SPF, DKIM, DMARC was never so simple! // EasyDMARC

  Рет қаралды 25,711

Christian Lempa

Christian Lempa

Күн бұрын

Пікірлер: 57
@dingokidneys
@dingokidneys 7 ай бұрын
Very nice clear guidance on what each is an how they work. Thanks for that.
@christianlempa
@christianlempa 7 ай бұрын
Glad it was helpful!
@falazarte
@falazarte 7 ай бұрын
Best video explaining these topics! You earned a new sub! Thank you.
@christianlempa
@christianlempa 7 ай бұрын
Thank you so much! :)
@marciifee
@marciifee 7 ай бұрын
BIMI costs money if they want the correct BIMI email security "add-on" topping :D. I am using the free version of BIMI, but you also forgot the also most important feature: MTA-STS, CAA, HSTS, and header security. Additionally, most people are reading and sending emails via a web browser, which leaves them vulnerable to man-in-the-middle attacks :)
@christianlempa
@christianlempa 7 ай бұрын
Yeah, well... you can make a video about all of this, it's gonna be 1h+ :D
@marciifee
@marciifee 7 ай бұрын
@@christianlempa I know, it's a huge topic :3 but the beauty of this is that not everyone is familiar with it. That's why I will always find my customers with it. :3
@Voigt_Analytics
@Voigt_Analytics 6 ай бұрын
@@christianlempaNope, you just have to say BIMI brings no real benefit, because only a handful of mail providers are using this; it‘s expensive; and other protocols are far more sophisticated.
@ulrikboesen
@ulrikboesen 7 ай бұрын
Thanks for the video. But as a homelab user, how could you fit in the free edition, its only supports one domain :)
@christianlempa
@christianlempa 7 ай бұрын
Don't complain about free stuff bro :D
@SGNetz
@SGNetz 7 ай бұрын
And how can I use this with my Mailcow?
@Trozpent
@Trozpent 7 ай бұрын
@Christian - I was wondering if you have ever setup a Hadoop environment. I've been really tempted with lookign to set one up for dealing with large amounts of data storage and processing.
@ddoecke
@ddoecke 6 ай бұрын
I wish I'd known about the 10 include statement thing a couple weeks ago - spent a while trying to figure out why it was happening before I found that info. And it was because one of the services we allow to send on our behalf had added an additional include in THEIR spf record, because apparently that 10 lookup limit counts all the nested Includes. Might have to look into that EasySPF - expand the extra lookups to IP addresses.
@christianlempa
@christianlempa 6 ай бұрын
Wow, that's interesting! I haven't heard before either, but thanks to EasyDMARC for teaching me :D
@krzysztofnowak7637
@krzysztofnowak7637 7 ай бұрын
18:40 Gmail does exactly that - it rejects emails from domains without an SPF record completely, and actually I think they do the right thing. It is also worth noting that DMARC checks the authorisation for the domain in the From header, not the SMTP FROM (the envelope From) as SPF does. And that's important because the From header value is usually the only thing the recipient sees. So it helps combat phishing emails sent from the attacker's domain that have the correct SPF but a fake domain in the From header.
@danielcastrorodriguez3934
@danielcastrorodriguez3934 7 ай бұрын
Thank you Christian!!
@christianlempa
@christianlempa 7 ай бұрын
Thanks for watching :)
@RK-ly5qj
@RK-ly5qj 7 ай бұрын
Dns sec is also worth to have ;)
@christianlempa
@christianlempa 7 ай бұрын
True!
@msmith1789
@msmith1789 7 ай бұрын
Great video Christian. Very informative. How does easydmarc compare to valimail?
@christianlempa
@christianlempa 7 ай бұрын
No idea, haven’t used valimail mysefl
@myuuiii
@myuuiii 7 ай бұрын
just as I gave up on setting up an email server :/
@christianlempa
@christianlempa 7 ай бұрын
You can still use it with M365 or Google workspace
@myuuiii
@myuuiii 7 ай бұрын
@@christianlempa Thank you! I’ll look into that :D, thanks for the great video!
@Darkk6969
@Darkk6969 7 ай бұрын
@@christianlempa I use ProtonMail to host my own domain and works pretty well with their services. During the migration of my domain it took me step by step and ProtonMail made sure I've added the proper SPF, DMARC and DKIM records to my Cloudflare DNS to ensure my e-mails are received properly. Worked like a champ. I am also Office 365 admin at work and had to dig around to find the DKIM settings. Thanks for pointing this out.
@keithmac3105
@keithmac3105 7 ай бұрын
sadly the free option is now switched to personal only
@christianlempa
@christianlempa 7 ай бұрын
:(
@markgresin6335
@markgresin6335 2 ай бұрын
So it's not a "for free" account like you said at 1:38. It is a 14 day trial. Not nice for you to make it sound free.
