#emailsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #emailsecurity, aggregated by home.social.
-
📰 Oculus Pathology Breach Exposes Patient Data via Email Hack
Oculus Pathology discloses a data breach after employee email accounts were compromised in April 2026. The incident potentially exposed patient PII, PHI, SSNs, and medical diagnoses. #DataBreach #Healthcare #HIPAA #EmailSecurity
-
📰 Oculus Pathology Breach Exposes Patient Data via Email Hack
Oculus Pathology discloses a data breach after employee email accounts were compromised in April 2026. The incident potentially exposed patient PII, PHI, SSNs, and medical diagnoses. #DataBreach #Healthcare #HIPAA #EmailSecurity
-
Scammers are chaining forgotten CNAMEs to create fully authenticated phishing firehoses. Valid crypto means nothing when the pipes are rotten.
https://andreklein.net/dns-debt-how-phishing-campaigns-pass-dkim-without-hacking-anything/
-
Scammers are chaining forgotten CNAMEs to create fully authenticated phishing firehoses. Valid crypto means nothing when the pipes are rotten.
https://andreklein.net/dns-debt-how-phishing-campaigns-pass-dkim-without-hacking-anything/
-
pmg-userprefs-sync is now public
📬 We have published pmg-userprefs-sync:
https://code.awit.at/D3/pmg-userprefs-syncThis small tool keeps per-user welcome/block lists from quarantine digests in sync across two standalone Proxmox Mail Gateways. A recipient’s decision therefore applies regardless of which equal-priority MX receives the next message.
The design is deliberately restrictive:
- Read peer data only through the PMG API with an Auditor role
- Write changes only locally via pmgsh
- Add-only: no automatic removals and no data loss
- No PMG cluster, no pmgcm, and no SSH between gateways
- Dry-run is the safe default; the systemd timer is optionalIt deliberately does not synchronise filter rules, transports, TLS policies, spam scores, or quarantine contents. Those are separate concerns with different risks.
Tested with PMG 9.1.2 across two production gateways. 🔧
#Proxmox #ProxmoxMailGateway #PMG #Mailserver #SelfHosting #OpenSource #Linux #Sysadmin #DevOps #EmailSecurity #AGPL
-
pmg-userprefs-sync ist jetzt öffentlich
📬 Wir haben pmg-userprefs-sync veröffentlicht:
https://code.awit.at/D3/pmg-userprefs-syncDas kleine Tool hält auf zwei unabhängigen Proxmox Mail Gateways die persönlichen Welcome-/Blocklisten aus den Quarantäne-Digests synchron. So wirkt die Entscheidung eines Empfängers unabhängig davon, über welchen gleichpriorisierten MX die nächste Mail ankommt.
Der Ansatz ist bewusst restriktiv:
- Peer-Daten nur lesend über die PMG-API mit Auditor-Rolle
- Änderungen ausschließlich lokal über pmgsh
- add-only: keine automatischen Löschungen, kein Datenverlust
- kein PMG-Cluster, kein pmgcm, kein SSH zwischen den Gateways
- Dry-run als sicherer Standard, systemd-Timer optionalNicht synchronisiert werden Filterregeln, Transports, TLS-Policies, Spam-Scores oder Quarantäne-Inhalte. Das sind bewusst getrennte Themen mit anderen Risiken.
Getestet mit PMG 9.1.2 auf zwei produktiven Gateways. 🔧
#Proxmox #ProxmoxMailGateway #PMG #Mailserver #SelfHosting #OpenSource #Linux #Sysadmin #DevOps #EmailSecurity #AGPL
-
pmg-userprefs-sync ist jetzt öffentlich
📬 Wir haben pmg-userprefs-sync veröffentlicht:
https://code.awit.at/D3/pmg-userprefs-syncDas kleine Tool hält auf zwei unabhängigen Proxmox Mail Gateways die persönlichen Welcome-/Blocklisten aus den Quarantäne-Digests synchron. So wirkt die Entscheidung eines Empfängers unabhängig davon, über welchen gleichpriorisierten MX die nächste Mail ankommt.
Der Ansatz ist bewusst restriktiv:
- Peer-Daten nur lesend über die PMG-API mit Auditor-Rolle
- Änderungen ausschließlich lokal über pmgsh
- add-only: keine automatischen Löschungen, kein Datenverlust
- kein PMG-Cluster, kein pmgcm, kein SSH zwischen den Gateways
- Dry-run als sicherer Standard, systemd-Timer optionalNicht synchronisiert werden Filterregeln, Transports, TLS-Policies, Spam-Scores oder Quarantäne-Inhalte. Das sind bewusst getrennte Themen mit anderen Risiken.
