1
00:00:06,485 --> 00:00:11,130
- In 18.3, we're gonna
focus in on email security.

2
00:00:11,130 --> 00:00:13,560
Now, secure email communications refers

3
00:00:13,560 --> 00:00:17,040
to the use of various
measures and protocols

4
00:00:17,040 --> 00:00:20,190
to protect the
confidentiality, the integrity,

5
00:00:20,190 --> 00:00:23,190
and the authenticity of
email messages exchanged

6
00:00:23,190 --> 00:00:24,333
between parties.

7
00:00:25,440 --> 00:00:27,120
Now, secure email communications

8
00:00:27,120 --> 00:00:29,370
really require both server side

9
00:00:29,370 --> 00:00:32,070
and client side configuration.

10
00:00:32,070 --> 00:00:33,570
So what we're gonna be
looking at here really

11
00:00:33,570 --> 00:00:34,920
is server side.

12
00:00:34,920 --> 00:00:38,820
Earlier when we looked at
encryption and digital signatures,

13
00:00:38,820 --> 00:00:41,010
we really looked at ways that
we could secure our email.

14
00:00:41,010 --> 00:00:41,880
We could use encryption

15
00:00:41,880 --> 00:00:44,010
to make sure that we had confidentiality,

16
00:00:44,010 --> 00:00:46,380
that if anyone else saw that message,

17
00:00:46,380 --> 00:00:48,660
they wouldn't be able to read
it, it would be encrypted.

18
00:00:48,660 --> 00:00:50,310
And then we used digital signatures,

19
00:00:50,310 --> 00:00:52,770
which had both hashing for integrity

20
00:00:52,770 --> 00:00:54,120
and our digital signature

21
00:00:54,120 --> 00:00:56,763
for authenticity and non-repudiation.

22
00:00:57,960 --> 00:01:01,890
So here are three server side
configuration options we have.

23
00:01:01,890 --> 00:01:06,367
SPF, DKIM, and DMARC, DMARK,

24
00:01:08,330 --> 00:01:11,430
The SPF stands for
Sender Policy Framework.

25
00:01:11,430 --> 00:01:14,040
Now it's an email
authentication method designed

26
00:01:14,040 --> 00:01:18,180
to prevent email spoofing
and to protect against forged

27
00:01:18,180 --> 00:01:22,653
or unauthorized use of domain
names in an email address.

28
00:01:24,030 --> 00:01:27,900
DKIM stands for DomainKeys
Identified Mail,

29
00:01:27,900 --> 00:01:29,910
is an email authentication method

30
00:01:29,910 --> 00:01:32,520
designed to verify the authenticity

31
00:01:32,520 --> 00:01:35,490
and the integrity of email messages.

32
00:01:35,490 --> 00:01:36,900
And lastly, DMARC,

33
00:01:36,900 --> 00:01:39,840
which stands for Domain-based
Message Authentication,

34
00:01:39,840 --> 00:01:43,083
Reporting and Conformance,
that's a long name,

35
00:01:43,920 --> 00:01:46,860
is an email authentication
protocol that helps protect

36
00:01:46,860 --> 00:01:50,220
against email spoofing
and phishing attacks.

37
00:01:50,220 --> 00:01:51,750
So we're gonna look at all three of these.

38
00:01:51,750 --> 00:01:56,010
SPF, DKIM and DMARC, all
these being server side

39
00:01:56,010 --> 00:01:58,713
email configuration security options.

40
00:01:59,820 --> 00:02:02,040
Now, SPF allows the domain owner

41
00:02:02,040 --> 00:02:05,400
to specify which email
servers are authorized

42
00:02:05,400 --> 00:02:08,040
to send mail on behalf of their domain.

43
00:02:08,040 --> 00:02:13,040
And that's accomplished by
publishing a SPF record in DNS.

44
00:02:14,040 --> 00:02:18,030
The SPF record specifies
the mechanisms and the rules

45
00:02:18,030 --> 00:02:21,540
for determining who the
authorized email servers are.

