This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
faq:email:prevent-email-being-spoofed [2019/12/31 09:51] – ziyu | faq:email:prevent-email-being-spoofed [2025/03/10 13:59] (current) – [How to prevent email being spoofed?] vikki | ||
---|---|---|---|
Line 1: | Line 1: | ||
+ | [[: | ||
+ | |||
====== How to prevent email being spoofed? ====== | ====== How to prevent email being spoofed? ====== | ||
- | Email spoofing | + | Email spoofing |
+ | |||
+ | To protect your emails, our system implements security measures that identify | ||
+ | * Hardfail Spoofed Emails: Emails that fail authentication checks definitively will be rejected outright. | ||
+ | * Softfail Spoofed Emails: Emails that partially fail authentication will be marked as spam, allowing you to review them with caution. | ||
+ | |||
+ | To further secure your domain and email communication, | ||
+ | |||
+ | ==== 1. Make sure your SPF record is configured correctly ==== | ||
+ | If you are using Lookafter email service, ensure that you are using [[faq: | ||
+ | If you need to authorize third-party email servers to send emails on your behalf, ensure they are properly included in your SPF record to avoid authentication failures. | ||
+ | |||
+ | ==== 2. Be cautious with unexpected emails ==== | ||
+ | If you receive an unexpected email from a colleague, vendor, or even yourself asking for urgent action, verify with them directly through another communication method (e.g., phone or chat). | ||
+ | |||
+ | ==== 3. Check the sender’s email address carefully ==== | ||
+ | Cybercriminals often use email addresses that look similar to legitimate ones (e.g., ceo@yourc0mpany.com instead of ceo@yourcompany.com). | ||
- | While there is no fool-proof way to prevent abuse to your email address, here are several practices that you can adopt when it comes to securing your email address: | + | ==== 4. Avoid Clicking Suspicious Links or Opening Attachments ==== |
+ | If an email asks you to click a link or download an attachment, hover over the link to see the actual destination before clicking.\\ | ||
+ | If in doubt, visit the official website directly instead of using the email link. | ||
- | * Set the "Allow spoof email" settings to **No** in your SMTP Settings. You can find this settings by logging in to your webmail as the Avomaster or voadmin, then go to **(1)Profile -> (2)Admin -> (3)SMTP settings**. Click on the **(4)No** option. Remember to press **(5)Update** once you have done setting. | + | ==== 5. Use Strong, Unique Passwords ==== |
- | * {{faq: | + | Never use the same password for multiple accounts.\\ |
- | * {{faq:general:smtpset.png|}}\\ | + | Enable [[faq:security:2auth|Second Factor Authentication (2Auth)]] to add an extra layer of security. |
- | * Change your password frequently; use strong password that is difficult to guess. Refer to the link here to [[https:// | + | |
- | * Run full virus scans on your computer **at least** once a week. | + | |
- | * Avoid including your email address in online blogs or posts. Try using (at) and (dot)com instead of @ and .com to prevent malicious automatons from harvesting your address. E.g. instead of using an email of user401@domain.com, | + | |
- | * Avoid using your primary email account for everything online. If you are signing up for something like a mailing list, contest, application form, etc, use a free email account or you can simply create one, on the spot via [[https:// | + | |
- | * Only use your primary email to communicate with people you know or trust or to deal with important messages. | + | |
+ | ==== 6. Keep Your Devices and Software Updated ==== | ||
+ | Regular updates help protect against security vulnerabilities that attackers may exploit.\\ | ||
+ | Ensure your antivirus software is active and running. | ||
- | Reference: [[https:// | + | ==== 7. Report Suspicious Emails ==== |
+ | If you suspect an email is spoofed, report it to your IT team or forward the email to [[helpdesk@lookafter.com]]. | ||
+ | Do not reply or engage with the sender. |