Sophos Email customers using IP-based mailflow rule connectors must migrate to certificate-based configuration by March 31st. To see if you're affected Click Here.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

E-mail Gateway malicious url e-mail allowed through


we have received an e-mail using an alias/send as from one of our domains. The e-mail was allowed through and leads to a malicious url. We have enabled the setting in E-mail Security to reject e-mails that impersonate one of our domains: 

Header anomalies
Email that appears to come from your own domain, but originates externally

Now it wasn’t rejected but as this sender does not match our spf or dmarc we feel it should have been quarantined next. It didn’t, not as far as I can see in the logs as it only gives delivered successfully.

Sophos Support claims it is a false positive and that I should send it to Sophos Labs. I can’t do anything with such support answers.

Questions: is send as / alias from a non-domain email adress using a send as / alias of one of our e-mail domains not picked up by:

a] header anomalies?

b] spf and dmarc settings?

Regards,

Fred



Added tags
[edited by: Raphael Alganes at 5:59 AM (GMT -7) on 7 Jun 2023]
Parents Reply Children
  • Hi LuCar Toni, 

    The ticket is 05122960. 

    Sophos needs to fix the logic. They need to check the sender IP and helo against the SPF and DMARC settings ot the FROM email domain. If they don't match, apply the SPF and DMARC settings,

    Any outside e-mail with a from domain corresponding to a protected own domain, not matching spf and dmarc should be treated as a header anomaly.

    malicious email should ofcourse be detected.

    Thanks,

    Fred

  • Hi and ,

    The case 05122960. has been closed again by Sophos Support without doing or communicating anything. The only thing they occasionaly did is check if Sophos Assistance on Central was still enabled and send a request to enable it again. Happened multiple times.

    As a workaround I am blacklisting (sometimes whole ranges) of mail server IP adresses that impersonate us. That stopped most.

    Not that they stop trying, yesterday we received an outside email request to purchase something in the name of the director. Luckily it was not using our email domain so he rang the director to check. If it had used our email domain and was allowed tru the question is if the manager would have doubted the e-mail.

    Regards,

    Fred

  • Hello Fred,

    I checked on your case, and Support sent you an email on Jun 23, telling you about some updates, however, there was no reply from your end, or after 3 follow-up emails. 

    In that email, they’re asking you to check a configuration related to the Allow List that might be conflicting with your SPF check.

    Additionally, they provided the following KB , for the error below:

    Results - PermError SPF Permanent Error: Too many DNS lookups

    Did you get a change to read that email?

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hi

    I have checked my mail box but no message from Sophos Support on that day. I went further and checked the Sophos Email Gateway logs and found that it was quarantined for a malicous url!

  • Hi

    Also the follow up e-mails were quarantined for a malicious url. I have reported them to SophosLabs as not spam.


    I will check the recommendations and monitor for changes.

    Thanks for the assistance.

    Fred

  • Hello Fred,

    Thank you for the follow-up and confirmation.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.