Phishing là gì? Nhận diện và phòng chống tấn công lừa đảo trực tuyến
Security

Phishing là gì? Nhận diện và phòng chống tấn công lừa đảo trực tuyến

Phishing là hình thức tấn công Social Engineering lừa người dùng cung cấp thông tin nhạy cảm qua email giả, trang web giả mạo hoặc SMS. Tìm hiểu cách nhận diện phishing, IDN homograph attack và bảo vệ bằng SPF/DKIM/DMARC.

Trong series: Bảo mật
  1. 1 Mã độc là gì? Phân loại, đặc tính và cách phòng tránh
  2. 2 DDos là gì? Dấu hiệu, xử lý và cách phòng chống hiệu quả
  3. 3 Phishing là gì? Nhận diện và phòng chống tấn công lừa đảo trực tuyến
  4. 4 DNS Sinkhole là gì? Ứng dụng và cách dùng kỹ thuật DNS Sinkhole
  5. 5 OAuth 2.0 là gì? Ủy quyền truy cập và đăng nhập bằng Google/Facebook
  6. 6 Trojan là gì? Những thông tin cơ bản về mã độc Trojan
  7. 7 Zero Trust Là Gì? Mô Hình Bảo Mật 'Không Tin Tưởng Ai'
  8. 8 VPN là gì? Mạng riêng ảo, WireGuard và OpenVPN
  9. 9 MFA Là Gì? So Sánh MFA vs 2FA và Các Phương Thức Xác Thực
  10. 10 Tường lửa là gì? Vai trò và chức năng trong bảo mật mạng
  11. 11 SQL Injection là gì? Tấn công cơ sở dữ liệu và cách phòng chống
  12. 12 Ransomware là gì? Mã độc mã hóa tống tiền và cách phòng chống
  13. 13 WAF Là Gì? Web Application Firewall Bảo Vệ Ứng Dụng Web
  14. 14 XSS là gì? Cross-Site Scripting và cách phòng chống hiệu quả
✦ Tóm tắt nhanh
Phishing là hình thức tấn công Social Engineering lừa người dùng cung cấp thông tin nhạy cảm qua email giả, trang web giả mạo hoặc SMS. Tìm hiểu cách nhận diện phishing, IDN homograph attack và bảo vệ...
Bài này thế nào?

Phishing là một trong những vũ khí nguy hiểm nhất mà hacker sử dụng — không cần khai thác lỗ hổng kỹ thuật, chỉ cần lừa con người. Hiểu rõ cơ chế hoạt động của phishing và các biến thể của nó là bước đầu tiên để bảo vệ bản thân và tổ chức trước làn sóng tấn công mạng ngày càng tinh vi.

Phishing là gì? Social Engineering qua web và email

Phishing là hình thức tấn công Social Engineering trong đó kẻ tấn công giả mạo một tổ chức hoặc cá nhân đáng tin cậy — ngân hàng, Google, Amazon, hay thậm chí đồng nghiệp của bạn — để lừa nạn nhân thực hiện hành động có hại: cung cấp mật khẩu, số thẻ tín dụng, mã OTP, hoặc cài đặt phần mềm độc hại.

Điểm cốt lõi của phishing là khai thác tâm lý con người, không phải lỗ hổng kỹ thuật. Các cảm xúc thường bị lợi dụng:

  • Sợ hãi: "Tài khoản của bạn sẽ bị khóa trong 24 giờ nếu không xác minh ngay"
  • Tham lam: "Bạn đã trúng thưởng 50 triệu đồng, nhấn vào để nhận"
  • Tin tưởng: "IT phòng HR yêu cầu bạn cập nhật mật khẩu VPN"
  • Khẩn cấp: "Đơn hàng của bạn sẽ bị hủy nếu không xác nhận trong 2 giờ"

Theo báo cáo Verizon Data Breach Investigations Report (DBIR), khoảng 90% data breach khởi đầu từ một email phishing. Không phải vì hệ thống yếu — mà vì con người luôn là mắt xích dễ bị tấn công nhất trong chuỗi bảo mật.

Phishing không phải là hiện tượng mới — thuật ngữ này xuất hiện từ thập niên 1990 khi hacker giả mạo AOL để đánh cắp thông tin tài khoản. Nhưng ngày nay, các cuộc tấn công ngày càng tinh vi, cá nhân hóa, và khó phân biệt với thông tin liên lạc hợp pháp.

Các hình thức phishing

Email Phishing — Mass, không cá nhân hóa

Hình thức cổ điển và phổ biến nhất. Attacker gửi hàng triệu email giả mạo ngân hàng, PayPal, Amazon, hay các dịch vụ phổ biến. Nội dung thường bao gồm link dẫn đến trang đăng nhập giả, yêu cầu nạn nhân nhập thông tin.