46
00:02:21,540 --> 00:02:24,300
Now, it can include an
IP address, IP range,

47
00:02:24,300 --> 00:02:27,060
or domain names of the authorized server.

48
00:02:27,060 --> 00:02:29,160
Now, it also might have
some additional information,

49
00:02:29,160 --> 00:02:31,890
such as the policy for handling emails

50
00:02:31,890 --> 00:02:34,080
that doesn't match the SPF record,

51
00:02:34,080 --> 00:02:36,900
and that's known as an SPF policy.

52
00:02:36,900 --> 00:02:39,570
But the goal here is
that we wanna make sure

53
00:02:39,570 --> 00:02:42,300
that the whole email domain knows

54
00:02:42,300 --> 00:02:45,270
that only these particular
servers, you know,

55
00:02:45,270 --> 00:02:49,503
are authorized to send email
from a specific domain name.

56
00:02:51,330 --> 00:02:52,740
So here's the SPF workflow.

57
00:02:52,740 --> 00:02:54,087
We're gonna have an SPF Record

58
00:02:54,087 --> 00:02:57,483
and SPF Check and an SPF result.

59
00:02:58,560 --> 00:03:01,350
The domain owner is gonna
create an SPF record

60
00:03:01,350 --> 00:03:04,860
and publishes it in the DNS
settings of their domain.

61
00:03:04,860 --> 00:03:07,290
Now the SPF record contains information

62
00:03:07,290 --> 00:03:09,510
about the authorized email servers

63
00:03:09,510 --> 00:03:12,843
that are allowed to send emails
on behalf of that domain.

64
00:03:13,890 --> 00:03:17,430
The receiving email server
performs an SPF Check

65
00:03:17,430 --> 00:03:21,180
by looking up the SPF record
of the sender's domain.

66
00:03:21,180 --> 00:03:23,700
It then compares the IP
address of the server

67
00:03:23,700 --> 00:03:26,820
that sent the email with the
list of authorized servers

68
00:03:26,820 --> 00:03:30,033
that have been specified
in the SPF record.

69
00:03:31,080 --> 00:03:33,330
Now, based on the SPF Check,

70
00:03:33,330 --> 00:03:36,510
the receiving mail server determines

71
00:03:36,510 --> 00:03:39,570
if the email is coming from
an authorized server or not.

72
00:03:39,570 --> 00:03:43,020
Now, it can take different
actions based on the SPF results,

73
00:03:43,020 --> 00:03:45,030
such as either accepting the email

74
00:03:45,030 --> 00:03:47,100
or marking it as suspicious

75
00:03:47,100 --> 00:03:49,803
or just like totally
rejecting it altogether.

76
00:03:52,950 --> 00:03:56,310
Our second option,
DKIM, allows a recipient

77
00:03:56,310 --> 00:03:59,130
to check if an email was
sent by the claim sender,

78
00:03:59,130 --> 00:04:02,681
and if it's been tampered
with during transmission.

79
00:04:02,681 --> 00:04:06,570
The DKIM works by adding
a digital signature

80
00:04:06,570 --> 00:04:08,220
to the header of the email.

81
00:04:08,220 --> 00:04:10,140
Now, that's not the
user's digital signature,

82
00:04:10,140 --> 00:04:12,120
it's the DKIM signature.

83
00:04:12,120 --> 00:04:13,590
Now, the signature is generated

84
00:04:13,590 --> 00:04:15,540
using public key cryptography

85
00:04:15,540 --> 00:04:18,660
and can be verified using
the public key stored

86
00:04:18,660 --> 00:04:21,300
in the sender domains, DNS record,

87
00:04:21,300 --> 00:04:23,340
which is stored as a text record,

88
00:04:23,340 --> 00:04:26,130
because remember that
a key is just a string

89
00:04:26,130 --> 00:04:28,353
so it's stored as a text record.

