r/EmailSecurity

▲ 20 r/EmailSecurity+1 crossposts

How would you protect 4–6 high-risk inboxes without breaking the bank?

We’re a small company with only 16 employees and currently use Microsoft Defender for email security. It works well overall, but a few of our executive accounts are targeted by phishing much more frequently, and one of them has been compromised in the past.

We’re looking for an extra layer of protection that we could apply to just a few users (around 4–6), rather than the whole organization.

Has anyone dealt with something similar? Any tools or solutions you’d recommend that work well alongside Defender and are cost-effective for such a small number of users?

reddit.com
▲ 10 r/EmailSecurity+1 crossposts

How to Stop OTP SMS Abuse When Attackers Rotate Valid Phone Numbers, Emails, and IPs?

Hi friends, I am currently dealing with a problem. An unknown person is targeting the OTP SMS service on our website's sign-up page. They are attempting this using multiple phone numbers, multiple email addresses, and rotating IP addresses. We are already using email validation services, yet they are using email addresses like "bowobon834@sepmaf.com" and "kiyow78785@toooby.com." They are also using a specific series of mobile numbers, such as:

"+201195127174", "+201181110723", "+201195130069",

"+201195127216",

"+201181111455",

"+201195127472",

"+201181113961",

"+201195127038",

"+201195129482",

"+201000177595",

All these numbers are valid. What kind of service provides such valid numbers? By submitting only valid numbers, they are negatively impacting our SMS budget. They are using two types of emails: valid permanent ones (like "mai.t.hi.e.ndi.9.5.5.11@gmail.com", "ph.a.nd.ong.nh.i.19.5.8.5@gmail.com", "m.er.ed.ith.geron.i.mo.24.1@gmail.com") and temporary ones (like "nofon85312@sepmaf.com", "yiridog100@toooby.com", "sapija5854@sepmaf.com").

Both types of emails they are using are valid. There are so many services that provide temporary emails; it is impossible to block them all. We simply won't be able to block every single one.

currently we create a script to mai.t.hi.e.ndi.9.5.5.11@gmail.com that pattern email but. when user email is normal and pass email verification service and able to create account in that case they put mobile number and send otp the promblem is occured the all number is valid in lookup api and they rotate the number, IP to prevent throttling.

What really matters is the service that provides valid phone numbers. If anyone has information about such services, please help us out.

Hi friends, I am currently dealing with a problem. An unknown person is targeting the OTP SMS service on our website's sign-up page. They are attempting this using multiple phone numbers, multiple email addresses, and rotating IP addresses. We are already using email validation services, yet they are using email addresses like "bowobon834@sepmaf.com" and "kiyow78785@toooby.com." They are also using a specific series of mobile numbers, such as:

"+201195127174", "+201181110723", "+201195130069",

"+201195127216",

"+201181111455",

"+201195127472",

"+201181113961",

"+201195127038",

"+201195129482",

"+201000177595",

All these numbers are valid. What kind of service provides such valid numbers? By submitting only valid numbers, they are negatively impacting our SMS budget. They are using two types of emails: valid permanent ones (like "mai.t.hi.e.ndi.9.5.5.11@gmail.com", "ph.a.nd.ong.nh.i.19.5.8.5@gmail.com", "m.er.ed.ith.geron.i.mo.24.1@gmail.com") and temporary ones (like "nofon85312@sepmaf.com", "yiridog100@toooby.com", "sapija5854@sepmaf.com").

Both types of emails they are using are valid. There are so many services that provide temporary emails; it is impossible to block them all. We simply won't be able to block every single one.

currently we create a script to mai.t.hi.e.ndi.9.5.5.11@gmail.com that pattern email but. when user email is normal and pass email verification service and able to create account in that case they put mobile number and send otp the promblem is occured the all number is valid in lookup api and they rotate the number, IP to prevent throttling.

Currently we do our best. Anyone guide me how we can handle in much efficiently of that kind of problems.

What really matters is the service that provides valid phone numbers. If anyone has information about such services, please help us out.

Let us know whos provider that kind of virtual numbers infinite as i review they use 200 mobile number to send otp.

reddit.com
▲ 3 r/EmailSecurity+1 crossposts

Trapped in a 50,000+ email loop after a large scan. IT is clueless and wants to delete my account. Need advice!

Hi everyone,

I am not a tech person, but I’m hoping someone here can give me advice or technical words I can use with my IT department. I'm currently trapped in a nightmare.