Vì được gửi hàng loạt không cá nhân hóa, email phishing thông thường thường dễ nhận ra hơn — ngôn ngữ chung chung, lỗi chính tả, domain người gửi lạ. Tuy nhiên, tỷ lệ thành công thấp bù lại bằng quy mô khổng lồ: chỉ cần 0.1% trong 10 triệu email bị lừa là attacker đã có 10,000 nạn nhân.

Spear Phishing — Cá nhân hóa, targeted

Spear phishing nhắm vào một cá nhân hoặc tổ chức cụ thể. Attacker nghiên cứu kỹ mục tiêu trước — tên đầy đủ, chức vụ, đồng nghiệp, dự án đang làm — và dùng thông tin đó để tạo email cực kỳ thuyết phục.

Ví dụ: "Chào anh Minh, theo yêu cầu của chị Lan (CEO), anh vui lòng xem qua hợp đồng Q4 đính kèm và phê duyệt trước 5 giờ chiều hôm nay."

Email này có tên thật, đề cập đến cấp trên thật, và tạo áp lực thời gian. Tỷ lệ thành công của spear phishing cao hơn nhiều so với email phishing thông thường — theo một số nghiên cứu, lên đến 30–40%.

Whaling — Nhắm CEO, CFO, CXO

Whaling là spear phishing nhắm vào "cá lớn" — CEO, CFO, hay các lãnh đạo cấp cao. Mục tiêu thường là thực hiện Business Email Compromise (BEC): thuyết phục CFO chuyển tiền vào tài khoản attacker, hoặc lấy được thông tin tài chính nhạy cảm.

FBI ước tính BEC gây thiệt hại hơn 26 tỷ USD trên toàn cầu từ 2016 đến 2022 — cao hơn cả ransomware.

Ransomware là gì? Mã độc mã hóa tống tiền

Smishing — SMS Phishing

Phishing qua tin nhắn SMS. Attacker giả mạo ngân hàng, shipper (GHN, J&T), hay cơ quan chính phủ. Tin nhắn thường ngắn gọn: "Đơn hàng của bạn đang chờ xác nhận: [link]" hoặc "Tài khoản VCB của bạn đã bị khóa, xác minh ngay: [link]".

Smishing hiệu quả vì người dùng thường ít cảnh giác hơn khi đọc SMS so với email, và màn hình nhỏ của điện thoại khiến URL bị rút gọn khó kiểm tra hơn.

Vishing — Voice Call Phishing

Attacker gọi điện trực tiếp, giả mạo nhân viên ngân hàng, hỗ trợ kỹ thuật, hay thậm chí công an. Họ tạo áp lực tâm lý để nạn nhân cung cấp mã OTP, thông tin tài khoản, hay thực hiện chuyển tiền.

Với sự phát triển của AI voice cloning, vishing ngày càng nguy hiểm hơn — attacker có thể clone giọng nói của CEO chỉ từ vài phút audio công khai để gọi điện cho nhân viên tài chính.

Clone Phishing — Nhân bản email hợp pháp

Attacker clone một email hợp pháp mà nạn nhân đã nhận trước đó (newsletter, xác nhận đơn hàng, thông báo từ service thật), thay thế link hoặc attachment bằng phiên bản độc hại, rồi gửi lại giả vờ là "phiên bản cập nhật" hay "gửi lại vì lỗi kỹ thuật".

Clone phishing đặc biệt nguy hiểm vì nạn nhân đã quen với format của email gốc và dễ tin tưởng hơn.

Anatomy của fake login page

Một trang login giả điển hình hoạt động theo quy trình sau:

Bước 1 — URL khác, giao diện giống hệt: Attacker tạo trang web có giao diện copy 1:1 từ trang thật — logo, màu sắc, layout, nội dung. Nhưng URL khác: accounts.g00gle.com, login-google.com, google-accounts-security.com, hay dùng IDN homograph (xem phần tiếp theo).

Bước 2 — Nạn nhân nhập thông tin: Vì giao diện trông giống hệt trang thật, nạn nhân không nghi ngờ và nhập username/password bình thường.

Bước 3 — Credential bị gửi về attacker server: Thay vì đăng nhập vào tài khoản thật, form submit gửi thông tin về server của attacker. Attacker lưu lại credential.

Bước 4 — Redirect về trang thật: Ngay sau khi thu thập thông tin, trang giả redirect nạn nhân về trang đăng nhập thật với thông báo "Phiên đăng nhập hết hạn, vui lòng đăng nhập lại." Nạn nhân đăng nhập thành công vào trang thật và không hay biết mình vừa bị đánh cắp thông tin.

Cả quy trình này xảy ra trong vài giây — đủ để attacker có credential, nhưng quá nhanh để nạn nhân nhận ra có gì đó bất thường.

