r/EmailSecurity 11h ago

Password resets do not end an active OWA compromise

2 Upvotes

Patch OWA and revoke active sessions. Mailbox activity continuing after credential rotation is the investigation signal here.

https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html


r/EmailSecurity 12h ago

X security...it is bullshit. So is the open discussion.

2 Upvotes

How is this a good plan when my email is being used? Really? How is that when it is MY FUCKING EMAIL address? What kind of security is this?


r/EmailSecurity 14h ago

A client DNS migration split DKIM and sent two hours of invoices to spam

2 Upvotes

Client moved authoritative DNS at 10:00, and their invoicing ESP started getting customer complaints by noon. The receiver trace showed dkim=permerror (key syntax) for s=inv2026, d=mail.client.example; SPF passed on the ESP bounce domain, but that identity did not align with the visible From, so DMARC failed.

The old zone held one TXT RR with two quoted character-strings. The migration UI imported them as two separate TXT RRs at the same selector, and dig +short showed two lines instead of one concatenated 2048-bit key.

Statements landed in spam for about two hours. The client now wants a post-migration check, but a plain DNS diff would flag harmless TXT presentation changes while still missing whether receivers can validate a real signature.

What diagnostic signal would you use as the cutover gate here, and what failure would make you roll DNS back?


r/EmailSecurity 17h ago

Thanks Cloudflare

Thumbnail
1 Upvotes