SlideShare a Scribd company logo
1 of 23
Who is using your domain for phishing & spam?
DMARC Compass™
Dan Ingevaldson
CTO
Email is a mission-critical communication channel for most
companies.
Over 205billion emails are sent and received every day (112.5
billion business emails).¹
Email has also become an untrusted channel.
Thanks to spam and phishing scams, users are
taught to be wary of incoming messages.
59.2%
2015 Proportion of Spam in Email²
Spam
97% of people globally are unable
to correctly identify phishing
emails³
This lack of trust impacts a company’s ability to
effectively communicate, market, and sell to
customers via email.
In 2014, email ROI reached 2,500%.⁴
(Domain MessageAuthentication, Reporting and Conformance)
DMARC
…stands to change all that.
DMARC
• Provides visibility into email flows
• Tells receiving servers to delete spoofed messages immediately
upon receipt
• Ensures only legitimate emails are delivered to inboxes
Getting started with DMARC
is easy. Any email sender and
receiver can use the DMARC
rails provided by the global
community.
Free use of the rails provides access to the critical, raw
reporting data that helps you see who is sending email
and who is spoofing your brand.
Can be deployed in Monitor,Quarantine or Reject mode.
DMARC
Monitor
A domain owner can begin using DMARC in "monitor mode" to
collect data from participating receivers.
Quarantine
As the data shows that their legitimate traffic is passing authentication
checks, they can change their policy to request that failing messages
be quarantined.
Reject
As they grow confident that no
legitimate messages are being
incorrectly quarantined, they can
move to a "reject" policy.
It is impossible for spoofed email to be delivered
to DMARC-protected email servers.
“DMARC protects more than 85% of the people who
receive and send e-mail from Facebook”
Michael Adkins, Facebook
“Implementing DMARC stopped nearly 25 million
attempted attacks on our customers during the 2013
holiday season alone” Trent Adams, PayPay / Ebay, Chair of DMARC.org
Does it work?
The DMARC Standard
DMARC is an IETF Draft Specification that allows email receivers to determine if
an email is authentic and what to do if it is not
DMARC Compass™ a comprehensive tool that provides clear
visibility into your e-mail delivery environment
What is needed forCompleteVisibility?
Putting DMARC into Context
% of Incidents from DMARC?
<20%
Hacked
Sites
Social Media
Fraudulent
Domains
DMARC
Malware/MobileApps
Non-spoofed Phish
Active Monitoring
DMARC on its own is not a complete fraud strategy – but anything that provides some visibility is a win.
Make sure that you have other layers in place to protect against these other threats.
ProactiveThreat Detection andTakedown
18
DMARC Compass™
Detect Monitoring Service™
Threat Reduction
Attack Deactivation
Why from Easy Solutions?
19
* 2014, Top 40 US Bank
Differentiators Initiate server takedowns backed
by 24/7/365 Security Operations
Center
Full Restful API to leverage
Compass data elsewhere in your
stack
Customized reporting for
analytics
Shares intelligence with the rest
of our products
Determine your server policies through Compass Explorer
Deploy DNSTXT record
Monitor results in Compass portal
Authorize, deauthorize servers as they are identified
Migrate DNS policies for stricter e-mail handling
Deployment
Learn more: DMARC Compass
Contact us: info@easysol.net
Sources:
1. http://www.radicati.com/wp/wp-content/uploads/2015/02/Email-Statistics-Report-2015-2019-Executive-
Summary.pdf
2. https://securelist.com/analysis/quarterly-spam-reports/69932/spam-and-phishing-in-the-first-quarter-of-
2015/
3. http://www.information-age.com/technology/security/123459514/think-you-can-spot-scam-97-people-
wouldnt-know-phishing-email-if-it-hooked-them
4. http://www.cmo.com/articles/2015/1/6/15_stats_marketing_ROI.html

More Related Content

Recently uploaded

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Recently uploaded (20)

A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 

Featured

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Featured (20)

