1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:03,150
we're going to discuss email security.

3
00:00:03,150 --> 00:00:05,100
Email security is a critical aspect

4
00:00:05,100 --> 00:00:06,780
of modern digital communication

5
00:00:06,780 --> 00:00:08,910
that involves various techniques and protocols

6
00:00:08,910 --> 00:00:11,220
to safeguard email content, accounts,

7
00:00:11,220 --> 00:00:13,740
and infrastructure from unauthorized access,

8
00:00:13,740 --> 00:00:15,840
lost or compromised.

9
00:00:15,840 --> 00:00:18,150
Some of these techniques includes the configuration

10
00:00:18,150 --> 00:00:22,290
of DKIM, SPF, DMARC,

11
00:00:22,290 --> 00:00:25,830
email gateway protocol and spam filtering mechanism.

12
00:00:25,830 --> 00:00:28,590
First, let's discuss DKIM.

13
00:00:28,590 --> 00:00:32,729
DKIM or the domain keys identified mail allows the receiver

14
00:00:32,729 --> 00:00:34,500
to check if the email was actually sent

15
00:00:34,500 --> 00:00:36,630
by the domain it claims to be sent from,

16
00:00:36,630 --> 00:00:39,600
and if the content was tampered with during transit.

17
00:00:39,600 --> 00:00:43,020
DKIM works by adding a digital signature to the headers

18
00:00:43,020 --> 00:00:45,120
of the email, which can then be validated

19
00:00:45,120 --> 00:00:47,460
against a public cryptographic key

20
00:00:47,460 --> 00:00:50,160
that is located on the domain's DNS records.

21
00:00:50,160 --> 00:00:54,180
For example, if someone at diontraining.com sends an email,

22
00:00:54,180 --> 00:00:57,570
the receiving server can check the DKIM signature against

23
00:00:57,570 --> 00:00:59,790
diontraining.com's public key.

24
00:00:59,790 --> 00:01:01,950
If the digital signature matches, this confirms

25
00:01:01,950 --> 00:01:04,980
that the email is genuinely from diontraining.com

26
00:01:04,980 --> 00:01:07,020
and that it hasn't been modified during transit

27
00:01:07,020 --> 00:01:09,480
from our service to your email server.

28
00:01:09,480 --> 00:01:12,330
DKIM can provide us with numerous benefits

29
00:01:12,330 --> 00:01:13,980
like email authentication,

30
00:01:13,980 --> 00:01:16,230
protection against email spoofing,

31
00:01:16,230 --> 00:01:18,227
improved email deliverability,

32
00:01:18,227 --> 00:01:20,340
and an enhanced reputation score.

33
00:01:20,340 --> 00:01:22,582
Second, we have SPF.

34
00:01:22,582 --> 00:01:25,230
SPF, or the sender policy framework,

35
00:01:25,230 --> 00:01:27,510
is an email authentication method designed

36
00:01:27,510 --> 00:01:31,530
to prevent forging sender addresses during email delivery.

37
00:01:31,530 --> 00:01:34,650
When an SPF enabled server receives email,

38
00:01:34,650 --> 00:01:37,260
it can verify the sender's IP address against a list

39
00:01:37,260 --> 00:01:39,270
of authorized IPs published

40
00:01:39,270 --> 00:01:41,760
in the sender's domain DNS records.

41
00:01:41,760 --> 00:01:45,660
For example, if someone at diontraining.com sends an email,

42
00:01:45,660 --> 00:01:47,940
the receiving email server will first check

43
00:01:47,940 --> 00:01:51,750
if the IP address of the sender is listed in the SPF record

44
00:01:51,750 --> 00:01:54,720
of diontraining.com before accepting it.

45
00:01:54,720 --> 00:01:56,160
If the IP address is not listed

46
00:01:56,160 --> 00:01:58,470
as authorized in the sender's policy framework,

47
00:01:58,470 --> 00:02:00,420
then the email will be marked as spam

48
00:02:00,420 --> 00:02:02,820
or it will be rejected by the email server.

