Why Blacklisting isn’t really the problem..

If you are on a blacklist, then you’re feeling the urgency and pain of getting off the blacklist and restoring your ability to send email to customers, prospects and vendors – you’re ready to get back to business.  But, wait a second, what caused you to be blacklisted in the first place?

Causes of Blacklisting

  • Malware or Virus infection
  • Errant bulk email campaign
  • Random mail to spam traps or honeypots

You can control these issues with software that filters inbound and outbound email, but really, these are just symptoms of a greater problem – poor Email Delivery Management, meaning methodically developing best practices to ensure email gets to the inbox.

What is going on with email delivery?

Long gone are the days when you could fire off an email and assume it went directly into your customers’ inboxes.  Between spam filters, anti-virus programs, and blacklist-based email filters your email delivery is controlled by several layers of security.  But, do you know anything about how that security works?  Do you know if your email is getting through?  Do you get any feedback from users?  Blacklists are just part of the equation.  By the time you know you are on a blacklist, it’s already too late, your email is already being denied.

In addition, you are probably using several 3rd party companies to email for you.  These could include a bulk email service, marketing automation, forwarders or even rogue email systems sitting in your network.  Do you know if you or partners emailing on your behalf have good reputations with your customers, their inbox providers and those security tools I mentioned?  Do you get any feedback until you’re blacklisted?

In recent years, Google and Outlook.com have been rapidly gaining market share as inbox providers.  They and many other companies are prioritizing email that has passed SPF verification and is signed by a valid DKIM signature.  Are you ready for SPF and DKIM?  Do you know if all your 3rd party emailers are covered in your SPF record?

Finally, email spoofing is becoming one of the biggest methods for exploiting a company’s brand to obtain private information and user credentials.  Do you know who is leveraging your brand to spoof your customers?

How do you manage email delivery?

The short answer is to adopt three important technologies:

  • SPF – Enables you to tell the world who is legitimately allowed to send email on your behalf
  • DKIM – Enables you to sign email and take ownership of the quality of the email you send
  • DMARC – Enables you to publish an email address where you can receive feedback from inbox providers about the quality of the email coming from your domain and control how a provider processes email that fails SPF or DKIM.

With all three technologies, you take ownership for the email you send, designate additional senders for your domain and get feedback on email sent by you, your senders and potentially malicious senders.  This is the start of email delivery management.

Our Experts

MxToolbox is the expert in email delivery.  Our team of highly skilled specialists can help you setup SPF, DKIM and DMARC and begin to manage your email delivery.

After talking with dozens of clients, we realized that our customers needed help decoding DMARC reports and understanding:

  • Who is sending email purporting to be from your domain
  • What is the reputation of your domains and delegated IPs
  • Where other senders are and What their reputations are
  • How your SPF, DKIM and DMARC setup is performing
  • What senders are failing DKIM
  • What senders are failing SPF verification
  • When to setup more restrictive policies for DMARC

Check out MxDelivery Center and how our experts can help you better reach your customers.

Investigate by URL

With recent upgrades to the Investigator tool, we’re bringing you even more value and information!  In addition to Related IPs and Related Domains , we recently added the capability to lookup based upon a URL.

Now, you can submit a URL to Investigator and we will pull up all the information on the Domain and take a screenshot of the URL you submit.

Use the Investigator to see if a suspect URL looks like it might contain harmful content while you checkout the rest of the domain!

Investigator URL

MxToolbox Investigator is premium tool included with our MxWatch Monitoring plans.  You can also try a free version of Investigator.

Announcing MxDelivery Center

The only constant in the email world is change…

In the Dot.Boom era, most people discovered email for the first time.  Quickly thereafter malicious individuals discovered how to exploit the new technology for profit with unwanted email: SPAM.  So, businesses created blacklists, lists of IP addresses implicated in the distribution of SPAM, to stop them.  At the same time, a need for legitimate business to know if they were flagged as SPAM and blacklisted arose, and MxToolbox has been informing businesses of their online blacklist reputation ever since.

Over the last decade and a half, legitimate businesses started to employ email filtering and 3rd party mass email companies to keep their email servers off of blacklists and improve inbox delivery.  In addition, new techniques and standards were created to help businesses manage these relationships: SPF, DKIM, DMARC, etc.

What do these standards do?

SPF tells the world what IP addresses and Domains can send email on your behalf.

DKIM electronically signs emails you send to prove that they were actually sent by you.

DMARC provides a framework for how a receiver of your email should process any discrepancies they see with SPF and DKIM and how they should tell you about them so that you can improve your email deliverability.

These technologies fit together nicely, but understanding them and reporting on it is complex.  So, we thought we’d help…

Announcing MxDelivery Center

MxDelivery Center provides everything you need to manage a complex email setup that includes everything from your own servers, to mail hosting services (like Gmail or Outlook.com) and 3rd party emailers while reducing the risk to your brand from phishing and spoofing attacks.

ed-interface

MxDelivery Center combines:

  • RFC compliance checking and recommendations for SPF and DKIM configurations
  • In-depth processing of DMARC reports from your email recipients
  • Graphical representation of your DMARC compliance, SPF Verification and DKIM Verification
  • Insight into spoofing and phishing attacks carried out with your brand
  • Reputation of providers and emailers sending on your behalf

ed-reputationpage

Learn more about MxDelivery Center on the product page.

ed-configurationpage

Or, try our Free DMARC Report before you buy MxDelivery Center!

