missing auth almost guarantees the spam folder
-
domains with SPF+DKIM+DMARC at enforcement see 2.7x better inbox delivery compared to unauthenticated domains
this number is aggregated across deliverability studies and consistent with what I see in report data
mailbox providers use authentication signals in their spam scoring
full auth doesn't guarantee the inbox, but missing auth almost guarantees the spam folder