Getestet mit PMG 9.1.2 auf zwei produktiven Gateways. 🔧
#Proxmox #ProxmoxMailGateway #PMG #Mailserver #SelfHosting #OpenSource #Linux #Sysadmin #DevOps #EmailSecurity #AGPL
-
Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections.
Most teams treat that as noise. It's early-warning threat telemetry.
The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically.
-
Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections.
Most teams treat that as noise. It's early-warning threat telemetry.
The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically.
-
Oh, look! Another thrilling tale about #DMARC, saving us from emails we never wanted and threats we don’t understand 🙄. But don't worry—this article manages to make email security as riveting as watching paint dry while they shamelessly plug their product 🤦♂️. Spoiler: It won’t protect you from bad writing! 📧🔒
https://senderledger.com/articles/what-dmarc-actually-protects-you-from #EmailSecurity #CyberThreats #ProductPlug #EmailSafety #HackerNews #ngated -
Oh, look! Another thrilling tale about #DMARC, saving us from emails we never wanted and threats we don’t understand 🙄. But don't worry—this article manages to make email security as riveting as watching paint dry while they shamelessly plug their product 🤦♂️. Spoiler: It won’t protect you from bad writing! 📧🔒
https://senderledger.com/articles/what-dmarc-actually-protects-you-from #EmailSecurity #CyberThreats #ProductPlug #EmailSafety #HackerNews #ngated -
What DMARC Protects You From, and What It Does Not
https://senderledger.com/articles/what-dmarc-actually-protects-you-from
Comments: https://news.ycombinator.com/item?id=49153361
#HackerNews #DMARC #EmailSecurity #CyberThreats #EmailAuthentication #InternetSafety
-
What DMARC Protects You From, and What It Does Not
https://senderledger.com/articles/what-dmarc-actually-protects-you-from
Comments: https://news.ycombinator.com/item?id=49153361
#HackerNews #DMARC #EmailSecurity #CyberThreats #EmailAuthentication #InternetSafety
-
Far to the north in Norway, we protect your email from viruses, harmful attachments, spam, and malicious scripts. 🇳🇴
👉 https://runbox.com/features/privacy-security/
#Emailsecurity #Security #Privacy #Runbox #Norway #European #Email #Degoogle
-
Far to the north in Norway, we protect your email from viruses, harmful attachments, spam, and malicious scripts. 🇳🇴
👉 https://runbox.com/features/privacy-security/
#Emailsecurity #Security #Privacy #Runbox #Norway #European #Email #Degoogle
-
On what planet would people not bother setting a simple switch to tell email servers to discard email claiming to be from their domains but aren't? You know to protect unsuspecting victims, protect the reputation of their domains, and prevent their domains from being shut down permanently for spam?
Apparently Earth.
People who leave the default option as it being OK to deliver spoofed email from their domain even if the email is screaming that it's a spoof, well, you know, deserve to lose their domain names, IMHO. What do you think?
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026
-
On what planet would people not bother setting a simple switch to tell email servers to discard email claiming to be from their domains but aren't? You know to protect unsuspecting victims, protect the reputation of their domains, and prevent their domains from being shut down permanently for spam?
Apparently Earth.
People who leave the default option as it being OK to deliver spoofed email from their domain even if the email is screaming that it's a spoof, well, you know, deserve to lose their domain names, IMHO. What do you think?
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026
-
🚨 BREAKING NEWS: The internet is shocked! 🚨 68.4% of companies still can't handle basic email security a mere 11 YEARS after DMARC's debut! 🎉 Let's all pretend to be surprised while they fumble with their DNS records like it's rocket science! 😂
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026 #internetsecurity #emailsecurity #DMARC #cybersecurity #dnsrecords #shockingnews #HackerNews #ngated -
🚨 BREAKING NEWS: The internet is shocked! 🚨 68.4% of companies still can't handle basic email security a mere 11 YEARS after DMARC's debut! 🎉 Let's all pretend to be surprised while they fumble with their DNS records like it's rocket science! 😂
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026 #internetsecurity #emailsecurity #DMARC #cybersecurity #dnsrecords #shockingnews #HackerNews #ngated -
DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026
Comments: https://news.ycombinator.com/item?id=49081783
#HackerNews #DMARC #cybersecurity #emailsecurity #domainprotection #enforcement
-
DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It
https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026
Comments: https://news.ycombinator.com/item?id=49081783
#HackerNews #DMARC #cybersecurity #emailsecurity #domainprotection #enforcement
-
Apple says a July 3 patch fully closes the Hide My Email vulnerability that exposed real iCloud+ addresses for over a year after disclosure.
