SlideShare una empresa de Scribd logo
1 de 9
Service Provider Email Implications
Thomas Stensitzki – MCM, MCT, Blogger
What is a Service Provider
External company providing email based services for an enterprise
Usually uses an email domain owned by the enterprise customer to obfuscate the service
Service provider emails are sent from servers owned by the service provider
Examples
Email Marketing Services
Travel Agencies
Cloud based Business Services
Service Provider Email Implications
Service provider emails are filtered as spam
Service provider emails are not received by internal recipients
Service provider emails are identified as being sent from an untrusted source
Using an enterprise primary top level domain
Accepted domain:
varunagroup.de
Service provider sender addresses
newsletter@varunagroup.de
booking@varunagroup.de
user@varunagroup.deExternal recipient Email Gateway
Email blocked due to identical sender and recipient domain
Solution A – Single Sub Domain
Single sub domain for external service providers
email.varunagroup.de
Requirement
Dedicated mail server hosting sub domain addresses
Email address verification only – never used for sending emails
Email security
One SPF Record containing all service provider SPF references
include:spf.nl2go.com include:spf.constantcontact.com
Multiple DKIM records in single DNS zone
provider1._domainkey.email.varunagroup.de
provider2._domainkey.email.varunagroup.de
Solution B – Multiple Sub Domains
Dedicated sub domains for external service provides
newsletter.varunagroup.de
booking.varunagroup.de
Requirement
Dedicated mail server hosting sub domain addresses
Email address verification only – never used for sending emails
Email security
One SPF Record per sub domain containing the service provider SPF references
include:spf.nl2go.com
Single DKIM record per DNS zone
provider1._domainkey.newsletter.varunagroup.de
provider2._domainkey.booking.varunagroup.de
Using an enterprise sub domain
Accepted domain:
varunagroup.de
Service provider sender addresses
newsletter@email.varunagroup.de
booking@email.varunagroup.de
user@varunagroup.deExternal recipient Email Gateway
Email accepted due to different sender and recipient domains
Technical Implementation – Example
Enterprise Email Server
e.g. Exchange Server
Sub Domain Email Server
e.g. SmarterMail
External IP addresses
Primary MX Records
Reverse DNS Setup
Email Security Gateway
e.g. NoSpamProxy
External IP address
Sub Domain MX Records
No Reverse DNS Setup
Internal DNS Server
Top Level/Sub Domain Zones
SPF, DKIM
External DNS Server
Top Level/Sub Domain Zones
SPF, DKIM, DMARC
Contact
Granikos GmbH & Co. KG
Web: https://www.granikos.eu
Email: info@granikos.eu
Blog: http://blog.granikos.eu
Thomas Stensitzki
Web: http://www.stensitzki.de
Twitter: @Stensitzki
Blog: http://JustCantGetEnough.Granikos.eu

Más contenido relacionado

Destacado

Final Copy Research Study
Final Copy Research StudyFinal Copy Research Study
Final Copy Research StudyKevin Strybosch
 
Configuration d'Outlook
Configuration d'OutlookConfiguration d'Outlook
Configuration d'Outlooks_0ra
 
120223_PAPUAALIVE_cp_emsyk_single page_reduced
120223_PAPUAALIVE_cp_emsyk_single page_reduced120223_PAPUAALIVE_cp_emsyk_single page_reduced
120223_PAPUAALIVE_cp_emsyk_single page_reducedYoansevin Kansil
 
Art Speak Presentation
Art Speak PresentationArt Speak Presentation
Art Speak PresentationAngela Kambic
 
Tellurian 2016 Corporate Diaries and Notebooks in Dubai, UAE
Tellurian 2016 Corporate Diaries and Notebooks in Dubai, UAETellurian 2016 Corporate Diaries and Notebooks in Dubai, UAE
Tellurian 2016 Corporate Diaries and Notebooks in Dubai, UAETellurian Book Production
 
Real estate by Alpine Housing
Real estate by Alpine HousingReal estate by Alpine Housing
Real estate by Alpine HousingAlpineHousing
 
Voluntrme Introduction
Voluntrme IntroductionVoluntrme Introduction
Voluntrme Introductionvoluntrme
 

Destacado (8)

Final Copy Research Study
Final Copy Research StudyFinal Copy Research Study
Final Copy Research Study
 
Photosynthesis
PhotosynthesisPhotosynthesis
Photosynthesis
 
Configuration d'Outlook
Configuration d'OutlookConfiguration d'Outlook
Configuration d'Outlook
 
120223_PAPUAALIVE_cp_emsyk_single page_reduced
120223_PAPUAALIVE_cp_emsyk_single page_reduced120223_PAPUAALIVE_cp_emsyk_single page_reduced
120223_PAPUAALIVE_cp_emsyk_single page_reduced
 
Art Speak Presentation
Art Speak PresentationArt Speak Presentation
Art Speak Presentation
 
Tellurian 2016 Corporate Diaries and Notebooks in Dubai, UAE
Tellurian 2016 Corporate Diaries and Notebooks in Dubai, UAETellurian 2016 Corporate Diaries and Notebooks in Dubai, UAE
Tellurian 2016 Corporate Diaries and Notebooks in Dubai, UAE
 
Real estate by Alpine Housing
Real estate by Alpine HousingReal estate by Alpine Housing
Real estate by Alpine Housing
 
Voluntrme Introduction
Voluntrme IntroductionVoluntrme Introduction
Voluntrme Introduction
 

Más de Granikos GmbH & Co. KG

Langzeitarchivierung - Warum ist Archivierung wichtig?
Langzeitarchivierung - Warum ist Archivierung wichtig?Langzeitarchivierung - Warum ist Archivierung wichtig?
Langzeitarchivierung - Warum ist Archivierung wichtig?Granikos GmbH & Co. KG
 
