best practices for email senders...talos group, cisco systems april 2019. who is talos? talos...

22
Best Practices for Email Senders Don Owens, Senior Architect Talos Group, Cisco Systems April 2019

Upload: others

Post on 21-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Best Practices for Email Senders

Don Owens, Senior Architect

Talos Group, Cisco Systems

April 2019

Page 2: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Who is Talos?

Page 3: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Talos

• Data for Email, Web, and Firewall (both cloud and on-prem).Vulnerability Discovery

Web

Endpoint

Cloud

Email

Data Sharing

Threat Traps

Network

Page 4: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Best Practices

Page 5: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Don’t look like the bad guys.

Page 6: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Don’t look l ike the bad guys

• No DGAs• Don’t generate hosts/subdomains using an algorithm• n3456x35.example.com looks evil – don’t do it

• Anchor text• if the anchor text for a link is a URL, it should match the

destination (URL in the href field)

Page 7: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Tell us who you are.

Page 8: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Show us you’re not a robot

• Use a real public host name for HELO– localhost.localdomain ← don't do this !– mta1.example.com ← do this "

• HELO and PTR match– Configure your MTA to HELO with the same host name

string as the PTR record for your IP address.

Page 9: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Authenticat ion

• SPF– Easy setup in DNS

• DKIM– Easy to set up in DNS, but also requires configuration in

your MTA

• DMARC– Based on SPF and DKIM– Allows you to specify what the receiver should do if

DMARC checks fail– Allows you to specify reporting addresses for DMARC

failures

Page 10: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Show us that you’re a

professional.

Page 11: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Show us that you’re a professional

• Marketing: include unsubscribe links and headers

• A mail server should do one thing. Only send and/or

receive mail. Don’t run DNS, web servers, etc., on

the same IP

• Don’t use domain privacy services

Page 12: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Warm up your IPs and domains

Page 13: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Require double opt- in

• It's very important to get permission to send marketing to a recipient.

• Not doing so may or may not increase your revenue in the short term, but it cost everyone money in the end, and it damages your reputation.

• GDPR

Page 14: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Monitor bounces

If too many of your emails are bounced (due to invalid recipients), it will look like you’re performing a directory harvest attack.

Page 15: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Don’t use gener ic fr iendly-froms

Always include your brand name in the From: header.• Bad:

– Updates– Account Verification– Customer Service

• Good:– Acme Updates– Acme Account Verification– Acme Customer Service

Page 16: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

URL shorteners and redirectors

There's a debate around this one, as some mail security providers feel this is needed to some extent, to protect customers with click-time protection.

The issue is that it's reputation hijacking.

If you use a URL shortener/redirector, it’s best to make sure it’s on your own domain (same as sender). If possible, include the original URL clearly visible in redirector links.

Page 17: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

List washing

One of the fastest ways to destroy trust, and

therefore your reputation.

• Don’t do it!

• Don’t do it!

• Just don’t!

Page 18: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Don't buy or rent l ists

• If you’re buying a list, the recipients on that list didn’t opt-in.

• Someone on those lists will eventually report your messages as spam. This will take time to recover from.

Page 19: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

It’s all about building trust

Page 20: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

Future of Reputation

Page 21: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

What’s Next?

• Sender Domain Reputation (SDR) – sender domain reputation for Cisco customers (was made available in general release of ESA 12.0 in Jan 2019).

• Sender domain block list from SpamCop, similar to the SpamCop IP blocklist, available to query by the public.

Page 22: Best Practices for Email Senders...Talos Group, Cisco Systems April 2019. Who is Talos? Talos •Data for Email, Web, and Firewall (both cloud and on-prem). Vulnerability Discovery

talosintelligence.comblog.talosintel.com@talossecurity