49
00:02:02,820 --> 00:02:05,100
Some of the benefits of implementing SPF

50
00:02:05,100 --> 00:02:07,050
include preventing email spoofing,

51
00:02:07,050 --> 00:02:08,982
improved email deliverability,

52
00:02:08,982 --> 00:02:11,009
and enhanced domain reputation.

53
00:02:11,009 --> 00:02:15,600
Third, we have D-M-A-R-C configuration, or DMARC.

54
00:02:15,600 --> 00:02:19,170
DMARC or Domain-based Message Authentication, Reporting,

55
00:02:19,170 --> 00:02:22,170
and Conformance is an email validation system designed

56
00:02:22,170 --> 00:02:24,750
to detect and prevent email spoofing.

57
00:02:24,750 --> 00:02:27,930
DMARC allows the administrative owner of a domain

58
00:02:27,930 --> 00:02:31,410
to publish a policy on which mechanisms should be employed

59
00:02:31,410 --> 00:02:33,660
when sending emails from that domain

60
00:02:33,660 --> 00:02:36,030
and how the receiver should deal with the failures.

61
00:02:36,030 --> 00:02:39,540
DMARC can work with either DKIM, SPF,

62
00:02:39,540 --> 00:02:42,000
or both depending on how you configure it.

63
00:02:42,000 --> 00:02:45,360
For example, a company like diontraining.com sets up

64
00:02:45,360 --> 00:02:48,540
a DMARC policy that instructs receiving email service

65
00:02:48,540 --> 00:02:50,490
to reject any emails that claim

66
00:02:50,490 --> 00:02:52,890
to come from diontraining.com,

67
00:02:52,890 --> 00:02:56,880
but have already failed the DKIM or SPF checks.

68
00:02:56,880 --> 00:02:59,370
This will be a proper way to implement DMARC

69
00:02:59,370 --> 00:03:01,890
in order to increase your email security.

70
00:03:01,890 --> 00:03:04,410
The primary purpose of implementing DMARC is

71
00:03:04,410 --> 00:03:06,450
to protect a domain from being used

72
00:03:06,450 --> 00:03:08,670
in business email compromised attacks,

73
00:03:08,670 --> 00:03:10,800
phishing emails, email scams,

74
00:03:10,800 --> 00:03:13,140
and other cybersecurity threat activities.

75
00:03:13,140 --> 00:03:14,910
In our modern enterprise networks,

76
00:03:14,910 --> 00:03:17,790
every email server should be configured to use DMARC

77
00:03:17,790 --> 00:03:19,380
as a minimum level of protection

78
00:03:19,380 --> 00:03:21,990
against email-based scams and attacks.

79
00:03:21,990 --> 00:03:23,640
Fourth, we have the configuration

80
00:03:23,640 --> 00:03:25,770
of our email gateway protocol.

81
00:03:25,770 --> 00:03:28,800
An email gateway is a server or a system that serves

82
00:03:28,800 --> 00:03:31,560
as the entry and exit point for emails.

83
00:03:31,560 --> 00:03:34,830
This gateway is then responsible for handling the transfer

84
00:03:34,830 --> 00:03:38,070
of emails between the Internet and a local network.

85
00:03:38,070 --> 00:03:40,740
Email gateways are crucial for ensuring the secure

86
00:03:40,740 --> 00:03:42,811
and efficient transmission of emails.

87
00:03:42,811 --> 00:03:45,030
Email gateways usually rely

88
00:03:45,030 --> 00:03:48,360
on the simple mail transfer protocol or SMTP

89
00:03:48,360 --> 00:03:50,730
to send and receive emails.

90
00:03:50,730 --> 00:03:52,653
When an email is sent, it first passes through

91
00:03:52,653 --> 00:03:54,570
to a sender's email gateway

92
00:03:54,570 --> 00:03:56,670
before it's sent over the internet.