Kỹ thuật bypass nhận diện

IDN Homograph Attack

Internationalized Domain Names (IDN) cho phép tên miền sử dụng ký tự Unicode. Điều này tạo ra lỗ hổng: nhiều ký tự Unicode trông giống hệt ký tự Latin nhưng thực chất là ký tự khác.

  • Chữ а (Cyrillic U+0430) trông giống a (Latin U+0061)
  • Chữ е (Cyrillic U+0435) trông giống e (Latin U+0065)
  • Chữ ο (Greek U+03BF) trông giống o (Latin U+006F)

Kết quả: pаypal.com (có 'а' Cyrillic) trông giống hệt paypal.com (Latin) trên màn hình, nhưng là domain hoàn toàn khác. Browser hiện đại đã có biện pháp đối phó bằng cách hiển thị dạng punycode: xn--pypal-4ve.com thay vì pаypal.com, nhưng không phải lúc nào cũng hiển thị kịp thời.

URL Shortener

Link như bit.ly/abc123 hay tinyurl.com/xyz che giấu hoàn toàn domain thật. Người dùng không thể biết link sẽ dẫn đến đâu chỉ từ URL rút gọn. Attacker dùng URL shortener để vượt qua bộ lọc email dựa trên blacklist domain.

HTTPS trên fake site

Nhiều người nghĩ "có khóa xanh HTTPS là an toàn" — đây là nhận thức sai phổ biến. HTTPS chỉ mã hóa kết nối, không xác minh trang web là hợp pháp. Attacker có thể đăng ký SSL certificate miễn phí từ Let's Encrypt cho bất kỳ domain nào, kể cả paypa1.com. Trang giả vẫn có khóa xanh.

Subdomain Trick

Domain paypal.com.attacker.com khiến người dùng vội vàng đọc thấy "paypal.com" và tin tưởng. Thực chất, domain thật là attacker.compaypal.com chỉ là subdomain. Kỹ thuật này đặc biệt hiệu quả trên mobile khi URL bị cắt ngắn.

Phòng chống cá nhân

Kiểm tra sender domain — không chỉ display name

Email client hiển thị tên người gửi (display name) mà attacker có thể đặt tùy ý: "PayPal Security" hay "Google Account Team". Điều quan trọng là phải kiểm tra địa chỉ email thực trong dấu <>: security@paypa1.com khác security@paypal.com.

Không tin vào display name — luôn mở header email để xem địa chỉ đầy đủ.

Trước khi nhấp vào link trong email, hover chuột qua link để xem URL thật hiển thị ở status bar phía dưới trình duyệt. Nếu URL không khớp với tổ chức đang liên lạc, đừng click.

Trên mobile, nhấn giữ link để xem preview URL trước khi mở.

Thói quen an toàn nhất: không bao giờ đăng nhập qua link trong email. Thay vào đó, mở browser và gõ trực tiếp địa chỉ trang web (hoặc dùng bookmark đã lưu sẵn). Nếu có vấn đề thật sự với tài khoản, thông báo sẽ hiện ra khi bạn đăng nhập trực tiếp.

2FA — Lá chắn kể cả khi mật khẩu bị lộ

Bật xác thực hai yếu tố (2FA) cho tất cả tài khoản quan trọng. Ngay cả khi attacker đánh cắp được mật khẩu qua phishing, họ vẫn cần mã OTP hoặc hardware key để đăng nhập. 2FA không ngăn được phishing nhưng giảm đáng kể thiệt hại khi mật khẩu bị compromise.

2FA là gì? Bảo mật hai yếu tố

Ưu tiên: Hardware key (YubiKey) > Authenticator app (TOTP) > SMS OTP (dễ bị SIM swap nhất).

Password Manager — Tự detect domain giả

Password manager như Bitwarden hay 1Password lưu credential kèm domain cụ thể. Khi bạn vào paypa1.com (giả), password manager sẽ không tự động điền thông tin vì domain không khớp với paypal.com (thật) trong cơ sở dữ liệu.

Đây là lớp phòng thủ tự động rất hiệu quả — ngay cả khi người dùng không nhận ra trang giả, password manager sẽ không autofill, tạo ra cảnh báo ngầm.

Phòng chống tổ chức: SPF / DKIM / DMARC

Để ngăn kẻ tấn công giả mạo domain của tổ chức bạn (gửi email từ ceo@yourcompany.com), cần cấu hình ba bản ghi DNS:

# DNS TXT records cho domain example.com

# SPF — chỉ mail server Google và Sendgrid được phép gửi
example.com. TXT "v=spf1 include:_spf.google.com include:sendgrid.net -all"

# DKIM — public key verify chữ ký email
google._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0G..."

# DMARC — reject nếu SPF và DKIM đều fail; gửi report về admin
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@example.com; pct=100"

SPF (Sender Policy Framework): Bản ghi SPF liệt kê các mail server được phép gửi email nhân danh domain của bạn. Khi server nhận kiểm tra email từ yourcompany.com, nó tra cứu SPF record và xác minh IP người gửi có trong danh sách cho phép không. -all ở cuối có nghĩa là reject tất cả server không được liệt kê.

