Email Security
Email security protects the systems, domains, messages, and people that use email. It combines domain authentication, encrypted transport, message protection, filtering, identity controls, and reporting so attackers cannot easily impersonate your organization or turn a message into account access.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Email Security
Email security is the craft of making a message earn the trust it asks for. Email was built to cross networks and organizations, which is excellent for communication and less excellent when a stranger arrives wearing a cardboard sign saying Finance. The work is to check the chain of claims from sending domain to human action.
The first useful trio is SPF, DKIM, and DMARC. SPF says which hosts may send for an SMTP identity. DKIM adds a domain-associated signature. DMARC compares that authenticated identity with the visible From domain, then publishes a policy and reports. They are colleagues, not identical triplets in matching jumpers. A passing SPF check can still be irrelevant to the From address a reader sees.
That distinction explains the job. List every legitimate sender first: the mailbox service, applications, support tools, marketing platform, and delegated providers. Then give each one an owner and an intended identity path. Reports reveal odd paths before a strict policy makes them disappear into a support ticket, which is a poor discovery tool despite its enthusiasm for surprise.
TLS protects the connection between mail systems. S/MIME can protect message content across hops, with certificates and keys to manage. Neither makes a deceptive request honest. A message can authenticate correctly and still ask for credentials, a payment approval, or a malicious click. That is why mailbox sign-in controls, filtering, easy reporting, evidence collection, and account containment remain on the guest list.
Read the intro for the complete chain of claims and the glossary when the names start breeding acronyms. Use Slides for the control map, Cheatsheet for the compact evaluation and response path, and Practice for an offline header-analysis exercise. The quiz checks the concepts. Field Notes concentrates on third-party senders, forwarding, delivery requirements, and the small identity tuple that saves an investigation from guesswork.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/177/r1/final
Supports
- Trustworthy email as complementary SMTP and DNS authentication
- TLS transmission security
- and S/MIME content-security controls
- Enterprise email administrators and security specialists as the operational audience
- SPF
- DKIM
- DMARC
- TLS
- certificate authentication
- and S/MIME terminology
- https://www.rfc-editor.org/rfc/rfc7208.html
Supports
- SPF as DNS-published authorization for hosts that use an SMTP identity
- SPF evaluation as distinct from visible From identity
- RFC 7208 publication in 2014
- https://www.rfc-editor.org/rfc/rfc6376.html
Supports
- DKIM as a domain-associated cryptographic signature and validation mechanism for email
- https://www.rfc-editor.org/rfc/rfc7489.html
Supports
- DMARC policy
- reporting
- SPF and DKIM domain authentication
- and visible From alignment
- Receiver handling of authentication failures and domain-owner feedback
- DMARC limits for content analysis
- display-name attacks
- and visually similar domains
- RFC 7489 publication in 2015
- https://www.cisa.gov/resources-tools/resources/phishing-postcard
Supports
- Phishing signs
- prevention actions
- and suspicious-message reporting
- https://www.rfc-editor.org/rfc/rfc821.html
Supports
- SMTP specification and publication in 1982
- https://www.rfc-editor.org/rfc/rfc2311.html
Supports
- S/MIME Version 2 message content protection and publication in 1998
- https://www.rfc-editor.org/rfc/rfc4408.html
Supports
- SPF publication in 2006
- https://www.rfc-editor.org/rfc/rfc4871.html
Supports
- DKIM publication in 2007
- https://www.rfc-editor.org/rfc/rfc8461.html
Supports
- MTA-STS policy for authenticated TLS delivery and publication in 2018
- https://www.rfc-editor.org/rfc/rfc8617.html
Supports
- ARC preservation of authentication assessments through intermediaries and publication in 2019
- https://www.rfc-editor.org/rfc/rfc9989.html
Supports
- DMARC interoperability limits for indirect mail flows
- Operational consequences of unmitigated forwarding and mailing-list failures under reject policy
- https://support.google.com/mail/answer/81126?hl=en
Supports
- Gmail sender authentication
- TLS
- alignment
- reporting
- and spam-rate requirements
- February 2024 bulk-sender requirements
- Third-party sender configuration and forwarding guidance
- https://support.microsoft.com/en-us/outlook/fix-ndr-error-550-5-7-515-in-outlook-com
Supports
- High-volume sender SPF
- DKIM
- DMARC
- alignment
- and header-analysis requirements
- Third-party sender identity configuration guidance
- https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365
Supports
- Microsoft Defender for Office 365 product placement for integrated mailbox protection
- https://www.proofpoint.com/us/products/email-protection
Supports
- Proofpoint Core Email Protection product placement for email threat protection
- https://www.mimecast.com/products/email-security/
Supports
- Mimecast Advanced Email Security product placement for email threat protection
- https://www.barracuda.com/products/email-protection
Supports
- Barracuda Email Protection product placement for email threat protection
- https://abnormal.ai/products/email-security
Supports
- Abnormal Email Security product placement for behavioral email threat detection
- https://www.cisco.com/site/us/en/products/security/email-security/index.html
Supports
- Cisco Secure Email product placement for email threat protection
- https://workspace.google.com/products/gmail/
Supports
- Google Workspace Gmail product placement for hosted organizational email
- https://www.hornetsecurity.com/en/services/365-total-protection/
Supports
- Hornetsecurity 365 Total Protection product placement for Microsoft 365 email security
