How an I prevent spoofed email using IronPort C160?

As part of Security Awareness training and testing we contracted a company called knowbe4 to initiate some random spoofed e-mail tests into our domain.  Normally I would have figured this would fail because when email comes into the C160 and it has our @domainname.com on it, it needs to validate the DKIM signature, and if it was not sent from our organization, IronPort would not have signed it, correct?
Anyway the security awareness organization was able to successfully send an e-mail inbound and make it appear as if it came from [email protected] (which we do not have a mailbox with that name, but I'm sure he certainly could have done research and used our real CEO's email address.).  In Outlook it does appear as [email protected] in the from box, but when you search message tracking for emails coming from that address you get nothing.  Upon further inspection of the e-mail headers, the message actually came from bounces+78188-4be9-username=[email protected]  So it matched policy DEFAULT for inbound mail policies and eventually it was successfully signed with domain key profile and DKIM profile matching [email protected], then queued for delivery.
How can an email arriving from one server "morph" into another?  Is there some sort of vulnerability that this organization is taking advantage of, perhaps some kind of active script that the IronPort ends up acting upon to alter the email address and sign it so it passes through?  This was a test today, but we need to plug this hole because the bad guys are going to use this technique to make phishing emails look legitimate coming from internal users.

I use knowbe4 as well, great phishing test templates, and what I found to work best to fight Domain spoofing are the following:
- Implement DMARC/SPF/DKIM DNS records and keys - You will want to set these to passive initially. I personally recommend using dmarcian.com they have tools to help with implementation. Initially you will just want to be in monitor mode then start suggesting actions that gateways should take based on your DNS records. (This will protect your domain from being spoofed to gateway or provider that has DMARC/SPF/DKIM enabled)
- Maintain your DNS SPF records (these are to used to help you authorize who can send emails from as your domains)
- Here is a good how-to video for configuring your appliance to block domain spoofing. You will want to add any providers you want to allow to spoof such as ADP, training, and other third party vendors that generally spoof your domain to send emails to your employees. https://supportforums.cisco.com/video/11932126/configure-spoof-protection-exception-lists
- Create a second mail flow policy similar to your allowspoof one, but turn off spam filtering, I called mine KnowBe4.
- Create a new HAT and call that KnowBe4 and point it to the new policy. Add all the Knowbe4 or who ever your phishing simulation provider is to this HAT table. I suggest adding a description so you will know which ones to delete later on.
You should now have taking care of e-mail spoofing, you will want to monitor this closely. Also if you are using Email Encryption you need to make sure the vendor's (even if using Cisco) gateways are added to your SPF record and your HAT table AllowSpoof list.
Finally I would recommend enabling DMARC feature in your appliance, this will help filter out and report to email providers and gateways who is spoofing their domains, it will also increase your filtering power, but it does not stop all spam just one more thing to eliminate low hanging fruit.
Knowbe4's test phish is a good way to test for spoofing, and your employees.

Similar Messages

  • How can I prevent that emails are downloaded (POP3) when the lid of my MacBook Pro is closed?

    How can I prevent that emails are downloaded (POP3) when the lid of my MacBook Pro is closed?

    Disable Power Nap in the Energy Saver pane of System Preferences. Uncheck the box marked Enable Power Nap... in each of the tabs.

  • HT4847 How does one prevent all email received from emigrating to the cloud at the time of receipt?

    How does one prevent all email received, from being sent to the cloud at time of receipt?
    leisurestreet

    Welcome to the Apple Community.
    That's how it's supposed to work, you can't stop it. If this isn't what you want you should get yourself a POP based email account.

  • How can we prevent back button  using java script

    how can we prevent back button using java script

    Would be quicker for you to google for javaScript
    javascript:window.history.forward(-1);

  • HT1689 I don't want my visa being used for ITunes.  I have an ITunes card.  How do I prevent ITunes from using my Visa

    I don't want my visa being used for ITunes.  I have an ITunes card.  How do I prevent ITunes from using my Visa?

    It automatically uses the gift card balance first.

  • How can I change the email used in iphoto

    how can i change the email that is used for iphoto? it goes to my email account that's connected to flickr but i want to have it different as a default. help or suggestions?

    Go to iPhoto's General preference pane and select the email client in the Email photos using: menu.
    Click to view full size
    OT

  • How do I prevent an email from going to bulk mail

    I have one individual that sends email to me, and their email always goes into BULK mail. I have added them to my address book, but they still are going to bulk--and I miss them or respond late. How can I get that email address to go to inbox?

    I'm not sure what you're referring to, then, as there's no standard IMAP mailbox called "bulk". That could be a junk mailbox by another name, provided by your e-mail provider. If this is happening with your company's e-mail server, you should talk to your company's tech support folks about this issue. It certainly doesn't sound like an issue with Mail, unless this "bulk" mailbox is one that you created, and are using a mail rule to move messages into.

  • How did someone send an email using my email address to others without my knowledge?

    Recently someone said I sent an email out to their friends.  I have a MacBook Pro.  How could this happen?

    It is likely that someone else's computer was used, your address was found in their address book and the spammer "spoofed" your email address.
    Email spoofing

  • TS4002 how can i block an email using icloud online?

    Hi
    I use icloud only online.  Is there a way to block an email so that its prevented from reaching my inbox.
    I also would like to know how to create an auto responder
    thanks
    z

    its ok, i figured it out... all done using Rules

  • How do I prevent my emails from being sent without my hitting the send key. Many of my emails are just "taking off" and sending while I am in the middle of typing. If this is a keyboard shortcut, I must disable it, so how do I do that

    How can I stop emails from being sent without my hitting the "send" key.