Last Wednesday, I scanned an 82-page document from my office copier to my email address (with the option "1 page = 1 PDF").

Right after, I started getting an automated error email from our organization's system every single minute, telling me the attachment exceeds the 10 MB limit.

I have received over 50,000 emails so far.

What we've tested :

- The copier's log says the job is "completed"

- We completely unplugged the physical copier from the wall for a while, but the emails kept coming.

-I set up email inbox rules to auto-delete these messages so I don't lose my mind, but they are still flooding my account in the background.

My organization's IT department doesn't know how to fix this. Local IT (on-site) and headquarters IT keep passing the buck to each other.

Now, their "solution" is to completely delete my email account and recreate a new one from scratch.

I am convinced there has to be a better solution than destroying my work account. Isn't this just a mail loop / stuck SMTP server queue on the central server side that an admin needs to purge?

What exact technical terms or instructions should I give them so they can fix this without deleting my account?

Thanks in advance for your help!

reddit.com
u/Naume — 3 days ago

A DMARC record that doesn’t enforce is décor. How are you scoring “present”?

Most dashboards still treat “DMARC published” as a win. In the July 2026 Cloudflare Radar Top 1M cut, 70.9% of mail-enabled domains were still spoofable.

Presence looks fine. Enforcement does not. If a scorecard gives full credit for a monitoring-only record, it’s measuring decoration.

Question: in your environment, does “DMARC present” still count as done, or do you only credit enforce?

reddit.com
u/SecLens_ONE — 4 days ago

Receiving emails with subjects related to other emails I've received.

So I've been getting a lot of emails regarding test results for my child with a typical subject line of "New test results from MyChart" or something similar, always includes "MyChart".

Lately I've been getting, what is clearly phishing or spam emails that have the subject title "MyChart".

I've changed my passwords just as a precaution but I'm wondering if anyone else experienced this or knows how they're sending these pretty specific tailored emails?

TIA

reddit.com
u/Actual_Pie6920 — 4 days ago
▲ 1 r/EmailSecurity+1 crossposts

Do i have to verify my terpmail?

I just got this email to my UMD terpmail inbox. It says I have to verify my microsoft account? Do i actually have to do this? This is literally the first time i have been notified to have to verify it, so i’m confused as to why the email says “this is the last time.” When i pressed the link and tried to type in my password in the designated “UMD Key@Word” box, it didn’t even hide my password while typing it? Idk… just seems pretty sus. Maybe i’m trippin tho? Just wanna make sure before I put my password in somewhere, because i was not made aware I have to fill out a form to verify my terpmail until now. Is this legit y’all? (Idk maybe im overthinking it lol)

u/Alxie_e — 7 days ago

Help stopping SPAM on my Support email

Hi everyone, hope you're doing good. I launched my Shopify website (Print on Demand from Printify to Shopify) a few months ago and since then keep getting blasted by emails from "consultants", "experts" and other professionals on my support email. I have triple checked multiple times and this full email address does not appear (in full) on the website. I don't even know where they get it from. We're talking 10+ emails everyday. It's really annoying... any idea how to fight this? Thanks for your advice!

reddit.com
u/PerdurNate — 6 days ago
▲ 24 r/EmailSecurity+1 crossposts

what should I do?

I found this sent on my spam folder yesterday.. what should I do? Should I block the email or just ignore?

u/PhonePitiful9717 — 8 days ago

What are the best questions/features to ask an email security vendor?

We’re currently evaluating email security vendors and comparing their capabilities with our existing solution. I’m looking for suggestions on good technical and security-focused questions to ask vendors during demos/POCs, beyond the usual feature checklist.

reddit.com
u/bugbeeboo — 6 days ago

Our email filtering keeps missing spoofed invoices - what are you using?

I look after IT for a company of about 120 people. We're on Microsoft 365 and leaning on the built in filtering, and it is not keeping up. Three spoofed emails reached our finance team this month and one nearly got paid.

Our current renewal quote came back much higher than last year so I'm looking at alternatives. What I need is something in front of our mail that catches spoofing properly, has a quarantine my helpdesk can release from without a ticket, and doesn't bury us in false positives.

What are you all running, and roughly what does it cost per mailbox?

reddit.com
u/Yokshith09 — 9 days ago
▲ 1 r/EmailSecurity+1 crossposts

Is my gmail account Hacked?