90
00:04:29,520 --> 00:04:32,010
So let's go through a DKIM workflow.

91
00:04:32,010 --> 00:04:33,570
We have an email digitally signed

92
00:04:33,570 --> 00:04:38,070
by the email server using
the DKIM private key.

93
00:04:38,070 --> 00:04:41,703
The DKIM signature is
added to the email header.

94
00:04:42,600 --> 00:04:45,240
Next, we have DKIM verification

95
00:04:45,240 --> 00:04:47,280
by the recipient email server

96
00:04:47,280 --> 00:04:50,280
looking at the DNS text record.

97
00:04:50,280 --> 00:04:52,500
And then we'll have the DKIM result.

98
00:04:52,500 --> 00:04:54,420
And that will tell us, right,

99
00:04:54,420 --> 00:04:58,533
whether the email is proven
to be tamper free or not.

100
00:05:00,780 --> 00:05:02,820
And our third option is DMARC.

101
00:05:02,820 --> 00:05:06,870
DMARC allows domain owners to
specify how email receivers

102
00:05:06,870 --> 00:05:09,750
should handle emails that
fail authentication checks,

103
00:05:09,750 --> 00:05:12,690
and it allows them to
also receive feedback

104
00:05:12,690 --> 00:05:15,813
on the emails using reporting mechanisms.

105
00:05:16,890 --> 00:05:21,690
Now, the primary goal of DMARC
is to combat domain spoofing

106
00:05:21,690 --> 00:05:25,050
and to protect the integrity
of email communication

107
00:05:25,050 --> 00:05:26,460
in the aggregate.

108
00:05:26,460 --> 00:05:30,540
Now, DMARC does require either
the implementation of SPF

109
00:05:30,540 --> 00:05:35,460
or DKIM or both for email authentication.

110
00:05:35,460 --> 00:05:38,970
SPF verifies the sending IP address

111
00:05:38,970 --> 00:05:42,780
or DKIM verifies the
integrity of the email content

112
00:05:42,780 --> 00:05:44,373
and the sender's domain.

113
00:05:45,630 --> 00:05:47,370
So here our DMARC components.

114
00:05:47,370 --> 00:05:50,370
We have a DMARC policy, policy actions,

115
00:05:50,370 --> 00:05:52,413
and then reporting mechanisms.

116
00:05:53,465 --> 00:05:55,830
Now, the DMARC policy specifies

117
00:05:55,830 --> 00:05:59,640
how the recipient's mail
server should handle emails

118
00:05:59,640 --> 00:06:03,603
that either fail an SPF
and/or a DKIM check.

119
00:06:03,603 --> 00:06:07,770
Now, the email domain owner
publishes the DMARC policy

120
00:06:07,770 --> 00:06:09,123
in their DNS record.

121
00:06:10,050 --> 00:06:13,500
And the DMARC policy
actions could include none,

122
00:06:13,500 --> 00:06:15,750
meaning it's just in monitoring mode,

123
00:06:15,750 --> 00:06:18,090
quarantine, which is marking the email

124
00:06:18,090 --> 00:06:19,860
as potentially suspicious,

125
00:06:19,860 --> 00:06:23,403
or reject, which is outright
rejection of the email.

126
00:06:24,900 --> 00:06:29,550
And the DMARC reporting mechanisms
provide or email domain,

127
00:06:29,550 --> 00:06:32,850
right, the original owners,
feedback including details

128
00:06:32,850 --> 00:06:36,543
about successful and failed
authentication attempts.

129
00:06:37,830 --> 00:06:40,050
So let's take a look at
some encryption options.

130
00:06:40,050 --> 00:06:42,120
You know, the goal of email encryption

131
00:06:42,120 --> 00:06:45,750
is that only the intended
recipient can read the email.

132
00:06:45,750 --> 00:06:47,430
So we really have two approaches.