    Firefox doesn't do email, it's a web browser.
    If you are using Firefox to access your mail, you are using "web-mail". You need to seek support from your service provider or a forum for that service.
    If your problem is with Mozilla Thunderbird, see this forum for support.
    [http://www.mozillamessaging.com/en-US/support/] <br />
    or this one <br />
    [http://forums.mozillazine.org/viewforum.php?f=39]

  • How Can I set up email using outlook settings?

    Hi All:
    Can I set up my Touch to fetch my email from my outlook account? can't figure out how to do it!!
    Thanks!!

    Hi anilajavaid,
    iCloud only works with IMAP accounts. POP accounts won't work with iCloud.
    Sorry,
    GB

  • How do I prevent Mail from using a particular signing certificate?

    I use Apple Mail for my emails, on a MacBook Pro running Lion 10.7.5.
    In my Mail client, I have two email accounts configured. One (we'll call this the Signed Account) has a signing certificate purchased from Verisign; the other (the Unsigned Account) does not. I would like to be able to sign — and, where appropriate, encrypt — emails I send from the former account, but not the latter, by default.
    Which would be the normal behaviour for Mail, I'm given to understand. Except that I have a second signing certificate on my computer. (I have several, in fact, but only the two I mention are important.) This second certificate was obtained from an academic grid signing authority for the purposes of connecting as an administrator to particular web databases. It's not intended to be used for email.
    But Mail tries to use it nonetheless. Specifically, because the certificate uses the email address of the Unsigned Account (for contact details?), the Mail program thinks it's good for signing emails sent from that account.
    The only way I've been able to disable that function (and, thus, avoid the big, ugly banner that says, "Unable to verify message signature.") is by turning off signing altogether (checking the seal button in the Compose window). This affects the other account — the Signed Account — as well.
    I tried to set the "Secure Mail (S/MIME)" setting to Never Trust in the Keychain settings for that particular certificate, but it doesn't seem to have changed anything in this regard.
    Is there a way of "permanently" disabling signing (but only if using the Unsigned Account), while keeping signing in place for the Signed Account? This could be in Mail itself, in Keychain Access, or in some other place.
    Thanks!

    Hmm.. probably not.
    You want to open Mail. Then go into Preferences > General and you will see something similar to this:
    In the area marked Default Mail reader click on the pull down and at the bottom of the list it will say Other. You can see if you can select Safari here and if that will open up Safari.
    Good luck.

  • How to backup sent & received email using thunderbird?

    hi all i want to backup my entire email includes inbox & sent item from thunderbird, but i dont know how? please help me! tqsm
    rahim

    Thunderbird always saves your email under the Thunderbird Profile.
    You can backup your profile and restore it
    *https://support.mozilla.org/en-US/kb/profiles-tb
    *https://support.mozilla.org/en-US/kb/moving-thunderbird-data-to-a-new-computer
    *http://kb.mozillazine.org/Profile_backup
    Try some of the Tools
    *http://mozbackup.jasnapaka.com/
    *http://www.backupthunderbird.com/
    We recommend the profile backup only.

  • How to recategorize URL's when using IronPort Web Usage Controls

    The usual way of recategorizing URL's doesn't work when Cisco IronPort Web Usage Controls are enabled. There's no Word in the doc about how to recategorize URL's neither. We're running AsyncOS 7.7 on S170. Please advise.

    Hi,
    You can try this link (normally takes 24-48 hours).
    https://securityhub.cisco.com/web/submited_urls
    If it doesn't work I suggest you to open a TAC case.
    Regards,
    Luis Silva

  • How can I reset the email used for sync?

    I set up a sync account when I tried FF4 Beta, and then deleted the account (and FF4 Beta). Now, I'd like to set the account up again, but Sync tells me my email is already in use.

    [https://account.services.mozilla.com/ This page] can be used to retrieve your password. or if you recall it to truly delete your account. Then start over, if you wish.

Maybe you are looking for

  • HP Lazer Jet Pro 200 not installing with Windows 8 64 bit

    My brand new HP Laser Jet Pro 200 MFP M276mw is not installing with my brand new Acer One725-0487 Netbook that has the Windows 8 64 bit operating system. I bought them both at Office Depot this week. I downloaded the software of HP.com/support and wh

  • Fatel error while impdp in ORACLE RAC 11.1.0.6

    Hi, I am trying to import expdp dump almost 12 GB Size in table. i am getting below error: Connected to: Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - 64bit Production With the Partitioning, Real Application Clusters, OLAP, Data Mining

  • ISE 1.1.0 posture troubleshooting

    Hello, I have an authorization rule which verify that the AV (mcafee 12.x) is installed (thanks to NAC agent), time restriction and so, and so.... The connection failed with this code : 15039 Rejected per authorization profile How can I obtain a some

  • Getting error when tried to learn the documents in OFR Designer

    Hi All, As per project requirements, I have to create Classification and Verification LearnSets in Oracle Form Recognition Designer depending on three Invoice Types-- PO,Non-PO and Pre-Approved. First I created three derived classes under Generic Cla

  • Where does the acropro.msi file belong?

    I have Adobe Creative Suite 6 installed on my laptop and I want to uninstall some of the programs I never use. A while back I moved the AcroPro.msi file from my laptop to an external hard drive. I believe I need it to properly uninstall these program