I've been getting mails saying your mail isn't delivered but I didn't send any mail at the first place. This has been happening from last 1 month it caught my attention today, I saw my inbox and my acc is sending mails to random people in Europe specifically more to german people and the email is mostly about paying bills or getting a refund or something it's probably a phisihing link

But why?? How do I stop this? I did check my settings my device is the only one logged in?? Im worried since my mail is sending mails to random people with probably phisihing links, how do I stop this?!?

u/chokondez — 10 days ago
▲ 5 r/EmailSecurity+1 crossposts

ARC has finally arrived on Cisco/Ironport

From the latest AsyncOS release notes:

Authenticated Received Chain (ARC) Support

Secure Email Cloud Gateway now supports Authenticated Received Chain (ARC). This feature ensures that legitimate emails can pass security checks even after being modified by intermediaries, such as mailing lists or forwarding services.

Core Functionality:

• ARC Sealing: Acts as a "sealer," appending authentication results and digital signatures to outgoing messages to preserve the chain of trust.

• ARC Verification: Validates existing chains on incoming messages. By referencing a list of trusted intermediaries, the system verifies the integrity of the message's history.

• Policy Override: Allows for the delivery of messages that would otherwise be blocked or quarantined by security policies, provided they possess a valid authentication chain.

• System Visibility: Provides clear status indicators within email headers. Comprehensive details are also integrated into the DMARC Verification Report and Message Tracking.

Anyone given it a spin yet?

reddit.com
u/zionegg — 8 days ago
▲ 33 r/EmailSecurity+1 crossposts

Someone here asked how many MX servers actually refuse mail without TLS. We measured all 366,215 of them. The answer is 0.2%.

Last month we posted month two of our monthly measurement of DMARC, MTA-STS, DANE and BIMI across the top million domains. In that thread someone asked a question we didn't have an answer to: how many MX servers refuse all connections that aren't encrypted?

It's a sharper question than it looks. MTA-STS and DANE are both ways for a domain to tell senders "use TLS when you deliver to me." Neither of them says anything about what happens when a sender ignores that. So this month we went and asked the servers directly.

We took all 366,215 unique MX hostnames in the top million, resolved each to an address, connected on port 25, read the EHLO capability list, and then tried to start a mail transaction in the clear.

290,230 gave a conclusive answer. Shares below are of those, not of 366,215:

  • Offers STARTTLS, accepts cleartext anyway (opportunistic): 278,502, 96.0%
  • Offers no STARTTLS at all: 11,135, 3.8%
  • Offers STARTTLS and refuses cleartext: 593, 0.20%

Two in a thousand. Per domain it's thinner: 598 of 620,240 cleanly measured domains, 0.096%, require TLS on every one of their MX hosts.

The cross-tab is the part we think this sub will care about, and the two protocols split. Domains publishing MTA-STS at enforce enforce inbound TLS at 0.82% against a 0.096% baseline, so 8.5x. Domains publishing DANE come in at 0.12%, which is 1.2x, i.e. no signal at all. That fits: MTA-STS is still mostly something an operator switches on deliberately, while DANE is overwhelmingly inherited from a provider default, and a default says nothing about the domain that inherited it.

Either way: 99.18% of the domains publishing an enforce policy will cheerfully accept your plaintext mail. For DANE publishers it's 99.88%.

Two things about who the 598 are. We went looking for an industry pattern and mostly didn't find one, so we're not going to pretend otherwise. What we did find was geography: .de is 4.7x over-represented, .eu 3.7x, .cz 3.5x, and German-speaking Europe overall is 15.4% of the enforcers against 3.8% of mail-eligible domains. The German names skew regulated: comdirect, DZ Bank, the federal debt agency, two hospital groups, a handful of city and regional governments. Our guess is BSI TR-03108 plus GDPR practice in health and finance, but we've measured the clustering, not the cause, so take that as a hypothesis.

The other thing: 71 of the 598 are on AWS SES Mail Manager, and 13 of that product's 14 measured hostnames enforce. That's not 71 security decisions, it's one product default. The customer list gives it away: 22 of the 71 are online casinos and gambling affiliates, 36 more are SEO and content-farm domains (seven of them near-identical .live search-spam sites), and the recognizable names left are Supercell's clashroyale.com and SAP's concursolutions.com.

Meanwhile the providers carrying most of the world's mail enforce essentially nothing: 0 of 116,692 measured Microsoft 365 tenant hostnames, 0 for Google, 0 for Cloudflare, Zoho, Proton, Fastmail and Yandex. Cisco's iphmx is the only one above zero, at 22 of 2,546. Microsoft's 119,676 hostnames collapse onto 130 addresses and exactly one refuses cleartext: not a tenant endpoint and not a consumer frontend, but outlook.com itself. Looks isolated rather than the front of a rollout, since the consumer domains that would flip first all still accept plaintext. That's our September watch item.

