Current Email Security Protocols.
Email: A Popular Tool Under Constant Threat
Current Email Security Protocols.
Email: A Popular Tool Under Constant Threat
Email remains one of the most widely used communication tools globally — but also one of the most abused. According to Station X, In the year 2022, an estimated 3.4 billion phishing emails were sent daily by cybercriminals impersonating trusted senders. These adversaries use these phishing emails for illicit reasons.
🕵️♂️ Techniques Used by Attackers
These are a vast number of techniques that attackers use to exploit email systems, whether corporate or private. These techniques include:
· Malware Attachments — Exploiters tend to attach malicious payloads to sensitive documents, which the receiver unknowingly opens
· Spoofing — Imitating a legitimate email sender.
· Credential Harvesting — Creating fake login portals to trick user into providing credentials like usernames and passwords.
A Basic Phishing + Credentials Harvesting Illustration.
You receive a mail from your bank requesting you to click on the link attached, this link redirects you to a website where you were able to complete a bank survey. A few moments later a large sum of money is deducted from your account without you authorising any bank transaction. You seem confused but your account has simply been compromised by an adversary and your bank details harvested for malicious activities.

Example of Email Phishing.
Does this mean that all our email communication is insecured?
To conclude that all our email communications are insecured is inaccurate. While there has been a drastic increase in email exploitation attacks and also advancement in the field of email phishing, there has also been a corresponding increase in defensive tools and protocols which have significantly damped these attacks. These tools came out of a desire to curb email phishing/spoofing attacks and strongly mitigate email exploitation attacks.
🛡️ Rise of New Email Security Measures
SPF (Sender’s Policy Framework): — SPF is used to verify the sender’s mail server, It helps receiving mail servers decide whether an incoming email is legitimate by checking if it was sent from an authorized source. If the sender’s mail server is not whitelisted then the email fails SPF checks, and depending on the domain’s DMARC policy, it may be rejected, quarantined, or flagged.
DKIM (DomainKey Identified Mail): — DKIM adds a digital signature to each outgoing email. It ensures the message was really sent by the domain it claims to come from and it has not been tampered with during transmission.
DMARC (Domain-based Messaging, Authentication, Reporting and Conformance): — DMARC is a builds on SPF and DKIM, they are prerequisites before an email is accepted. Company use DMARC policy to decide on emails received, some of policies include:
· Reject = An email fails SPF and/or DKIM
· Quarantine = Emails that fail SPF and DKIM checks are sent to spam/junk instead of inbox.
Conclusion.
Regardless of advanced email exploiting techniques like email spoofing/phishing, Cybersecurity defenders have risen to the task and have created advanced email security measures to counteract these attacks. Overall, evolve their techniques, defenders will continue to develop corresponding security measures. Stay tuned for more lessons, and field notes as I keep pushing forward on this blue team journey
메타데이터
- post_id
- 6568024b422c
- slug
- current-email-security-protocols-6568024b422c
- url
- https://medium.com/@Cy_berJack/current-email-security-protocols-6568024b422c
- canonical_url
- https://medium.com/@Cy_berJack/current-email-security-protocols-6568024b422c
- author_url
- https://medium.com/@Cy_berJack
- status
- ok
- fetched_at
- 2026-08-30 10:48:43