toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

273
active users

#emailsecurity

2 posts2 participants0 posts today
mailbox.org<p>When emails don't reach your students, your e-learning business is at risk! </p><p>oncampus GmbH faced this exact challenge – their emails were marked as spam. How did Germany's leading digital education provider solve this critical problem? </p><p>Watch the video to discover their success story! 👉 <a href="https://mailbox.org/en/post/enhanced-email-security-in-the-education-sector" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mailbox.org/en/post/enhanced-e</span><span class="invisible">mail-security-in-the-education-sector</span></a></p><p><a href="https://social.mailbox.org/tags/emailsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>emailsecurity</span></a> <a href="https://social.mailbox.org/tags/digitaleducation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>digitaleducation</span></a> <a href="https://social.mailbox.org/tags/casestudy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>casestudy</span></a> <a href="https://social.mailbox.org/tags/elearning" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>elearning</span></a></p>
Pyrzout :vm:<p>Cybercriminals are getting personal, and it’s working <a href="https://www.helpnetsecurity.com/2025/08/07/email-attacks-q2-2025/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/08/07</span><span class="invisible">/email-attacks-q2-2025/</span></a> <a href="https://social.skynetcloud.site/tags/cybercriminals" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybercriminals</span></a> <a href="https://social.skynetcloud.site/tags/emailsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>emailsecurity</span></a> <a href="https://social.skynetcloud.site/tags/VIPRESecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VIPRESecurity</span></a> <a href="https://social.skynetcloud.site/tags/BECscams" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BECscams</span></a> <a href="https://social.skynetcloud.site/tags/phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>phishing</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>News</span></a></p>
Runbox<p>⚠️ Watch Out for Phishing Scams</p><p>❌ Don’t click on unknown links<br>❌ Double-check the sender’s email address<br>❌ Never enter your password on unfamiliar pages</p><p>✅ Stay safe — only log in at runbox.com</p><p><a href="https://mastodon.social/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://mastodon.social/tags/EmailSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EmailSecurity</span></a> <a href="https://mastodon.social/tags/Runbox" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Runbox</span></a> <a href="https://mastodon.social/tags/Privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Privacy</span></a> </p><p><a href="https://blog.runbox.com/2025/08/avoid-phishing-scams-what-every-runbox-user-should-know/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.runbox.com/2025/08/avoid-</span><span class="invisible">phishing-scams-what-every-runbox-user-should-know/</span></a></p>
DataDef(AE)<p>🔎 Why Do Hackers Still Use Phishing Links in 2025?</p><p>Because they work.</p><p>Despite advances in cybersecurity tools, phishing remains a primary vector for initial compromise — targeting not systems, but people.</p><p>Here’s what phishing links are really used for 👇</p><p>🧠 Credential harvesting — email, cloud, and corporate logins are sold or used for lateral movement.<br>💰 Financial theft — fake payment pages steal card or crypto wallet data.<br>🏢 Corporate infiltration — a single click by an employee can expose internal systems.<br>🦠 Malware delivery — links often lead to silent installs of trojans, stealers, or ransomware.<br>🧪 User profiling — mass phishing helps attackers identify easy future targets.</p><p>🔐 Defense starts with awareness:</p><p>✔ Check URLs before clicking<br>✔ Use phishing-resistant MFA<br>✔ Educate staff continuously<br>✔ Monitor for social engineering attempts</p><p>Phishing is low-cost, scalable, and increasingly convincing. Organizations can’t afford to rely solely on filters — training and vigilance matter just as much.</p><p>Let’s build a safer digital environment, one educated user at a time.</p><p><a href="https://defcon.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://defcon.social/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://defcon.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://defcon.social/tags/DigitalRisk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DigitalRisk</span></a> <a href="https://defcon.social/tags/SecurityAwareness" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecurityAwareness</span></a> <a href="https://defcon.social/tags/SocialEngineering" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SocialEngineering</span></a> <a href="https://defcon.social/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://defcon.social/tags/EmailSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EmailSecurity</span></a> <a href="https://defcon.social/tags/HumanFactor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HumanFactor</span></a> <a href="https://defcon.social/tags/CyberThreats" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberThreats</span></a></p>
knoppix<p>Proton Mail launches “Newsletters” view — a built-in tool to manage email subscriptions without giving up privacy. 📬</p><p>No third-party access, no tracking, no ads. Just a cleaner inbox, on your terms. A welcome upgrade from one of the most privacy-respecting email providers. 🔒✉️</p><p><span class="h-card" translate="no"><a href="https://mastodon.social/@protonprivacy" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>protonprivacy</span></a></span> </p><p><a href="https://proton.me/blog/proton-mail-newsletters" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">proton.me/blog/proton-mail-new</span><span class="invisible">sletters</span></a></p><p><a href="https://mastodon.social/tags/Privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Privacy</span></a> <a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://mastodon.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mastodon.social/tags/Proton" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Proton</span></a> <a href="https://mastodon.social/tags/ProtonMail" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ProtonMail</span></a> <a href="https://mastodon.social/tags/Email" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Email</span></a> <a href="https://mastodon.social/tags/EmailSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EmailSecurity</span></a> <a href="https://mastodon.social/tags/DigitalPrivacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DigitalPrivacy</span></a> <a href="https://mastodon.social/tags/BigTech" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BigTech</span></a> <a href="https://mastodon.social/tags/DataProtection" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DataProtection</span></a> <a href="https://mastodon.social/tags/TechForGood" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechForGood</span></a> <a href="https://mastodon.social/tags/Tech" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tech</span></a> <a href="https://mastodon.social/tags/TechNews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechNews</span></a></p>
Loki the Cat<p>Breaking: Trying to escape spam can make you spam's favorite person! 📧 Security researchers warn unsubscribe links can confirm active emails and redirect to malicious sites. It's like telling telemarketers your phone works perfectly.</p><p><a href="https://it.slashdot.org/story/25/06/16/1935213/that-unsubscribe-button-could-be-a-trap-researchers-warn" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">it.slashdot.org/story/25/06/16</span><span class="invisible">/1935213/that-unsubscribe-button-could-be-a-trap-researchers-warn</span></a></p><p><a href="https://toot.community/tags/EmailSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EmailSecurity</span></a> <a href="https://toot.community/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://toot.community/tags/DNSFilter" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DNSFilter</span></a></p>
Pyrzout :vm:<p>Email security risks healthcare IT can’t afford to ignore <a href="https://www.helpnetsecurity.com/2025/06/12/healthcare-it-email-security/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/06/12</span><span class="invisible">/healthcare-it-email-security/</span></a> <a href="https://social.skynetcloud.site/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/emailsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>emailsecurity</span></a> <a href="https://social.skynetcloud.site/tags/healthcare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>healthcare</span></a> <a href="https://social.skynetcloud.site/tags/Paubox" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Paubox</span></a> <a href="https://social.skynetcloud.site/tags/report" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>report</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>News</span></a></p>
mailbox.org<p>No more spam in your inbox! Disposable email addresses are the insider tip for anyone wanting to protect their privacy.</p><p>✅ Register anonymously with unknown services <br>✅ Enter competitions without spam risk <br>✅ Online shopping without marketing harassment</p><p>At mailbox.org, disposable addresses are part of the complete package in standard and premium tariffs. </p><p>How it works and why you need it: <a href="https://mailbox.org/en/post/how-disposable-addresses-against-digital-threats" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mailbox.org/en/post/how-dispos</span><span class="invisible">able-addresses-against-digital-threats</span></a></p><p><a href="https://social.mailbox.org/tags/Privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Privacy</span></a> <a href="https://social.mailbox.org/tags/DataProtection" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DataProtection</span></a> <a href="https://social.mailbox.org/tags/EmailSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EmailSecurity</span></a></p>