133
00:06:47,430 --> 00:06:49,410
We have server-to-server encryption

134
00:06:49,410 --> 00:06:51,240
and end-to-end encryption.

135
00:06:51,240 --> 00:06:53,310
Server-to-server encryption establishes

136
00:06:53,310 --> 00:06:56,880
an encrypted connection to
protect the email data in transit

137
00:06:56,880 --> 00:07:00,690
between the sender and the
recipient's email servers.

138
00:07:00,690 --> 00:07:02,610
Where end-to-end encryption ensures

139
00:07:02,610 --> 00:07:06,390
that the email message is
encrypted on the sender's device

140
00:07:06,390 --> 00:07:09,900
and can only be de-encrypted
by the intended recipient.

141
00:07:09,900 --> 00:07:12,600
That means it not even
the email service provider

142
00:07:12,600 --> 00:07:15,243
has access to the decrypted content.

143
00:07:17,580 --> 00:07:20,310
Let's take a look at some
secure email protocols.

144
00:07:20,310 --> 00:07:21,143
TLS.

145
00:07:21,143 --> 00:07:22,410
Oh, that should sound familiar.

146
00:07:22,410 --> 00:07:24,360
And S/MIME.

147
00:07:24,360 --> 00:07:26,310
TLS or Transport Layer Security

148
00:07:26,310 --> 00:07:28,530
is a cryptographic
protocol that we can use

149
00:07:28,530 --> 00:07:31,590
to encrypt communication
between our email servers

150
00:07:31,590 --> 00:07:33,540
during transmission.

151
00:07:33,540 --> 00:07:37,410
Where S/MIME, Secure/Multipurpose
Internet Mail Extensions

152
00:07:37,410 --> 00:07:40,260
is a standard for securing email messages

153
00:07:40,260 --> 00:07:43,800
that provide for encryption
and digital signatures.

154
00:07:43,800 --> 00:07:46,860
So server-to-server and end-to-end.

155
00:07:46,860 --> 00:07:49,890
That, my friends, takes us
to a three second challenge.

156
00:07:49,890 --> 00:07:52,020
Five challenge questions,
three seconds each.

157
00:07:52,020 --> 00:07:52,853
Let's do it.

158
00:07:53,790 --> 00:07:55,950
Email authentication
method designed to protect

159
00:07:55,950 --> 00:08:00,300
against forged use of a
domain name in email messages.

160
00:08:00,300 --> 00:08:01,863
One, two, three.

161
00:08:02,700 --> 00:08:05,703
It's gonna be SPF or
Sender Policy Framework.

162
00:08:06,690 --> 00:08:07,980
Number two.

163
00:08:07,980 --> 00:08:12,210
Allows email domain owners to
specify how email receivers

164
00:08:12,210 --> 00:08:16,110
should handle emails that
fail authentication checks.

165
00:08:16,110 --> 00:08:17,657
One, two, three.

166
00:08:17,657 --> 00:08:19,380
That's gonna be DMARC

167
00:08:19,380 --> 00:08:23,250
or domain-based message
authentication, reporting,

168
00:08:23,250 --> 00:08:24,573
and conformance.

169
00:08:26,100 --> 00:08:27,270
Number three.

170
00:08:27,270 --> 00:08:28,950
Allows the recipient to check

171
00:08:28,950 --> 00:08:32,013
if an email was indeed
sent by the claim sender.

172
00:08:32,910 --> 00:08:34,623
One, two, three.

173
00:08:36,270 --> 00:08:38,190
And that's gonna be DKIM,

174
00:08:38,190 --> 00:08:40,803
which is DomainKeys Identified Mail.

175
00:08:41,730 --> 00:08:43,230
Number four.

176
00:08:43,230 --> 00:08:45,930
This record states the
authorized email servers

177
00:08:45,930 --> 00:08:48,390
that are allowed to send emails.

178
00:08:48,390 --> 00:08:49,953
One, two, three.

179
00:08:51,060 --> 00:08:52,683
That's the SPF record.

