• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Use SPF and Don’t Get Burned!

July 11, 2017 Posted by Chris Barretto Cybersecurity, IT Security

When one hears the acronym ‘SPF,’ the first thing that comes to mind is protection from the sun. But in the realm of information security, SPF is synonymous with protection from annoyances such as spam and malicious attacks such as phishing. While spam can be a pain in the butt – it is phishing that can truly harm an organization. By either harvesting company credentials or by tricking the end user in clicking on an attachment, a malicious attacker can do serious damage. A properly configured SPF record can help prevent this from occurring.

SPF stands for ‘Sender Policy Framework’ and it simply represents a list of email servers which are authorized to send email using a given domain name. They are designed to protect against forged emails and the delivery of incoming spam messages. From a technical perspective, an SPF record is a DNS TXT record that a mail server can access to verify if the source of the email message corresponds to an authorized sender. If the source IP address is not listed within the organization’s SPF record, the email will never make it the user’s inbox. A properly configured SPF record will take part of the burden off of the user, since the user will never have an opportunity to click on a malicious email using a “spoofed” domain name.

To configure SPF, a company’s system administrator will augment their existing DNS records with a special TXT record. This extra DNS record links the MX record identifying the mail server with the IP addresses of all hosts which are allowed to send email using that domain. For example, consider the company MyCompany.com. A properly configured SPF record will prevent a malicious attacker from sending inbound email as [email protected], in an attempt to trick a user into thinking the email actually came from the IT department. If this risk was not mitigated, an attacker could potentially mimic a user within the corporate environment to gain the trust of their victims.

As with any technical change – one should vigorously test its behavior before and after implementation. Try and spoof your own domain in an attempt to validate that SPF is properly configured. Once fully implemented, an SPF record will ensure that only YOU can send emails as YOU!

So as the height of summer approaches, and phishing attacks continue to make headlines, remember to wear plenty of SPF this summer and make sure that the Sender Policy Framework is protecting your environment! For more information on SPF check out OpenSPF.org or contact OCD Tech today. 844-OCDTECH

Tags: emailphishingsender policy frameworkSPF
Share
0
Chris Barretto

About Chris Barretto

Chris is a Senior IT Auditor at O’Connor & Drew. He works on a number of engagements with the firm, focusing on heavily regulated entities.

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next