93
00:03:56,670 --> 00:03:59,190
Once the email reaches the recipient's domain,

94
00:03:59,190 --> 00:04:02,130
it will then go through the recipient's email gateway

95
00:04:02,130 --> 00:04:05,414
before it's delivered to the intended recipient inbox.

96
00:04:05,414 --> 00:04:09,000
Email gateways are implemented to help with email routing,

97
00:04:09,000 --> 00:04:11,030
email security, policy enforcement,

98
00:04:11,030 --> 00:04:14,310
and the encryption and decryption of emails.

99
00:04:14,310 --> 00:04:16,860
Our organization's email gateway is primarily responsible

100
00:04:16,860 --> 00:04:19,890
for routing outgoing emails to the correct destination

101
00:04:19,890 --> 00:04:21,750
and directing incoming emails

102
00:04:21,750 --> 00:04:23,640
to the appropriate user inboxes.

103
00:04:23,640 --> 00:04:26,970
These email gateways also provide us with higher levels

104
00:04:26,970 --> 00:04:29,160
of email security by helping to protect us

105
00:04:29,160 --> 00:04:31,860
against threats like spam, phishing, and malware

106
00:04:31,860 --> 00:04:34,800
by scanning each incoming or outgoing email

107
00:04:34,800 --> 00:04:37,371
for malicious content or suspicious pattern.

108
00:04:37,371 --> 00:04:40,410
We can also use our email gateways as a method

109
00:04:40,410 --> 00:04:42,780
of enforcing policies that have been set forth

110
00:04:42,780 --> 00:04:44,970
by our organization, such as being able

111
00:04:44,970 --> 00:04:46,920
to block any outgoing emails

112
00:04:46,920 --> 00:04:49,080
that might contain sensitive information,

113
00:04:49,080 --> 00:04:50,910
or you could block incoming emails

114
00:04:50,910 --> 00:04:53,520
from a specific or known malicious user.

115
00:04:53,520 --> 00:04:55,260
In addition to all of these features,

116
00:04:55,260 --> 00:04:58,020
our email gateways can provide email encryption services

117
00:04:58,020 --> 00:05:01,470
by encrypting outgoing emails and decrypting income emails

118
00:05:01,470 --> 00:05:04,110
to protect your organization's sensitive information.

119
00:05:04,110 --> 00:05:06,390
These email gateways can be installed and configured

120
00:05:06,390 --> 00:05:08,610
as either an on-premise, cloud-based,

121
00:05:08,610 --> 00:05:10,290
or hybrid email gateway.

122
00:05:10,290 --> 00:05:12,930
An on-premise email gateway is a physical server

123
00:05:12,930 --> 00:05:15,600
that's located within the organization's own data center

124
00:05:15,600 --> 00:05:17,910
or premises that provides an organization

125
00:05:17,910 --> 00:05:20,340
with full control over their email system.

126
00:05:20,340 --> 00:05:22,230
This gives us the most flexibility

127
00:05:22,230 --> 00:05:24,960
when we opt to use the on-premise solution,

128
00:05:24,960 --> 00:05:25,980
but it does require

129
00:05:25,980 --> 00:05:28,290
that our system administrators maintain the system

130
00:05:28,290 --> 00:05:30,270
and update it as needed over time.

131
00:05:30,270 --> 00:05:32,730
A cloud-based email gateway is an email gateway

132
00:05:32,730 --> 00:05:35,610
that is hosted by a third party cloud service provider

133
00:05:35,610 --> 00:05:37,260
to provide us with the greatest scalability

134
00:05:37,260 --> 00:05:38,760
and ease of maintenance,

135
00:05:38,760 --> 00:05:40,320
but this can be more expensive

136
00:05:40,320 --> 00:05:42,300
to operate than an on-premise solution,

137
00:05:42,300 --> 00:05:43,380
and you'll be limited

138
00:05:43,380 --> 00:05:45,420
to the cloud service provider's security measures

139
00:05:45,420 --> 00:05:47,610
when determining your exact configurations.