Our Suite of DNSSEC Tools

Recently, you might have an uptick in Denial of Service attacks or problems with root domain servers.  DNS, while the backbone of the internet, was always easy to spoof with man-in-the-middle attacks and other exploits.  To reduce the effects of these exploits, smart people in the industry created a standard to help secure DNS through a bolt-on security framework called DNSSEC.

Basically, DNSSEC enables an organization with DNS servers to vouch for a DNS entry that it serves to a requestor by signing it.  This is similar to new standards for other early unencrypted Internet protocols communications, like DKIM for email.  Using DNSSEC is like DKIM in that a provider publishes their signature in a separate DNS entry that can be queried by a DNSSEC aware client.  Clients in this way guard themselves against false DNS entries seeking to exploit them.

MxToolbox wants to make it easier for you to keep up on the latest security and networking standards, so we’ve created a suite of tools to help you with DNSSEC.  Check them out:

  • DS –  identifies the Delegation Signers (DS) for the specified domain
  • DNSKEY – returns the DNSSEC records for a domain
  • IPSECKEY –  returns the public key that resolvers can use to secure data at the IP layer using IPSEC
  • NSEC3PARAM – used by authoritative DNS servers to calculate and determine which NSEC3-records
  • NSEC – identifies the next secure (NSEC) record for the specified domain
  • RRSIG – identifies the Resource Record Signatures for the specified domain

Let us know how you like these tools!  Email us at feedback.

Security Tools

Over the last few years, Security has become a huge concern for many companies. MxToolbox has always made email security information accessibility a primary concern – after all, blacklisting is a sign of greater security problem.  However, we feel like reputation is only one (important) part of the security equation.  That’s why we’re happy to highlight some of the new Security Tools we’ve created to make it easier to do your daily security related work and investigate any issues that might arise.

IP and Domain Reputation

Whether you’re researching a potential partner or an incident, understanding the online reputation of an IP address or Domain is incredibly important.

Blacklist

Presence on a blacklist is a clear indicator of an issue with an IP or Domain.  Use MxToolbox’s Blacklist tool to research an individual IP or Domain’s reputation.  The more blacklists an IP or Domain is on, the more egregious the problem and more likely there is a virus or malware infection or other problem.

Investigating a Domain

Our new Investigator tool give you every piece of information you might want on a Domain or URL:

  • Related IP address with reverse DNS, ASN, Geolocation and more
  • Related Domains
  • DNS Nameserver
  • MX record analysis
  • SPF Record analysis
  • Blacklists
  • Whois data

With Investigator, you get all this information in a single-pane view, allowing you to do quick analysis of potential trouble.

mxtoolbox_investigator_email

Checking Large IP ranges

Imagine knowing immediately when one of your hundreds, thousands or millions of IP addresses is compromised by a bad reputation.  While Blacklisting is traditionally caused by sending spam or malware, it could be a result of maintaining servers with a security posture that is open to attack.  Knowing your network reputation is therefore an important part of your security knowledge.

MxToolbox Service Provider allows you to keep tabs on the blacklist reputation of an entire continuous block of IP addresses.  Designed to give you constant updates on your large IP networks, MxToolbox Service Provider alerts you when any changes to your reputation occur giving you instant warning of potential security issues.

SP Graphs

Incident Analysis

When you have an incident the important thing to do is quickly analyze potential source and refining the precise issue.  For that you need a quick way to analyze your log files and then dig into potential abusers.

Looking at Logs with Bulk Lookup

What do you do with a big log file full of IP addresses and domains that could contain your abuser?  Do you go through it by hand looking for odd IPs or strange domains?

How about a tool where you could dump the entire log file, have it parsed and then lookup all the IPs or domains in a single bulk lookup?  That’s why we created our Bulk Lookup Tool.  Bulk Lookup gives you:

  • Reverse IP Address (for domains)
  • AS Number
  • AS Name
  • Geo Location
  • Blacklist Status
  • Start of Authority (SOA)
  • MX Records
  • Nameservers
  • Email Provider
  • DNS Provider

 

DNSBatch_results

You can correlate sites by ASN and DNS/Email service provider, highlight sites with bad blacklist reputations and identify those in geographies known to be troublesome our outside your client area.  With all this information available you can select those that need further investigation with Investigator or our Networking Tools.

Networking tools

MxToolbox has always provided free tools that simplify your server setup, DNS configuration checks and network evaluation, but many customers use them to pursue security investigations.

Think about the power of being able to Ping, Traceroute or investigate the DNS setup of a suspect server.  Or get realtime reputation information on an IP address hitting your servers.  Or get information on the email configuration of a troubling message.

Our tools give you tremendous flexibility to find the information you need on domains and IP addresses to simplify your security research.

What is DMARC?

