Shakespeare, Brutus, and DMARC
Santosh Pandit
Regulator ? Creator of “Hard.Email” ? Author of “Cyber Landscape in 2035” ?
Friends and followers:
I am going to use some words from Shakespeare today, and oh boy, he was good at calling a spade a spade.
To find ourselves dishonourable graves. Men at some time are masters of their fates.
The fault, dear Brutus, is not in our stars, But in ourselves, that we are underlings.
ProofPoint wrote an article last week about a cybercriminal group, which deploys various tricks including abusing DMARC. It is a nice article, I suggest you read it when you have the time.
Preventing DMARC Abuse
The zero-dollar question is, "Are businesses preventing DMARC abuse?"
The reason I call it a "zero-dollar question" is because it costs nothing. You do not need to be a Global Fortune Giant to do DMARC properly. And yet, four out of the top ten in the Fortune list are not implementing DMARC properly.
There is always a risk that DMARC records themselves can be manipulated by highly sophisticated cyber attackers and therefore using DNSSEC becomes essential. There you will find that only one out of Fortune top ten are using DNSSEC.
What would Shakespeare say today?
In the modern world that we live in, we could well say:
"The fault, dear Brutus, is not in hackers, But in ourselves, that we are reckless.
To find ourselves dishonourable emails. Men at some time are masters of their fates."
I do not expect you to agree with me. But I would like you to be honest and strict with yourself and your service providers.
Santosh Pandit
22.4.2024