SPF, DKIM, DMARC was never so simple! // EasyDMARC

preview_player
Показать описание
In this video, I will be discussing the importance of outbound email security and how it can protect your company's reputation. I will introduce you to technologies such as SPF, DKIM, DMARC, and BIMI, and explain how they work together to prevent email fraud and spoofing. Additionally, I will be showcasing EasyDMARC, a cloud native service provider that offers advanced managed solutions for mid-sized to large enterprises, as well as free tools for Homelab users.

________________

💜 Support me and become a Fan!

💬 Join our Community!

________________

Read my Tech Documentation

My Gear and Equipment-*

________________

Timestamps:

00:00 Introduction
01:32 What is EasyDMARC?
02:50 You need outbound email security!
04:06 Connect your domain
05:41 SPF
12:52 DKIM
18:14 DMARC
22:45 BIMI

________________
All links with `*` are and/or include affiliate links.
Рекомендации по теме
Комментарии
Автор

18:40 Gmail does exactly that - it rejects emails from domains without an SPF record completely, and actually I think they do the right thing.

It is also worth noting that DMARC checks the authorisation for the domain in the From header, not the SMTP FROM (the envelope From) as SPF does. And that's important because the From header value is usually the only thing the recipient sees. So it helps combat phishing emails sent from the attacker's domain that have the correct SPF but a fake domain in the From header.

krzysztofnowak
Автор

Very nice clear guidance on what each is an how they work. Thanks for that.

dingokidneys
Автор

This helped me understand spf, dkim and dmarc better. thx a lot!

fabs
Автор

Best video explaining these topics! You earned a new sub! Thank you.

falazarte
Автор

Thank you, man, I've been struggling with this all day!

May God bless you!

AmirT.-lrfk
Автор

BIMI costs money if they want the correct BIMI email security "add-on" topping :D. I am using the free version of BIMI, but you also forgot the also most important feature: MTA-STS, CAA, HSTS, and header security. Additionally, most people are reading and sending emails via a web browser, which leaves them vulnerable to man-in-the-middle attacks :)

marciifee
Автор

Just in time! 🙂
And this is difficult info to find, so well and concisely explained. Thanks

fabienudriot
Автор

Great video, I loved it! Christian, saw some other videos and enjoyed every minute.

segalnoam
Автор

At 1:43 where the easyDMARC site mentions 14 days data hιstory what does it mean? Afterwards the old incoming / sent emails will be lost?
In order to use SPF you need to have a static IP? Else your IP will change as well like the attackers. Or the ability to use a txt record bypasses that need?
Why all these records at cloudflare need not to be proxied?

ierosgr
Автор

And how can I use this with my Mailcow?

vnetz
Автор

@Christian - I was wondering if you have ever setup a Hadoop environment. I've been really tempted with lookign to set one up for dealing with large amounts of data storage and processing.

WolfSparc
Автор

Thanks for the video. But as a homelab user, how could you fit in the free edition, its only supports one domain :)

ulrikboesen
Автор

I wish I'd known about the 10 include statement thing a couple weeks ago - spent a while trying to figure out why it was happening before I found that info. And it was because one of the services we allow to send on our behalf had added an additional include in THEIR spf record, because apparently that 10 lookup limit counts all the nested Includes.

Might have to look into that EasySPF - expand the extra lookups to IP addresses.

ddoecke
Автор

I hate email so much. Easily the most annoying service to set up

syrusk
Автор

when are you going to make a self SMTP server video?

ALWALEEDALWABEL
Автор

Very nice video, thank you Christian!

bojandimic
Автор

This is not an option for me because I have multiple domains and I don't want to pay dozens of SaaS providers for a single use case. These records are something that needs to be set up perfectly once, and I have no intention of changing anything after that. There are other ways of monitoring the MX.

Voigt_Analytics
Автор

just as I gave up on setting up an email server :/

myuuiii
Автор

Great video Christian. Very informative. How does easydmarc compare to valimail?

msmith
Автор

Having just migrated from paid gmail to Microsoft 365 Family I would love to understand how people run their email as I'm not really satisfied with the M365 solution and how it supports custom domains. If you run your own email server I'd love to hear how you do that including the UI you use for email etc.

lekkimworld
visit shbcf.ru