- Hands-On G Suite for Administrators
- Cesar Anton Dorantes
- 405字
- 2021-06-24 15:32:15
Spoofing and authentication
Sometimes, we get messages that attempt to trick us into providing sensitive information by pretending to be a trusted source. This is a very common and effective way to tricking members of the organization into leaking data or providing their credentials:

Spoofing and authentication contains several measures to keep the team protected:
- Protect against domain spoofing based on similar domain names: A common way to try to trick you into giving your password is showing you a fake login using a similar domain name. This option will make Gmail try to detect this kind of attack. You can choose whether it would be best to just show a warning next to suspicious messages or whether they should be moved to the spam folder directly:

- Protect against spoofing of employee names: Enabling this will block messages coming from a known address, but which lacks the appropriate certificate. By default, it will keep the message and warn the user that the sender could not be confirmed, but it can be changed to Move email to spam instead so that it can be seen by the user if necessary:

- Protect against inbound emails spoofing your domain: Attackers may attempt to steal information by sending messages using your domain as the origin. These may have a valid address from one of the members of the organization, but it will be lacking a digital certificate. In this section, you can choose how you wish to deal with these kinds of messages within your organization.
By default, a warning will be shown to users before they open these kinds of messages, but they will be visible from their inbox. As an administrator, you can choose to change this to Move email to spam when they lack the proper certificate:

- Protect against any unauthenticated emails.This option will target all messages whose sender could not be verified. Usually, this has no action by default. But it's recommended to change it to Move email to spam or to Keep email in inbox and show a warning to warn the user of suspicious content:

It's recommended to use an attack simulator for Gmail at random intervals to train your users into recognizing and acting against different kinds of phishing attacks.
Once or twice a month should be enough to keep everyone on the lookout for this kind of threat.
推薦閱讀
- 辦公軟件高級應用實用教程
- 從原始數據到分析報告:Excel數據透視表高效達人養成記
- 用友ERP-U8(8.72版)標準財務模擬實訓
- 新編電腦辦公(Windows 7 + Office 2013版)從入門到精通
- The Art of CRM
- Excel公式與函數大辭典
- Excel辦公高手應用技巧
- 電腦辦公直通車
- Java EE 8 Cookbook
- 新編Word/Excel/PPT商務辦公應用大全(2016實戰精華版)
- Office 2016辦公應用從入門到精通
- PPT進化:如何設計一份驚艷的PPT
- 辦公軟件高級應用實驗指導
- ChatGPT+Excel高效數據計算與處理(視頻教學版)
- PowerPoint 2016從入門到精通