@christianlempa
@christianlempa 2 ай бұрын
There's still a free plan, where you can use some of the features like the tools, or managed DMARC, managed BIMI.
@DeNNiiiable
@DeNNiiiable 7 ай бұрын
it seems the free plan changed from 10000 emails to 1000. this might be eaten up just by notifications in most homelabs so i guess no thank you as we will do it the way we have always done
@fabienudriot3977
@fabienudriot3977 7 ай бұрын
Just in time! 🙂 And this is difficult info to find, so well and concisely explained. Thanks
@christianlempa
@christianlempa 7 ай бұрын
Glad it was helpful!
@Voigt_Analytics
@Voigt_Analytics 6 ай бұрын
This is not an option for me because I have multiple domains and I don't want to pay dozens of SaaS providers for a single use case. These records are something that needs to be set up perfectly once, and I have no intention of changing anything after that. There are other ways of monitoring the MX.
@fabs9930
@fabs9930 7 ай бұрын
This helped me understand spf, dkim and dmarc better. thx a lot!
@christianlempa
@christianlempa 7 ай бұрын
glad it helped :)
@simongajdosik5105
@simongajdosik5105 7 ай бұрын
Nice vid, but there is also mta-sts policy.
@christianlempa
@christianlempa 7 ай бұрын
thanks, yes that's true ;)
@simongajdosik5105
@simongajdosik5105 7 ай бұрын
@@christianlempa Would you consider to create vid also for that? It's very easy to add txt record, but many don't know about it at all.
@ALWALEEDALWABEL
@ALWALEEDALWABEL 7 ай бұрын
when are you going to make a self SMTP server video?
@AmirT.-lr7fk
@AmirT.-lr7fk 3 ай бұрын
Thank you, man, I've been struggling with this all day! May God bless you!
@ierosgr
@ierosgr 7 ай бұрын
At 1:43 where the easyDMARC site mentions 14 days data hιstory what does it mean? Afterwards the old incoming / sent emails will be lost? In order to use SPF you need to have a static IP? Else your IP will change as well like the attackers. Or the ability to use a txt record bypasses that need? Why all these records at cloudflare need not to be proxied?
@EdwinMartin
@EdwinMartin 4 ай бұрын
I’m pretty sure the DMARC success/fail messages are only kept for 14 days. The IP address in the SPF record is the address of the smtp server*, so it’s not a problem if you send mail from a dynamic IP address. *technically, it might not be the same IP address
@bojandimic3914
@bojandimic3914 7 ай бұрын
Very nice video, thank you Christian!
@christianlempa
@christianlempa 7 ай бұрын
thank you!
@jebucaro
@jebucaro 7 ай бұрын
Thank you, very useful!
@christianlempa
@christianlempa 7 ай бұрын
Thanks!
@ronm6585
@ronm6585 7 ай бұрын
Thank you.
@christianlempa
@christianlempa 7 ай бұрын
You're welcome!
@lekkimworld
@lekkimworld 7 ай бұрын
Having just migrated from paid gmail to Microsoft 365 Family I would love to understand how people run their email as I'm not really satisfied with the M365 solution and how it supports custom domains. If you run your own email server I'd love to hear how you do that including the UI you use for email etc.
@christianlempa
@christianlempa 7 ай бұрын
I'm currently using M365 myself because it's easy, and has many features for a fair price. But sure, you could also think about switching to Google Workspace, or run your own self-hosted mail server if you feel comfortable about it.
How to protect Linux from Hackers // My server security strategy!
30:39
Christian Lempa
Рет қаралды 223 М.
Stop email from going to spam
26:22
Syntax
Рет қаралды 2,6 М.
Watermelon magic box! #shorts by Leisi Crazy
00:20
Leisi Crazy
Рет қаралды 8 МЛН
LIFEHACK😳 Rate our backpacks 1-10 😜🔥🎒
00:13
Diana Belitskay
Рет қаралды 3,9 МЛН
Microsoft 365 SPF, DKIM and DMARC; Improve Your Email Security!
17:37
Jonathan Edwards
Рет қаралды 58 М.
Secure authentication for EVERYTHING! // Authentik
39:50
Christian Lempa
Рет қаралды 166 М.
World Wide Storage, on a Raspberry Pi.
38:21
Hardwood Homelab
Рет қаралды 1,1 М.
Email authentication Explained, SPF, DKIM, DMARC records
31:12
Office365Concepts
Рет қаралды 7 М.
How DKIM SPF & DMARC Work to Prevent Email Spoofing
17:15
Thobson Technologies
Рет қаралды 105 М.
Is it time to switch? // Docker vs Podman Desktop
16:05
Christian Lempa
Рет қаралды 234 М.
What is SPF, DKIM, DMARC, and BIMI | Easy Explanations
7:21
Jason Rebholz - TeachMeCyber
Рет қаралды 3,4 М.
Don’t run Proxmox without these settings!
25:45
Christian Lempa
Рет қаралды 222 М.
A Pi-Hole DNS server for my homelab - No Music
24:39
Hardwood Homelab
Рет қаралды 1,2 М.
Learning Docker // Getting started!
35:56
Christian Lempa
Рет қаралды 109 М.