On method, since that's usually where these threads go. The probe stops at MAIL FROM with a null sender. Never RCPT, never DATA, so it never delivers mail and never does anything resembling a sender callout. The price of that restraint is that a server enforcing TLS only at a later stage reads as opportunistic to us, so 0.20% is a floor. Unlike a DNS lookup this is answered by a mail server that can decline to talk to you at all, so the 75,985 hostnames we couldn't measure (16,113 with no address to dial, 54,940 that resolved but wouldn't hold an SMTP conversation, 4,932 that rejected us for non-TLS reasons like greylisting or IP reputation) are kept in their own buckets and excluded from the denominator rather than counted as "doesn't require TLS." Folding those in would bias the number in exactly the flattering direction, and the hosts that refuse a prober are never a random sample of the internet.

The rest of this month, briefly: DANE grew 5.18% on a same-domain basis, its fastest reading yet, and 85% of that is Strato switching on TLSA for its entire customer base (995 of its 1,001 domains in our data gained it in one month). Last month was Migadu deleting theirs. Strip both provider events out and organic DANE growth was 0.82% in July and 0.77% in August, which is the most stable number in the whole dataset. Migadu's records never came back.

Happy to get into any of it, especially the classification logic if anyone wants to poke holes in it. And thanks to @slfyst who asked the original question, it turned into the most interesting thing we measured this month.

reddit.com
u/Ok_Philosophy_9766 — 13 days ago
▲ 3 r/EmailSecurity+1 crossposts

Phishing email to my co-workers

I had a phishing email come into my office and wonder how i should attack this one? Whenever the link is clicked, it seems to go through their sent emails and send 500+ emails with the screenshot attached. Everyone has MFA enabled, and all have secure passwords. Should i tell staff to change passwords even though they haven't been alerted of a sign in attempt? I can't tell what the endgame of these emails are since it can't tell was was collected with the click.

Can anyone tell me exactly what is located in the URL? and how it works?

Any tips that i can take besides more cyber training for them? Thanks!

u/No_Fix_7679 — 13 days ago

Safe sender list overrode DMARC p=reject: four phishing emails failed SPF and DKIM and were still delivered at SCL -1

ZeroBEC published research on Tuesday about the Greatness phishing kit, and it is travelling under a headline saying the kit bypasses email security and MFA. The research says the opposite, in a sentence: “The security stack was not broken. It was working exactly as configured. The vulnerability was the configuration itself.”

From the headers: on 22 July, four emails hit one organization seconds apart, spoofing RingCentral voicemail notifications from an IONOS host with no connection to RingCentral’s mail infrastructure. SPF failed, there was no DKIM signature, and DMARC failed against a published p=reject at full enforcement. All four were delivered anyway and assigned SCL -1, which marks a message safe and skips the remaining filtering. The organization is a RingCentral customer and had put the domain in its safe sender configuration, so that exclusion outranked the authentication result.

The emails carried a banner reading “This sender has been verified by [organization].com safe senders list.” The attacker is using the victim’s own allow-list as social proof, which only works against an organization that has one.

The MFA claim has the same shape. An AiTM proxy relayed the genuine Microsoft challenge in real time, including number-matching; the user completed it, and the token that came back already carried a satisfied MFA. That token gets replayed from attacker infrastructure rather than the victim’s browser, so impossible-travel rules never fire, and more than two weeks later the same proxy IP was still authenticating against the account. The coverage keeps dropping the condition that makes it possible: the sign-in logs show no Conditional Access policies applied.

Worth weighing that this comes from an email security vendor whose own product is the control that caught the four emails, concluding that behavioural analysis catches what gateway checks miss. The headers stand on their own; the framing around them gets less weight.

The transferable part has nothing to do with this kit. Every domain in a safe-sender list or transport-rule exclusion is a standing instruction to ignore authentication for anyone who can claim that domain, which was a reasonable trade when the downside was a partner’s invoice landing in junk, and is a worse one now that vendor breaches leak customer lists.

So, if you audited your exclusions this morning, how many vendor domains would be in there, and how many would be unconditional rather than requiring authentication to pass first?

reddit.com
u/compileindebug_175 — 14 days ago