Link to home
Start Free TrialLog in
Avatar of DARSHAN DIORA
DARSHAN DIORAFlag for India

asked on

Email security isues

We are using Microsoft 365 - Outlook.
Recently we are facing issues like email send from many of customers are seems to be from different email users may be hacker.
Like earlier original mail from one customer purchase@mesco.in  and now i checked its from purchase.mesco.in@mail.com. when we send proforma invoice to our customer they receive with different  bank details than us due to this same one of customer transferred the payment to this fraudster. How can we resolve this.

Best Regartds
Darshan
Avatar of Hayes Jupe
Hayes Jupe
Flag of Australia image

implement standard mail security features, such as DNS reverse lookups, SPF, DKIM/DMarc

advise your clients to also implement these.

Organisations not having the basics implemented (at least SPF and reverse lookup as a minimum) is a disaster waiting to happen.
Avatar of DARSHAN DIORA

ASKER

Hi,
we are using Microsoft 365 and having cloud based emails and no server control Kindly explain where its has to be implemented 
Office 365 is just installed on the Desktop but email taken from Bigrock. Kindly explain in detials where it has to be implemented  
You will need to inform your customers that invoices will only come from your domain name. Example, invoices@<yourdomain.com>
 
Since you are using Microsoft365, it should help generate the needed spf record for your domain, but as Hayes Jupe mentioned, you should also look at setting up your DKIM and DMARC records after your spf is confirmed. I advise you work with your current DNS/Domain name provider to help you with this.
Hi
Can any tweak possible at desktop level  to resolve this issue as we have Quick heal antivirus updated and windows 10 updated yesterday.
SOLUTION
Avatar of David Favor
David Favor
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
My bet is some of your users are getting compromised. On top of the controls that have been suggested here, you need a better password policy, along with multi factor authentication.
when we send proforma invoice to our customer they receive with different  bank details than us
what generates the proforma invoice? What is the path from generation to the reception by the client?  You can only do so much at your end and the client also has to take responsibility as well.
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial