<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spoofed Email - Phishing reports\Investigation tool in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Spoofed-Email-Phishing-reports-Investigation-tool/m-p/1068#M716</link>
    <description>&lt;P&gt;have you first made sure your SPF record is correct?&amp;nbsp; SPF is the first step and will prevent someone elsewhere in the world sending as your domain, rather not really prevent...but it will communicate to all receiving email systems where valid email for your domain can originate from.&amp;nbsp; So it is up to you to allow via SPF config the servers that are authorized to send on behalf of your domain.&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 18:34:50 GMT</pubDate>
    <dc:creator>MattFeider</dc:creator>
    <dc:date>2023-09-21T18:34:50Z</dc:date>
    <item>
      <title>Spoofed Email - Phishing reports\Investigation tool</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Spoofed-Email-Phishing-reports-Investigation-tool/m-p/1067#M715</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know I need to get my DMARC setup finished, but in the meantime I have something that has been bothering me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had someone spoof on our principals email address.&amp;nbsp; It came through with a warning from Google to be wary of this email, but if you dig deeper it did not appear to be a hack of her account, but just someone sending email as her\us.&amp;nbsp; It had a different reply to address and said up the top user@domain.com via another party.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interestingly I had the user click the report phishing and I received an email to my admin account that the phish report had been made, but since the email was spoofed the phish report said that it was against(actor) my user@domain.com.&amp;nbsp; Am I missing something?&amp;nbsp; Should I be digging deeper into this users account?&amp;nbsp; or is this just a matter of needing to get my DMARC record straight and that is the only answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, if I do a search in the investigative tool the email there as coming from user@domain.com - this isn't right though it is pretty clearly a spoofed email sent from a server in Europe.&amp;nbsp; How is the investigation tool populated?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do have 2 factor on all accounts, but this just appears to be a spoof.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wanted to make sure I am crossing my ts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 18:16:45 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Spoofed-Email-Phishing-reports-Investigation-tool/m-p/1067#M715</guid>
      <dc:creator>E8419</dc:creator>
      <dc:date>2023-09-21T18:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Spoofed Email - Phishing reports\Investigation tool</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Spoofed-Email-Phishing-reports-Investigation-tool/m-p/1068#M716</link>
      <description>&lt;P&gt;have you first made sure your SPF record is correct?&amp;nbsp; SPF is the first step and will prevent someone elsewhere in the world sending as your domain, rather not really prevent...but it will communicate to all receiving email systems where valid email for your domain can originate from.&amp;nbsp; So it is up to you to allow via SPF config the servers that are authorized to send on behalf of your domain.&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 18:34:50 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Spoofed-Email-Phishing-reports-Investigation-tool/m-p/1068#M716</guid>
      <dc:creator>MattFeider</dc:creator>
      <dc:date>2023-09-21T18:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Spoofed Email - Phishing reports\Investigation tool</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Spoofed-Email-Phishing-reports-Investigation-tool/m-p/1074#M717</link>
      <description>&lt;P&gt;Yeah, everyone really needs to read&amp;nbsp; through and adjust their DNS according to &lt;A title="Support article on SPF, DKIM and DMARC" href="https://support.google.com/a/topic/9061731?hl=en&amp;amp;fl=1&amp;amp;sjid=4514271506941951759-NA" target="_blank" rel="noopener"&gt;this support article&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;SPF, DKIM and DMARC should be one of the first things to set up on a new Workspace account.&lt;/P&gt;&lt;P&gt;DMARC reject is also the only real option to use, and should be set as soon as possible after SPF and DKIM are working.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 07:43:20 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Spoofed-Email-Phishing-reports-Investigation-tool/m-p/1074#M717</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-22T07:43:20Z</dc:date>
    </item>
  </channel>
</rss>

