• DigitalDilemma
    link
    fedilink
    English
    028 days ago

    This is not reliable.

    Phish training companies are using a huge variety of domains, including look-alikes relevant to the test - including valid spf/dkim/dmarc configurations. Exactly as real phishers do - and there’s no effective way to automate their filtering.

    • slazer2au
      link
      fedilink
      English
      028 days ago

      Are you sure? Have you ever looked at the header of an email from knowb4 or phishme? The emails come from their own mail servers.

      • DigitalDilemma
        link
        fedilink
        English
        028 days ago

        Yes, absolutely. We used to use knowbe4. I’m not saying they didn’t do this in the past, but I know for certain they didn’t when I checked.

        There were obviously hints - the campagns are designed to be detectable - but easy filtering was not one of them, that would be stupid.