Forum Discussion
nikitamobile85
Apr 19, 2021Copper Contributor
Someone spoofed my company's domain
Good afternoon,
someone has spoofed my company's domain and is sending hundreds of emails to random organizations worldwide. He is using one of the valid email accounts to impersonate and as a result one of our users was receiving 20-30 replies from unknown people. We have enabled DMARC reject policy and it gave an effect. I can see that multiple attempts are now being rejected due to SPF check failure. However DMARC doesn't protect in 100% cases and some of the emails are still being delivered. I believe these are those cases where receiving side is not validating SPF/DKIM. I'm getting multiple DMARC reports and can see source IP addresses for spoofing emails. All of them are from GoDaddy IP range but GoDaddy is not replying to abuse reports. My question: Whether there is any other way to complain and stop this?
- NNS51875Copper ContributorI suggest please check with your Internal security team there are various way!
Please deploy Azure Defender to protect your Public DNS as we all IaaS and PaaS workload, start adopting "Zero Trust security model" and Defender for endpoint , Azure ATP, MCAS and AIP and for that you M365 license E5, which more effective. - Reza_AmeriSilver ContributorMake sure instruct users about this spam and when they receive it, then mark it as Junk (instead of deleting) and this way your Anti-Spam filter will gets smarter
- Sadly it's not that easy, best thing to do is harden things on your end and keep on reporting them.