#Citibank emailed me an alert. The same bank that constantly warns me about email scams. And, yet, they misconfigured their email so it comes as a spoofed email. My email provider delivered it anyway because Citi has a "relaxed" policy in their DNS that says that EMAIL FROM A SPOOFING SERVER CAN BE DELIVERED so long as the signature passes. Yep, servers spoofing them are not a major red flag and the email should be delivered to the inbox anyway. The email provider is not to blame here.

A major bank should not do it this way.

The spoofing SMTP server check failed because the sending IP address is not authorized by Citibank's SPF record for info6.citi.com to send their email. This has been going on for years. Do you want Citibank email from a server not authorized by them to send it?

This relaxed attitude by corporations is why people get scammed.

Authentication-Results: mail.protonmail.ch; spf=fail smtp.mailfrom=info6.citi.com
Authentication-Results: mail.protonmail.ch; arc=none smtp.remote-ip=173.213.5.122

📢 Mail relays | Are you forwarding mail without checks, validation, or spam filtering? You could be creating a real mess. 😵‍💫

Typos, spamtraps, and forged senders can quickly snowball into blocklistings and delivery failures.

In part two of our short series on mail relays, we jump into the chaos careless forwarding can cause, and what you can do to avoid it:

👉 spamhaus.org/resource-hub/deli

1. Hacker News, a #CyberSecurity newsletter, is sent from a domain where DMARC policy is p=none, which tells email providers, like gmail, to deliver all email that is screaming, "I am a Hacker News spoof email sent by a POS scammer" to the intended recipient anyway. p=none means take no action, even if you know it's a scam. Spam folder optional. Email services and clients will oblige. WTF Hacker News?

2. Hacker News is also using an insecure signature algorithm for signing their newsletter.

3. An extremely well-known Cybersecurity expert is sending the newsletter from a domain that has no DMARC record at all, so all spoof emails claiming to be from them will be delivered. And likely this is being constantly exploited. A DMARC policy of p="reject" would have those spoof emails trashed and not delivered. But no DMARC policy means "whatever, and I don't want to know". So, spoof emails go through unstopped and no reports of abuse are being sent to this person either. And it's their job to tell us how to stay secure and not be fooled by spoof emails. WTF?

Sometimes I don't understand how things work in the world.

I received an "important email" from #Dreamhost about my domain registration. You'd think that #email security would be paramount for them.

They have no DKIM setting, so it's impossible to see if the email was tampered with in transit and if it was sent by the claimed sender. And, their DMARC policy is p=none, which tells email providers, "don't do anything special if you can't verify me".

Their dreamhostregistry.com domain is wide open for spoofing because they've configured it to be wide open for spoofing.

How can a web hosting company be so lax about email security? How can I trust emails they send to me if I have no assurance they sent it, and it wasn't modified in transit?

🔐 Email authentication used to be something only big players worried about. Not anymore. While small senders may not feel the heat yet, it’s only a matter of time before it reaches them...

Want to stay ahead of the curve?

Learn how authentication can be implemented at the relay level to improve deliverability, prevent abuse, and protect your reputation before problems hit.

👉 spamhaus.org/resource-hub/deli