|
||
|
||

A new case study from eco documents how ams OSRAM approached securing its corporate email infrastructure, focusing on the deployment of three established authentication mechanisms: SPF, DKIM and DMARC.
The case study is intended as a practical implementation reference for organizations seeking to reduce domain spoofing and phishing while gaining better visibility into the systems sending email on their behalf.
The project began with a problem common to large organizations: incomplete visibility into email sources. Companies may operate numerous domains while email is generated by internal infrastructure, cloud services, marketing platforms and other third-party systems. Without a complete inventory, configuring authentication policies can leave legitimate senders unidentified or domains insufficiently protected.
The case study centers on three complementary technologies. Sender Policy Framework (SPF) identifies servers authorized to send mail for a domain. DomainKeys Identified Mail (DKIM) uses cryptographic signatures to allow receiving systems to verify that a message was authorized by the signing domain and has not been altered in transit. Domain-based Message Authentication, Reporting and Conformance (DMARC) builds on SPF and DKIM, providing domain owners with policy controls and reports about authentication results.
For ams OSRAM, the objectives extended beyond blocking fraudulent messages. The project sought to protect the company’s brand identity against phishing and spoofing, improve deliverability of legitimate email to customers and partners, identify legitimate and illegitimate sending sources, and address security and compliance requirements.
“Email security is one of the fundamental protective measures,” said Steffen Siguda, Corporate Information Security Officer at ams OSRAM Group. He noted that the underlying measures can substantially improve the traceability of email without requiring investment in a dedicated tool, adding that the case study sets out steps other companies can take.
The deployment challenge is particularly relevant because authentication policies depend on knowing which systems are legitimately entitled to use an organization’s domains. Moving toward stronger enforcement therefore requires organizations to first establish that visibility and correctly authenticate legitimate traffic, rather than simply publishing restrictive policies.
The full case study is available from eco for organizations that want to examine the implementation in greater detail. It provides the practical steps behind the ams OSRAM project and shows how SPF, DKIM and DMARC can be incorporated into a broader approach to protecting corporate domains and email communications.
Readers can download “Email Security in Practice: The ams OSRAM Case Study” from eco.
Sponsored byWhoisXML API
Sponsored byIPv4.Global
Sponsored byVerisign
Sponsored byCSC
Sponsored byVerisign
Sponsored byDNIB.com
Sponsored byRadix