140
00:05:47,610 --> 00:05:50,550
A hybrid email gateway is used to combine the benefits

141
00:05:50,550 --> 00:05:52,770
of both on-premise and cloud-based gateways

142
00:05:52,770 --> 00:05:54,540
into a single offering by attempting

143
00:05:54,540 --> 00:05:56,940
to achieve a good balance between more control

144
00:05:56,940 --> 00:05:57,840
and more convenience.

145
00:05:57,840 --> 00:05:59,970
Finally, let's quickly discuss the concept

146
00:05:59,970 --> 00:06:01,170
of spam filtering.

147
00:06:01,170 --> 00:06:03,810
Spam filtering is a process of detecting unwanted

148
00:06:03,810 --> 00:06:06,120
and unsolicited emails and preventing them

149
00:06:06,120 --> 00:06:07,980
from reaching a user's inbox.

150
00:06:07,980 --> 00:06:10,320
Spam filtering usually involves various techniques

151
00:06:10,320 --> 00:06:13,140
such as content analysis, Bayesian filtering,

152
00:06:13,140 --> 00:06:17,580
DNS-based sinkhole list, and general email filtering rules.

153
00:06:17,580 --> 00:06:21,030
For example, if an email contains words commonly associated

154
00:06:21,030 --> 00:06:24,330
with spam messages like lottery, free, prize,

155
00:06:24,330 --> 00:06:26,910
or other commonly used spamming languages,

156
00:06:26,910 --> 00:06:30,120
then your enterprise network spam filter might flag it

157
00:06:30,120 --> 00:06:33,330
as potentially being spam and move it to the spam folder.

158
00:06:33,330 --> 00:06:36,630
So remember, email security can be improved

159
00:06:36,630 --> 00:06:39,180
by using various techniques including the configurations

160
00:06:39,180 --> 00:06:42,420
of DKIM, SPF, DMARC,

161
00:06:42,420 --> 00:06:45,840
email gateway protocols, and spam filtering mechanisms.

162
00:06:45,840 --> 00:06:49,290
DKIM is used to add a digital signature to the email header

163
00:06:49,290 --> 00:06:51,210
that can be used to validate the recipient

164
00:06:51,210 --> 00:06:54,240
and ensure that the email was not modified during transit.

165
00:06:54,240 --> 00:06:56,730
SPF prevents sender address forging

166
00:06:56,730 --> 00:07:00,110
by checking if the sender's IP address is authorized

167
00:07:00,110 --> 00:07:01,200
in the domains DNS records.

168
00:07:01,200 --> 00:07:03,987
DMARC is a protocol that uses SPF

169
00:07:03,987 --> 00:07:07,770
and DKIM to determine the authenticity of the email message

170
00:07:07,770 --> 00:07:09,960
by allowing a domain owner to specify

171
00:07:09,960 --> 00:07:12,240
how to handle any emails that fail

172
00:07:12,240 --> 00:07:14,100
that particular security check.

173
00:07:14,100 --> 00:07:17,250
Email gateways serve as the entry point and exit point

174
00:07:17,250 --> 00:07:19,530
for all enterprise emails.

175
00:07:19,530 --> 00:07:21,660
These email gateways are implemented to help

176
00:07:21,660 --> 00:07:24,990
with email routing, email security, policy enforcement,

177
00:07:24,990 --> 00:07:27,930
and the encryption and decryption of emails.

178
00:07:27,930 --> 00:07:30,390
And lastly, we also have spam filtering,

179
00:07:30,390 --> 00:07:31,633
which is a technique to detect

180
00:07:31,633 --> 00:07:35,040
and block unwanted emails based on various criteria

181
00:07:35,040 --> 00:07:38,433
such as content, sender reputation and user preferences.

