This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| faq:email:prevent-email-being-spoofed [2022/03/08 11:05] – vikki | faq:email:prevent-email-being-spoofed [2025/03/10 13:59] (current) – [How to prevent email being spoofed?] vikki | ||
|---|---|---|---|
| Line 3: | Line 3: | ||
| ====== How to prevent email being spoofed? ====== | ====== How to prevent email being spoofed? ====== | ||
| - | Email spoofing | + | Email spoofing |
| - | While there is no fool-proof way to prevent abuse to your email address, here are several practices | + | To protect |
| + | * Hardfail Spoofed Emails: Emails that fail authentication checks definitively will be rejected outright. | ||
| + | * Softfail Spoofed Emails: Emails that partially fail authentication will be marked as spam, allowing | ||
| - | * Set the "Allow spoof email" settings to **No** in your SMTP Settings. You can find this settings by logging in to your webmail as the Avomaster or voadmin, then go to **Profile -> Admin -> SMTP settings**. Click on the **No** option. Remember to press **Update** once you have done setting. | + | To further secure |
| - | * Change your password frequently; use strong password that is difficult to guess. Refer to the link here to [[https:// | + | |
| - | * Run full virus scans on your computer **at least** once a week. | + | |
| - | * Avoid including your email address in online blogs or posts. Try using (at) and (dot)com instead of @ and .com to prevent malicious automatons from harvesting your address. E.g. instead of using an email of user401@domain.com, we type it as user401(at)domain(dot)com . | + | |
| - | * Avoid using your primary email account for everything online. If you are signing up for something like a mailing list, contest, application form, etc, use a free email account or you can simply create one, on the spot via [[https:// | + | |
| - | * Only use your primary email to communicate with people you know or trust or to deal with important messages. | + | |
| + | ==== 1. Make sure your SPF record is configured correctly ==== | ||
| + | If you are using Lookafter email service, ensure that you are using [[faq: | ||
| + | If you need to authorize third-party email servers to send emails on your behalf, ensure they are properly included in your SPF record to avoid authentication failures. | ||
| - | Reference: [[https:// | + | ==== 2. Be cautious with unexpected emails ==== |
| + | If you receive an unexpected email from a colleague, vendor, or even yourself asking for urgent action, verify with them directly through another communication method (e.g., phone or chat). | ||
| + | |||
| + | ==== 3. Check the sender’s email address carefully ==== | ||
| + | Cybercriminals often use email addresses that look similar to legitimate ones (e.g., ceo@yourc0mpany.com instead of ceo@yourcompany.com). | ||
| + | |||
| + | ==== 4. Avoid Clicking Suspicious Links or Opening Attachments ==== | ||
| + | If an email asks you to click a link or download an attachment, hover over the link to see the actual destination before clicking.\\ | ||
| + | If in doubt, visit the official website directly instead of using the email link. | ||
| + | |||
| + | ==== 5. Use Strong, Unique Passwords ==== | ||
| + | Never use the same password for multiple accounts.\\ | ||
| + | Enable [[faq: | ||
| + | |||
| + | ==== 6. Keep Your Devices and Software Updated ==== | ||
| + | Regular updates help protect against security vulnerabilities that attackers may exploit.\\ | ||
| + | Ensure your antivirus software is active and running. | ||
| + | |||
| + | ==== 7. Report Suspicious Emails ==== | ||
| + | If you suspect an email is spoofed, report it to your IT team or forward the email to [[helpdesk@lookafter.com]]. | ||
| + | Do not reply or engage with the sender. | ||