How to use ESA to block spoof emails (using Emkei tool)

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-21-2019 12:11 AM
Hi team,
I am testing an ESA with the SPF and Check Sender DNS features enable. At that time, I use this tool: https://emkei.cz/ to spoof an email to send to my real email. I did create the fake email (but using my correct email) to send to my real email.
Unfortunately, the ESA did not block that spoof email and I still get the fake one. and the ESA did not show any proof to block.
Highly appreciate that any guys can explain to me that how this tool work and how to block it on the ESA?
Thanks in advance.
Br,
hainm
- Labels:
-
Email Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-21-2019 01:16 AM
Can you explain more about your setup, how your topology (what kind of email Servers you have behind ESA)
If ESA handling all your in and outgoing email SMTP traffic?
Look at the this example setup :
also grep the logs and post to forum to look what is wrong ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-22-2019 08:21 AM - edited 03-22-2019 09:11 AM
Check the Tracking Logs
Make sure the email is showing that SPF and DMARC validation is occurring. ( or check the Authentication header on the email )
By enabling / checking SPF and DMARC on incoming messages doesn't necessarily mean its blocked.
You may have enabled SPF in HAT - just records results.
Plus set the DMARC profile to deliver rather than abide by the domains DMARC Policy.
Do you have the DMARC profile set to action - such as Quarantine / Drop.
Do you have a Message or Content Filter to action based on the SPF result.
Personally, I use a cascading Email Authentication Message Filter to check the results of SPF, DKIM and DMARC to make a decisions based on the various permutations that may occur and what action to take for each.
