Has anyone seen an email gateway service or tool ...
# _general
s
Has anyone seen an email gateway service or tool that protects users from being stupid? lol. For example, our users keep falling for mistyped domain name emails. Like when someone registers a domain called whitelow.com and the real domain is whitelaw.com. Anyway to scan against malicious typos?
j
Have you looked at Mimecast?
s
We have Mimecast. Im not seeing a way for them or any other email provider for this specific example
j
Do you have URL protection enabled? That has built in domain typo squatting blocks
s
yes, but that is for when clicking on a domain or url. Im talking about just getting an email with a on purpose typo.
The real registered dns email from adress has an on purpose mispelling. I think its a 100% human issue but wanted to double check
j
ah a mail piece from a domain squatting?
s
yes
typoSquatting
j
And they pass DMARC auth?
s
oh, that would help is we enabled you must have DMARC pass on. Do most people do that now? I found that blocked to many small buisness types in the past
Yeah, that wont work. “_*MARC email authentication*_: DMARC can help brands ensure their domain isn’t impersonated in phishing emails. DMARC enables email systems to detect and reject phony emails that appear to come from legitimate domains, before the email messages reach recipients’ inboxes. However, DMARC can’t prevent attacks that use domain names similar, but not identical, to a brand’s domain.”
j
Yeah DMARC won't stop a typoSquat, but it's also rare that a typoSquatter go for that level of authentication....unless targeted