DMARC is a type of email authentication protocol that leverages the widely used SPF and DKIM protocols to improve a sender’s understanding of how their email in circulation is processed.  Email claiming to be from their domain is analyzed by receiving organizations and a digest of acceptance/failures is sent back to the sender.  DMARC is used to reduce spam and fraudulent email by giving senders information on what recipients see.  DMARC stands for Domain-based Message Authentication, Reporting & Conformance.

How is DMARC setup?

DMARC uses DNS to publish information on how an email from a domain should be handled.  Because it uses DNS, anyone can publicly access your DMARC record to see how to process email that is reportedly from your domain.  This also makes it simple to deploy, only requiring a DMARC (TXT) record.

dmarc-googlerecord

An example DMARC record from Google.com.

How is it used?

DMARC is used in conjunction with SPF and DKIM.  Essentially a sender’s DMARC record tells a recipient what to do with suspicious email purporting to come from a sender.  Does it have a proper DKIM signature (and should it)?  Does it match authorized senders in the SPF record?  Should I pass it on, quarantine it or send it back?  Finally, is there an email address I can forward information about suspicious emails so that the sender is aware of the problem?  DMARC records contain all of these policy decisions.

Why do I need DMARC?

DMARC helps in the fight against malicious email practices that put your business in danger.  Whether you are doing e-commerce or offline sales, your business uses email as a primary means of communication with employees, customers and suppliers.  Unsecured email is easy to spoof and increasingly sophisticated criminals are finding lucrative ways to utilize email.  DMARC helps senders and receivers of email work together to better secure email and reduce spoofing.

MxToolbox Tools for DMARC

MxToolbox has the free tools you need to test your DMARC setup and compare it to best practices.  MxToolbox’s DMARC lookup checks your DNS DMARC record for availability and compatibility with RFCs, which is especially useful when you setup your initial DMARC record.

dmarc-googleresults

A simple DMARC record for Google.com. This one instructs recipients to reject email that comes from Google.com that doesn’t pass DKIM and SPF and where to send the feedback about rejected emails.

dmarc-outlookrecord

A more complex DMARC record used by Outlook.com

Once your record is setup, it is a good idea to monitor your DMARC record to make sure it is publicly accessible.  MxToolbox Monitoring Solutions provide a first-line defense against missing or lost DNS records, like your DMARC record.

What’s coming?

MxToolbox is dedicated to making it easier for you to get your message through to your customers, by providing free tools and paid services like monitoring.  We have introduced a free DMARC reporting tool that takes your recipients DMARC responses and allows you to analyze them.

Coming SOON! We will have an advanced service that goes into more depth on DMARC reporting including your email delivery statistics, setup issues with DKIM and SPF and the reputation of all your sending and receiving servers.

What is DKIM?

DKIM, standing for DomainKeys Identified Mail, is a method where a sender (or forwarder) can take responsibility for the content of an email by digitally signing for the message.  A DKIM signature is added to the header of any outbound email message that a sender would like to vouch for.  The recipient can then compare this DKIM signature to a publicly available DKIM key that decodes it.  If successfully decoded, the message is authenticated as being from that sender.  Otherwise, the recipient can choose to run more intense checks on the email, quarantine or discard it.

A receiver using DKIM will be able to reduce inbox delivery of erroneously forwarded or spoofed email received.  This greatly reduces the potential for abuse as recipients now have more information on the sender.

Should I setup DKIM?

Absolutely!  Both email senders and receivers should be using DKIM on their email systems.  While DKIM does not itself filter email, the DKIM signature is important in your overall delivery/rejection process.  Regardless of the volumes of outbound email, a sending organization should use a DKIM key to sign for email.  This attaches your reputation to the email and makes it easier for customers to trust that email is coming from you.  If there isn’t a signature on email that looks like it comes from you, then it could be spoofed.  It’s better to stand behind what you send.

Similarly, if you aren’t scanning incoming email for DKIM signatures, you are opening yourself up to potential attacks.  At minimum, you are treating all email the same and need to run more checks on incoming email against blacklists, scan for viruses and malware, which can be more taxing than a simple DKIM check.

DKIM works hand-in-hand with SPF and DMarc to help senders and receivers better communicate on the quality of email being sent.  Overtime, these technologies will dramatically reduce spam, spoofing and other unsafe mail delivery.

How do I get a DKIM key?

We often refers customers to one of the many services that will generate a key for you.  Right now, we recommend letsencrypt.org.

MxToolbox Tools for DKIM

A DKIM sender may have several DKIM records, so MxToolbox DKIM Lookup searches the specific record selector you request (see below).  DKIM lookup results are parsed and compared to RFCs to alert you to issues.  The example below contains a very simple DKIM record.

dkim-lookup

MxToolbox provides a free DKIM lookup tool that provides a lookup of your DKIM records by selector.

 

dkim-results

Results of a typical DKIM record are parsed and explained.

Get Support!

As a paid MxToolbox.com user, you get access to our expert Support team.  Open a ticket to get access to the best advice on improving your email delivery including setting up SPF and implementing DKIM and Dmarc.