• DigitalDilemma@lemmy.ml
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 days ago

    This is not reliable.

    Phish training companies are using a huge variety of domains, including look-alikes relevant to the test - including valid spf/dkim/dmarc configurations. Exactly as real phishers do - and there’s no effective way to automate their filtering.

    • slazer2au@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      5 days ago

      Are you sure? Have you ever looked at the header of an email from knowb4 or phishme? The emails come from their own mail servers.

      • DigitalDilemma@lemmy.ml
        link
        fedilink
        English
        arrow-up
        4
        ·
        5 days ago

        Yes, absolutely. We used to use knowbe4. I’m not saying they didn’t do this in the past, but I know for certain they didn’t when I checked.

        There were obviously hints - the campagns are designed to be detectable - but easy filtering was not one of them, that would be stupid.