#Email Security

Every story tagged Email Security, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

11 stories · open in the command center

  • Security & PrivacyHacker News3m

    SPF Record Syntax: Mechanisms, Qualifiers, Modifiers, and Macros

    SPF (Sender Policy Framework) is a critical email authentication mechanism that requires precise DNS configuration to prevent authentication failures across all organizational email; misconfigurations—even single syntax errors—can block legitimate mail delivery organization-wide, making SPF management a key IT responsibility alongside DMARC and DKIM implementation. For technology leaders, this means SPF records represent both a security control and an operational risk that demands careful governance, monitoring, and clear ownership within IT organizations to ensure email deliverability while maintaining authentication integrity.

  • Security & PrivacyHacker News3m

    What DMARC Protects You From, and What It Does Not

    DMARC is a narrowly-scoped authentication protocol that validates sender identity alignment but is frequently misunderstood as a comprehensive security solution against phishing and spoofing. IT leaders implementing p=reject policies believing they achieve phishing-proof email are at risk of false confidence, potentially neglecting critical controls for threats DMARC doesn't address, such as lookalike domains, display-name impersonation, and content-based attacks. Organizations must recognize DMARC's actual value—preventing exact-domain spoofing and generating visibility into unauthorized senders—while implementing complementary security layers to cover the gaps this protocol deliberately does not fill.

  • Security & PrivacyHacker News3m

    DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It

    Despite DMARC being available for 14 years, 68.4% of domains either lack DMARC records or fail to enforce authentication policies, with the primary bottleneck being the inability to identify and validate legitimate mail sources before implementing enforcement. Organizations are stuck in monitoring-only mode (p=none) due to the operational burden of analyzing complex, fragmented reporting data across dozens of vendors and one-off mailbox configurations. This widespread authentication gap represents a critical security vulnerability that directly impacts email delivery reliability, brand reputation protection, and regulatory compliance—making it a strategic priority for IT leaders overseeing email infrastructure and security.

  • Security & PrivacyHacker News3m

    DKIM2 and DMARCbis Have Landed

    DKIM2 and DMARCbis represent the first major advancement in email authentication protocols in two decades, addressing critical vulnerabilities in DKIM1 that enable message replay attacks, forwarding failures, and spoofing—threats that directly compromise organizational security posture and customer trust. These new standards establish verifiable chains of custody for email messages and replace outdated authentication mechanisms, making them essential updates for IT organizations responsible for email infrastructure and security. CIOs must plan migration strategies now, as widespread adoption will improve phishing defenses, reduce email infrastructure complexity, and strengthen domain protection against impersonation attacks.

  • Security & PrivacyHacker News3m

    Why DMARC's new "NP" tag can fail with DNSSEC

    A critical incompatibility exists between DMARC's new 'np' (non-existent subdomain policy) tag and DNSSEC's Compact Denial of Existence specification, causing the np tag to fail unpredictably on domains using DNSSEC with major providers like Cloudflare, AWS Route 53, and Azure. This vulnerability undermines email security controls for protecting unused subdomains from spoofing attacks, with no agreed-upon solution currently available from the IETF working group. Organizations relying on DNSSEC for DNS integrity face a gap in their email authentication defenses that could expose them to sophisticated phishing campaigns targeting non-existent subdomains.

  • Security & PrivacyHacker News3m

    Don't verify email addresses by sending spam to them

    A web application (Pangram) is sending unsolicited bulk emails to validate user email addresses during signup, disguising spam as legitimate verification messages while rotating through dozens of sender domains and retrying from blacklisted IP addresses. This practice violates email regulations (CAN-SPAM, GDPR), damages organizational reputation, exposes companies to legal liability, and undermines email deliverability infrastructure that IT leaders depend on for legitimate communications. CIOs must audit their organization's email validation practices and ensure development teams implement proper verification methods that comply with regulations and industry standards.

  • Security & PrivacyCIO Online5m

    Microsoft says you don’t need another email security tool; experts say, not so fast

    Microsoft claims its Defender for Office 365 catches nearly all malicious emails independently, with third-party tools adding less than 1% additional protection, but security experts caution that these aggregate percentages obscure the volume and sophistication of threats that do slip through—particularly AI-enabled targeted attacks. Given that even a single compromised email can trigger a breach, industry analysts strongly recommend maintaining a defense-in-depth strategy with multiple layers of email security rather than relying on a single vendor solution. This has significant implications for IT organizations considering consolidation around Microsoft's ecosystem, as the apparent marginal gains from additional tools must be weighed against the evolving threat landscape and the operational risk of vendor lock-in.

  • Security & PrivacyTechMemeMeir Orbach2m

    Ocean, which uses AI agents to detect email attacks, raised a $20M Series A led by Lightspeed, following an $8M seed in 2024 (Meir Orbach/CTech)

    Ocean, an AI-powered email security startup, has secured $20M in Series A funding to scale its intent-based threat detection platform that replaces traditional pattern-matching defenses. This funding round signals growing market confidence in AI agents as the next generation of email security, enabling IT leaders to move beyond legacy solutions toward more sophisticated, behavioral-analysis-driven threat prevention. For CIOs, this represents both a competitive pressure to modernize email security stacks and an opportunity to improve detection accuracy while reducing alert fatigue from conventional systems.

  • Security & PrivacyAndroid PoliceMatthew Mountjoy2m

    Google has added a new 'Verified Email' feature to make app sign-ups instant

    Google's new Verified Email feature eliminates friction from app authentication by leveraging cryptographically verified credentials already stored on Android devices, reducing reliance on OTP codes for sign-ups, account recovery, and sensitive actions. While this enhances user experience and security posture for consumer Gmail accounts, IT leaders must note the current limitation to personal Google accounts—Workspace and managed accounts remain restricted to legacy verification methods, creating a bifurcated authentication landscape. This shift signals Google's broader strategy to modernize credential management and presents both opportunities for improved user onboarding and challenges for enterprises managing hybrid identity ecosystems.

  • Security & PrivacyHacker News3m

    FSF trying to contact Google about spammer sending 10k+ mails from Gmail account

    The Free Software Foundation (FSF) is experiencing a significant spam incident involving 10,000+ emails originating from a Gmail account, and is seeking direct contact with Google to resolve the issue. This highlights ongoing challenges with email security controls and abuse prevention at major cloud providers, which can impact organizational communication reliability and security. For IT leaders, this underscores the dependency on third-party providers' responsiveness to security incidents and the potential for business disruption when abuse mitigation processes are inadequate.

  • Enterprise TechHacker News3m

    We have a 99% email reputation. Gmail disagrees

    A software company with a 99% email reputation score through SendGrid discovered their messages were being systematically filtered to spam by Gmail, which operates an independent reputation system that penalizes infrequent senders. This reveals a critical infrastructure challenge: email delivery systems now require constant high-volume sending to maintain 'IP warmth,' creating a catch-22 that punishes companies attempting to respect customer inbox preferences. The incident highlights how third-party platform algorithms can silently undermine direct customer communication channels, potentially impacting product launches and customer engagement without triggering obvious technical failures.

Browse all tags