Connect with us

Hi, what are you looking for?

News

We’ve revised our SMIME email security standard

SMIME

SMIME Email Security Revised: Following challenges around support inconsistencies and a mobile shortfall with SMIME, the SigniFlow development team has taken the decision to change the default email policy for cloud and hybrid servers.

As of 1 October 2021, SigniFlow’s default email security will subscribe to the DMARC authentication standard, in lieu of SMIME.

The change in mail standard is based on SigniFlow’s core design priority, i.e. security. Since inception, security has been the driving factor behind all SigniFlow system changes and development decisions.

In recent months in particular, SMIME has become a cumbersome process for many of our clients’ document recipients. Specifically, because SMIME is not widely introduced on mobile devices, messages on these devices end up being displayed as attachments, as opposed to the intended format.

The screenshot below illustrates this issue:

Similarly, with many organisations having introduced email scanning services like Mimecast, the scanning and flagging of emails effectively breaks the signature and shows the email as being tampered with.

The screenshot below illustrates this issue:

Introducing DMARC

DMARC (Domain-based Message Authentication, Reporting & Conformance) is a technical standard that helps protect email senders and recipients from advanced threats that can be the source of an email data breach. DMARC email security provides a way for domain owners to outline their authentication practices and specify the actions to be taken when an email fails authentication. DMARC also provides a way for recipients to report on email that fails authentication.

DMARC benefits businesses by providing another layer of protection that guards against attacks like impersonation fraud, where an attacker uses a legitimate domain to send a fraudulent message.

How will it work going forward?

As of October 2021, mails will no longer be signed with SMIME certificates by default. Instead, SigniFlow will be adopting SPF, DKIM and DMARC records to ensure email origination can be validated by receiving mail servers.

SMIME signing of emails will still be available as a feature, and can be enabled on request for hybrid server clients.

For more information, read Agari’s email security blog HERE, or this LinkedIn article by cybersecurity professional, Marnix Dekker, HERE.

REFERENCES

  1. Mimecast: What is DMARC
  2. LinkedIn: https://www.linkedin.com/pulse/stop-asking-encrypted-email-marnix-dekker/
  3. Agari.com: https://www.agari.com/email-security-blog/dmarc-101-part-smime-spf-dkim/

You May Also Like

Electronic Signatures

Digital signing for SMEs: Enterprise power without the complexity  Running a small or medium-sized business often means balancing growth with efficiency. Teams are smaller, budgets...

Electronic Signatures

Can a digital signature be proven in court?  As more organisations move to paperless processes, a common legal concern continues to surface. If a digital signature...

Electronic Signatures

What happens when a digitally signed document is challenged years later?  What happens when a digitally signed document is challenged years after it was...

Electronic Signatures

What are the advantages of enterprise electronic signatures?  Enterprise organisations operate in environments where speed, security, compliance, and operational efficiency are critical. The advantages of enterprise...

Electronic Signatures

Affordable electronic signature solution for small businesses  Running a small business means finding ways to do more with less. Time is limited, resources are...

Release Notes

Our latest release introduces several enhancements, new features, and fixes designed to improve performance and usability. Here’s a quick overview of what’s included in...

Electronic Signatures

Australia’s Tranche 2 compliance requirements: What businesses need to know   Australia’s regulatory landscape is changing, and organisations across legal, accounting, property, and professional services sectors are preparing for Tranche 2 compliance requirements. As...

Electronic Signatures

Can you prove where your government data is stored during an audit?  Governments around the world are under increasing pressure to modernise services, digitise...

Electronic Signatures

What does SigniFlow’s ISO 27001 Certification mean for your business?  You have probably seen the ISO 27001 badge and thought, “That sounds important.”  But what does ISO actually mean for...

Electronic Signatures

How do you know who is really signing? The hidden risk in electronic signatures Most industries are no longer slowly transitioning into the digital world. They are fully...

Copyright © 2023 - SIGNIFLOW© SOFTWARE
Disclaimer: The information in this BLOG is provided for general informational purposes only and is the opinion of the author only. No information contained in this blog should be construed as legal advice from SigniFlow or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this blog should act or refrain from acting on the basis of any information included in, or accessible through, this blog without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue.