Post

Andy
Andy@andy_waugh·
@robtlee @SANSInstitute Great response, thank you for being so open. Are you able to share any detail on what alerted you to the rule? I see the webcast overview says it was identified in "a systematic review of email configuration and rules” - did something trigger that review or was it just routine?
English
0
0
0
0
cybercdh
cybercdh@cybercdh·
@robtlee @SANSInstitute I wonder @robtlee if SANS are considering implementing a DMARC policy on their domain based off this event? From what I've seen, the email spoofs the recipient domain, so quarantining or rejecting DMARC failures could have helped prevent the initial delivery...?
English
0
0
0
0
Paylaş