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 

Who is Using Your Domain for Phishing & Spam? A DMARC Overview

  • 1. Who is using your domain for phishing & spam? DMARC Compass™ Dan Ingevaldson CTO
  • 2. Email is a mission-critical communication channel for most companies. Over 205billion emails are sent and received every day (112.5 billion business emails).¹
  • 3. Email has also become an untrusted channel. Thanks to spam and phishing scams, users are taught to be wary of incoming messages. 59.2% 2015 Proportion of Spam in Email² Spam 97% of people globally are unable to correctly identify phishing emails³
  • 4. This lack of trust impacts a company’s ability to effectively communicate, market, and sell to customers via email. In 2014, email ROI reached 2,500%.⁴
  • 5. (Domain MessageAuthentication, Reporting and Conformance) DMARC …stands to change all that.
  • 6. DMARC • Provides visibility into email flows • Tells receiving servers to delete spoofed messages immediately upon receipt • Ensures only legitimate emails are delivered to inboxes
  • 7. Getting started with DMARC is easy. Any email sender and receiver can use the DMARC rails provided by the global community.
  • 8. Free use of the rails provides access to the critical, raw reporting data that helps you see who is sending email and who is spoofing your brand.
  • 9. Can be deployed in Monitor,Quarantine or Reject mode. DMARC
  • 10. Monitor A domain owner can begin using DMARC in "monitor mode" to collect data from participating receivers.
  • 11. Quarantine As the data shows that their legitimate traffic is passing authentication checks, they can change their policy to request that failing messages be quarantined.
  • 12. Reject As they grow confident that no legitimate messages are being incorrectly quarantined, they can move to a "reject" policy.
  • 13. It is impossible for spoofed email to be delivered to DMARC-protected email servers.
  • 14. “DMARC protects more than 85% of the people who receive and send e-mail from Facebook” Michael Adkins, Facebook “Implementing DMARC stopped nearly 25 million attempted attacks on our customers during the 2013 holiday season alone” Trent Adams, PayPay / Ebay, Chair of DMARC.org Does it work?
  • 15. The DMARC Standard DMARC is an IETF Draft Specification that allows email receivers to determine if an email is authentic and what to do if it is not
  • 16. DMARC Compass™ a comprehensive tool that provides clear visibility into your e-mail delivery environment
  • 17. What is needed forCompleteVisibility? Putting DMARC into Context % of Incidents from DMARC? <20% Hacked Sites Social Media Fraudulent Domains DMARC Malware/MobileApps Non-spoofed Phish Active Monitoring DMARC on its own is not a complete fraud strategy – but anything that provides some visibility is a win. Make sure that you have other layers in place to protect against these other threats.
  • 18. ProactiveThreat Detection andTakedown 18 DMARC Compass™ Detect Monitoring Service™ Threat Reduction Attack Deactivation
  • 19. Why from Easy Solutions? 19 * 2014, Top 40 US Bank
  • 20. Differentiators Initiate server takedowns backed by 24/7/365 Security Operations Center Full Restful API to leverage Compass data elsewhere in your stack Customized reporting for analytics Shares intelligence with the rest of our products
  • 21. Determine your server policies through Compass Explorer Deploy DNSTXT record Monitor results in Compass portal Authorize, deauthorize servers as they are identified Migrate DNS policies for stricter e-mail handling Deployment
  • 22. Learn more: DMARC Compass Contact us: info@easysol.net
  • 23. Sources: 1. http://www.radicati.com/wp/wp-content/uploads/2015/02/Email-Statistics-Report-2015-2019-Executive- Summary.pdf 2. https://securelist.com/analysis/quarterly-spam-reports/69932/spam-and-phishing-in-the-first-quarter-of- 2015/ 3. http://www.information-age.com/technology/security/123459514/think-you-can-spot-scam-97-people- wouldnt-know-phishing-email-if-it-hooked-them 4. http://www.cmo.com/articles/2015/1/6/15_stats_marketing_ROI.html

Editor's Notes

  1. A domain owner who has deployed email authentication can begin using DMARC in "monitor mode" to collect data from participating receivers. As the data shows that their legitimate traffic is passing authentication checks, they can change their policy to request that failing messages be quarantined. As they grow confident that no legitimate messages are being incorrectly quarantined, they can move to a "reject" policy.
  2. DMARC stands for, Domain Message Authentication, Reporting and Conformance IEFT – Internet Engineering Task Force SPF - Sender Policy Framework (SPF) records allow domain owners to publish a list of IP addresses or subnets that are authorized to send email on their behalf.  DKIM – DomainKeys Identified Mail DKIM provides a method for validating a domain name identity that is associated with a message through cryptographic authentication.