Most of us have heard of phishing, ransomware and CEO fraud. These terms cover some of the many inventive email scams that an increasing number of companies and individuals are falling victim to. It's a shame to fall victim to these scams, but it's just as bad if they are committed in your name. Not only does it cost you money, it also costs you credibility, and deeply damages trust in email as a form of communication.
While large organizations such as SKAT, Nets and Postnord have been exploited in phishing, cybercriminals are increasingly targeting smaller companies from which customers and users do not expect fraud. We are already seeing this with so-called CEO fraud.
As hackers get smarter and technology becomes more advanced, so do the scams. Recent ransomware epidemics (such as WannaCry in May 2017) have revealed that the activation of the malware does not always depend on clicking a link or opening an attachment - actions most people now know to be wary of. Instead, the software has been able to spread on your computer, encrypt files and demand a ransom all by itself. It's more important than ever that malicious emails don't reach the inbox at all, and this is where increased awareness and critical thinking fail. Technical security measures are needed.
Center for Cybersecurity recommends DMARC
The Center for Cyber Security continuously assesses the threat level of cybercrime in Denmark. In the latest report from May, the threat is assessed to be VERY HIGH. Danish organizations and companies are therefore recommended to implement DMARC technology, which helps secure a domain name from being misused and protects the recipient's security as well as the sender's credibility.
It's all about sender identification and verification
In almost all forms of email fraud, the sender poses as someone else - typically a person or organization that the recipient trusts. Therefore, email security is all about identifying and verifying the sender of an email. It sounds simple, but unfortunately it's not.
If we compare it to traditional mail, we can think of the envelope and the letter itself inside and the sender information given in both places. If you receive a letter from your aunt, Kirsten Kristoffersen, she might sign herself as "Aunt Kirsten" in the letter itself, while on the outside of the envelope she will give her full name and address, i.e. some technical sender information.
When it comes to emails, the technical sender information is incomprehensible to the layman, which is why you don't see the "envelope" in your inbox. Instead, you see the sender information as the sender wants the recipient to see it, i.e. "Aunt Kirsten" and not "Kirsten Kristoffersen, Svanevænget 9, 5000 Odense C". Often this is exactly what is exploited in phishing and other forms of email fraud.
How DMARC works
DMARC stands for Domain-based Message Authentication, Reporting & Conformance.
By implementing a DMARC standard, you set up guidelines for how an email's authenticity (i.e. its authenticity and origin) is assessed by the recipient and whether it can be approved and delivered to the inbox.
DMARC is based on two auxiliary technologies, SPF record and DKIM, which each check the identity of the sender: DKIM by assigning the email a digital signature that verifies that the sender is who they claim to be; SPF by comparing the technical sender information with a central registry where the domain owner has specified which servers are authorized to send out emails in the domain's name.
If we compare this to traditional mail, it would mean that Aunt Kirsten had to use NemID to send a letter and that the postal service checked the population register to see if Kirsten was correctly registered at the specified sender address.
Many companies have already set up an SPF record, which is a good step towards good email security. However, by implementing DMARC, the level of security is significantly increased because sender authenticity is checked in two different ways. At the same time, DMARC has the important advantage that it also includes a reporting function that gives the domain owner feedback on the delivery of sent emails. This doesn't happen with SPF, which means you don't have the opportunity to act on any abuse.
Global Cyber Alliance has published a short and clear video about DMARC. Watch it here here
The extra gain
If you have a large customer database that you regularly send newsletters to, there is an extra benefit to be gained. The major email providers such as Google, Yahoo etc. have already implemented DMARC and rate incoming emails with DMARC standard higher than emails without.
By proactively taking care of your email security, you create optimal conditions for your emails to reach their recipients and not get bounced, quarantined or end up in spam filters.
Contact us on 70 100 150 to learn more about how we can help you secure your email security and improve your email deliverability.