180
00:08:53,730 --> 00:08:57,630
And lastly, number five, using
this encryption approach,

181
00:08:57,630 --> 00:09:00,690
the email message is encrypted
on the sender's device

182
00:09:00,690 --> 00:09:04,323
and can only be decrypted
by the intended recipient.

183
00:09:05,280 --> 00:09:06,663
One, two, three.

184
00:09:07,560 --> 00:09:09,693
That's gonna be end-to-end encryption.

185
00:09:10,830 --> 00:09:13,170
Right, that brings us
to a security and action

186
00:09:13,170 --> 00:09:14,310
so you can apply your knowledge.

187
00:09:14,310 --> 00:09:16,740
And this one's about email security.

188
00:09:16,740 --> 00:09:19,590
To enhance your
organization's email security,

189
00:09:19,590 --> 00:09:22,290
you are recommending TLS encryption

190
00:09:22,290 --> 00:09:27,150
and the implementation
of SPF records and DKIM.

191
00:09:27,150 --> 00:09:28,530
The first question you're asked

192
00:09:28,530 --> 00:09:31,530
is why do you need all three?

193
00:09:31,530 --> 00:09:33,870
It's like, isn't just one of them enough?

194
00:09:33,870 --> 00:09:37,620
So my question to you is,
how are you gonna respond?

195
00:09:37,620 --> 00:09:41,760
TLS encryption, SPF records, and DKIM,

196
00:09:41,760 --> 00:09:43,350
why do you need them all?

197
00:09:43,350 --> 00:09:44,640
Go ahead and put me on pause

198
00:09:44,640 --> 00:09:46,990
and think about what your
approach is gonna be.

199
00:09:50,931 --> 00:09:51,764
Well, TLS, DKIM, and SPF each
address different aspects

200
00:09:55,680 --> 00:09:57,240
of security.

201
00:09:57,240 --> 00:10:01,173
TLS provides encryption to
enforce confidentiality.

202
00:10:02,310 --> 00:10:04,740
DKIM allows the recipient to check

203
00:10:04,740 --> 00:10:07,860
if an email was indeed
sent by the claim sender

204
00:10:07,860 --> 00:10:10,630
and if it's been tampered
with during transmission

205
00:10:11,760 --> 00:10:15,390
SPF provides a way to
verify the authenticity

206
00:10:15,390 --> 00:10:17,730
of the sender's domain by ensuring

207
00:10:17,730 --> 00:10:21,210
that the email is actually
sent from an authorized server,

208
00:10:21,210 --> 00:10:25,230
that implementing SPF protects
your domain's reputation

209
00:10:25,230 --> 00:10:28,650
and reduces the chance
of your domain being used

210
00:10:28,650 --> 00:10:31,350
for spoofing or phishing.

211
00:10:31,350 --> 00:10:33,900
So all really good things to use.

212
00:10:33,900 --> 00:10:36,660
You can use them, you know,
in concert with each other.

213
00:10:36,660 --> 00:10:40,530
They all handle or address
different aspects of security.

214
00:10:40,530 --> 00:10:42,540
So understanding that, explaining that

215
00:10:42,540 --> 00:10:43,890
being able to implement that,

216
00:10:43,890 --> 00:10:46,800
that, my friends, is security and action.

217
00:10:46,800 --> 00:10:47,670
There's your word cloud.

218
00:10:47,670 --> 00:10:48,990
Not particularly big

219
00:10:48,990 --> 00:10:51,330
but a lot of really important components,

220
00:10:51,330 --> 00:10:52,410
a lot of important stuff here.

221
00:10:52,410 --> 00:10:54,900
So make sure you understand
all of it before you move on.

222
00:10:54,900 --> 00:10:57,150
If not, go back in through the lesson.

223
00:10:57,150 --> 00:10:58,170
And when you're ready,

224
00:10:58,170 --> 00:11:00,420
know I'll be waiting
for you our next lesson.