AD FS Workshop | Part 1 | Quick Overview
AD FS Workshop | Part 1 | Quick OverviewAD FS Workshop | Part 1 | Quick Overview
AD FS Workshop | Part 1 | Quick OverviewGranikos GmbH & Co. KG
 
Modern Anti-Spam Protection - Rejection, no sorting
Modern Anti-Spam Protection - Rejection, no sortingModern Anti-Spam Protection - Rejection, no sorting
Modern Anti-Spam Protection - Rejection, no sortingGranikos GmbH & Co. KG
 
Modernes Anti-Spam - Abweisen, nicht sortieren
Modernes Anti-Spam - Abweisen, nicht sortierenModernes Anti-Spam - Abweisen, nicht sortieren
Modernes Anti-Spam - Abweisen, nicht sortierenGranikos GmbH & Co. KG
 
Long Time Preservation - The Importance of Archiving
Long Time Preservation - The Importance of ArchivingLong Time Preservation - The Importance of Archiving
Long Time Preservation - The Importance of ArchivingGranikos GmbH & Co. KG
 

Más de Granikos GmbH & Co. KG (7)

Langzeitarchivierung - Warum ist Archivierung wichtig?
Langzeitarchivierung - Warum ist Archivierung wichtig?Langzeitarchivierung - Warum ist Archivierung wichtig?
Langzeitarchivierung - Warum ist Archivierung wichtig?
 
AD FS Workshop | Part 2 | Deep Dive
AD FS Workshop | Part 2 | Deep DiveAD FS Workshop | Part 2 | Deep Dive
AD FS Workshop | Part 2 | Deep Dive
 
AD FS Workshop | Part 1 | Quick Overview
AD FS Workshop | Part 1 | Quick OverviewAD FS Workshop | Part 1 | Quick Overview
AD FS Workshop | Part 1 | Quick Overview
 
Exchange 2013 Site Mailboxes
Exchange 2013 Site MailboxesExchange 2013 Site Mailboxes
Exchange 2013 Site Mailboxes
 
Modern Anti-Spam Protection - Rejection, no sorting
Modern Anti-Spam Protection - Rejection, no sortingModern Anti-Spam Protection - Rejection, no sorting
Modern Anti-Spam Protection - Rejection, no sorting
 
Modernes Anti-Spam - Abweisen, nicht sortieren
Modernes Anti-Spam - Abweisen, nicht sortierenModernes Anti-Spam - Abweisen, nicht sortieren
Modernes Anti-Spam - Abweisen, nicht sortieren
 
Long Time Preservation - The Importance of Archiving
Long Time Preservation - The Importance of ArchivingLong Time Preservation - The Importance of Archiving
Long Time Preservation - The Importance of Archiving
 

Último

AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Angeliki Cooney
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfOrbitshub
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 

Último (20)

AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 

Service provider email implications

  • 1. Service Provider Email Implications Thomas Stensitzki – MCM, MCT, Blogger
  • 2. What is a Service Provider External company providing email based services for an enterprise Usually uses an email domain owned by the enterprise customer to obfuscate the service Service provider emails are sent from servers owned by the service provider Examples Email Marketing Services Travel Agencies Cloud based Business Services
  • 3. Service Provider Email Implications Service provider emails are filtered as spam Service provider emails are not received by internal recipients Service provider emails are identified as being sent from an untrusted source
  • 4. Using an enterprise primary top level domain Accepted domain: varunagroup.de Service provider sender addresses newsletter@varunagroup.de booking@varunagroup.de user@varunagroup.deExternal recipient Email Gateway Email blocked due to identical sender and recipient domain
  • 5. Solution A – Single Sub Domain Single sub domain for external service providers email.varunagroup.de Requirement Dedicated mail server hosting sub domain addresses Email address verification only – never used for sending emails Email security One SPF Record containing all service provider SPF references include:spf.nl2go.com include:spf.constantcontact.com Multiple DKIM records in single DNS zone provider1._domainkey.email.varunagroup.de provider2._domainkey.email.varunagroup.de
  • 6. Solution B – Multiple Sub Domains Dedicated sub domains for external service provides newsletter.varunagroup.de booking.varunagroup.de Requirement Dedicated mail server hosting sub domain addresses Email address verification only – never used for sending emails Email security One SPF Record per sub domain containing the service provider SPF references include:spf.nl2go.com Single DKIM record per DNS zone provider1._domainkey.newsletter.varunagroup.de provider2._domainkey.booking.varunagroup.de
  • 7. Using an enterprise sub domain Accepted domain: varunagroup.de Service provider sender addresses newsletter@email.varunagroup.de booking@email.varunagroup.de user@varunagroup.deExternal recipient Email Gateway Email accepted due to different sender and recipient domains
  • 8. Technical Implementation – Example Enterprise Email Server e.g. Exchange Server Sub Domain Email Server e.g. SmarterMail External IP addresses Primary MX Records Reverse DNS Setup Email Security Gateway e.g. NoSpamProxy External IP address Sub Domain MX Records No Reverse DNS Setup Internal DNS Server Top Level/Sub Domain Zones SPF, DKIM External DNS Server Top Level/Sub Domain Zones SPF, DKIM, DMARC
  • 9. Contact Granikos GmbH & Co. KG Web: https://www.granikos.eu Email: info@granikos.eu Blog: http://blog.granikos.eu Thomas Stensitzki Web: http://www.stensitzki.de Twitter: @Stensitzki Blog: http://JustCantGetEnough.Granikos.eu