#Apple #iCloud #HideMyEmail #Privacy #EmailSecurity #InfoSec
-
Apple says a July 3 patch fully closes the Hide My Email vulnerability that exposed real iCloud+ addresses for over a year after disclosure.
#Apple #iCloud #HideMyEmail #Privacy #EmailSecurity #InfoSec
-
Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. https://hackernoon.com/two-thirds-of-the-top-million-domains-can-still-be-spoofed #emailsecurity
-
Daily DNS scans of the Tranco top-1M show 67% of mail-receiving domains have no enforced DMARC policy — and the enforcement share keeps falling. https://hackernoon.com/two-thirds-of-the-top-million-domains-can-still-be-spoofed #emailsecurity
-
SPF, DKIM, DMARC, BIMI : j’ai publié un guide pratique pour mettre au propre l’anti-spoofing d’un domaine email.
Return-path, alignement DMARC, rapports rua, vérifs DNS, ESP, BIMI et pièges classiques.
https://cryptolab.re/posts/2026/antispoofing-email-spf-dkim-dmarc-guide/
-
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.
Full post: https://graylog.org/post/unlock-email-threat-visibility-with-mimecast-and-graylog/
#Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife -
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.
Full post: https://graylog.org/post/unlock-email-threat-visibility-with-mimecast-and-graylog/
#Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife -
New by me: CybersecKyle Security How-To Series: Power User and Small Team, Part 2 - Email Security with SPF, DKIM, and DMARC
#Cybersecurity #InfoSec #EmailSecurity #DMARC #CybersecKyleHowTo
-
New by me: CybersecKyle Security How-To Series: Power User and Small Team, Part 2 - Email Security with SPF, DKIM, and DMARC
#Cybersecurity #InfoSec #EmailSecurity #DMARC #CybersecKyleHowTo
-
🚀 Wow, #DKIM2 and #DMARCbis have "landed" like a spaceship nobody asked for, and Stalwart is apparently fluent in their alien language! 🤖 Meanwhile, mere mortals are left sifting through a jumble of buzzwords and tech jargon, wondering why email security always feels like deciphering a tech bro's gibberish bingo card. 🎉
https://stalw.art/blog/dkim2-dmarcbis/ #emailsecurity #techjargon #cybersecurity #HackerNews #ngated -
🚀 Wow, #DKIM2 and #DMARCbis have "landed" like a spaceship nobody asked for, and Stalwart is apparently fluent in their alien language! 🤖 Meanwhile, mere mortals are left sifting through a jumble of buzzwords and tech jargon, wondering why email security always feels like deciphering a tech bro's gibberish bingo card. 🎉
https://stalw.art/blog/dkim2-dmarcbis/ #emailsecurity #techjargon #cybersecurity #HackerNews #ngated -
Why DMARC's new "NP" tag can fail with DNSSEC
https://dmarcwise.io/blog/dmarc-np-incompatibility-with-dnssec
#HackerNews #DMARC #DNSSEC #NPtag #cybersecurity #emailsecurity
-
Why DMARC's new "NP" tag can fail with DNSSEC
https://dmarcwise.io/blog/dmarc-np-incompatibility-with-dnssec
#HackerNews #DMARC #DNSSEC #NPtag #cybersecurity #emailsecurity
-
Your email account is the key to almost everything.
If someone gains access to it, they can often reset passwords for many of your other accounts.
That's why securing your email should be one of the first things you do.
📖 Lesson 6: https://error-404.cc/en/digital-privacy-security/start-here/lesson-6-email-security/
#DigitalHygiene #Privacy #OnlineSafety #EmailSecurity #mastodon #Fediverse #infosec
-
FBI IC3 reported $2.77B in business email compromise losses in 2024
BEC works because attackers impersonate trusted domains
DMARC at enforcement makes exact-domain spoofing fail
it doesn't stop all BEC
lookalike domains and compromised accounts are separate problems
but it eliminates the most common vector
every dollar spent on DMARC monitoring returns multiples in prevented impersonation
-
30.4% adoption vs. 12.8% enforcement: the DMARC gap
of 5.5M domains I scanned, 30.4% have a DMARC record
only 12.8% are at p=quarantine or p=reject
that means 57.9% of domains "doing DMARC" aren't actually enforcing it
they're collecting reports they probably aren't reading, some aren't even monitoring it at all!
a DMARC record at p=none is a monitoring declaration, not a security control