Good Morning
We have recently received email stating new banking details sent from gmail spoofed as a .co.za domain sender. I have searched for solutions on how to block this type of inbound email with no luck on a quarantine it solution. The email originated via a gmail server and the reply to address states a gmail address in the header. the from header however states a .co.za domain. By all appearance it seems to have been sent via google webmail. (Which left me a tad frustrated that google do not block these emails from sending via their smtp servers). I have copied relevant mail headers below - replaced privacy parts with ### where relevant. Any ideas on how to block these kind of emails in future? Usually the UTM does a sterling job of taking care of these - however in this instance spf / dkim etc etc all failed miserably leaving many late hours and lots of coffee how to protect organizations from being caught due to human error that overlooked the gmail appart - even after printing the email - oi oi trouble. Specialists your input would be as always much appreciated.
Received: from mail-ot0-f181.google.com ([74.125.82.181])
by @@@@@@.net with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128)
(Exim 4.84_2)
(envelope-from <garry#####@gmail.com>)
id 1et8nZ-0004Ce-1Z
From: " \"Sharlisa<##@###security.co.za>\" " <garry#####@gmail.com>
To: Susan <##@#####.co.za>
envelope-to: ##@#####.co.za
This thread was automatically locked due to age.