DKIM (DomainKeys Identified Mail): DKIM thêm chữ ký số vào mỗi email gửi đi. Mail server của bạn ký email bằng private key; server nhận verify chữ ký bằng public key được publish trong DNS. Chữ ký này bao phủ nội dung email, giúp phát hiện email bị giả mạo hoặc chỉnh sửa trong quá trình truyền.

DMARC (Domain-based Message Authentication, Reporting, and Conformance): DMARC chỉ định chính sách áp dụng khi SPF hoặc DKIM fail:

  • p=none: Chỉ giám sát, không block — dùng khi mới bắt đầu deploy
  • p=quarantine: Chuyển vào spam/junk folder
  • p=reject: Từ chối email hoàn toàn — cấu hình mục tiêu cho production

DMARC cũng cung cấp cơ chế reporting (rua): server nhận gửi báo cáo về địa chỉ email bạn chỉ định, giúp bạn theo dõi ai đang gửi email giả mạo domain của mình.

Lộ trình deploy DMARC:

  1. Bắt đầu với p=nonerua để thu thập dữ liệu (2-4 tuần)
  2. Phân tích report, đảm bảo tất cả mail server hợp pháp đã có trong SPF và có DKIM
  3. Chuyển sang p=quarantine với pct=10 (10% email)
  4. Tăng dần pct lên 100%
  5. Cuối cùng chuyển sang p=reject

XSS là gì? Cross-Site Scripting


Phishing is one of the most dangerous weapons in a hacker's arsenal — it requires no technical exploit, only human deception. Understanding how phishing works and its many variants is the first step toward protecting yourself and your organization against an ever-more-sophisticated wave of cyber attacks.

What is Phishing? Social Engineering via Web and Email

Phishing is a Social Engineering attack in which an adversary impersonates a trusted organization or individual — a bank, Google, Amazon, or even a colleague — to trick victims into taking a harmful action: handing over passwords, credit card numbers, OTP codes, or installing malware.

The core of phishing is exploiting human psychology, not technical vulnerabilities. Emotions commonly leveraged include:

  • Fear: "Your account will be locked in 24 hours if you don't verify immediately"
  • Greed: "You've won $2,000 — click here to claim your prize"
  • Trust: "IT from HR is requesting you update your VPN password"
  • Urgency: "Your order will be cancelled if you don't confirm within 2 hours"

According to the Verizon Data Breach Investigations Report (DBIR), approximately 90% of data breaches begin with a phishing email. Not because systems are weak — but because humans are always the most exploitable link in the security chain.

Phishing is not a new phenomenon — the term dates back to the 1990s when hackers impersonated AOL to steal account credentials. But today's attacks are increasingly sophisticated, personalized, and indistinguishable from legitimate communications.

Types of Phishing Attacks

Email Phishing — Mass, Non-Personalized

The classic and most common form. Attackers send millions of fake emails impersonating banks, PayPal, Amazon, or popular services. Messages typically include a link to a fake login page, urging victims to enter their credentials.

Because they are sent at mass scale without personalization, standard phishing emails are often easier to spot — generic language, spelling errors, unfamiliar sender domains. However, low success rates are offset by enormous volume: even 0.1% of 10 million emails yields 10,000 victims.

Spear Phishing — Personalized and Targeted

Spear phishing targets a specific individual or organization. Attackers research their target carefully beforehand — full name, title, colleagues, current projects — and use that information to craft extremely convincing emails.

Example: "Hi Alex, per the request of CEO Sarah, please review the attached Q4 contract and approve before 5 PM today."

This email includes a real name, references a real superior, and creates time pressure. Success rates for spear phishing are dramatically higher than mass phishing — some studies report 30–40%.

Whaling — Targeting CEOs, CFOs, and C-Suite

Whaling is spear phishing aimed at "big fish" — CEOs, CFOs, or other senior executives. The goal is often Business Email Compromise (BEC): convincing a CFO to wire funds to an attacker-controlled account, or extracting sensitive financial data.

The FBI estimates BEC caused over $26 billion in losses globally from 2016 to 2022 — more than ransomware.

Smishing — SMS Phishing

Phishing via SMS. Attackers impersonate banks, delivery services, or government agencies. Messages are typically brief: "Your package is awaiting confirmation: [link]" or "Your account has been locked, verify now: [link]".

Smishing is effective because users tend to be less vigilant when reading SMS than email, and small mobile screens make it harder to inspect URLs.

Vishing — Voice Call Phishing

Attackers call directly, impersonating bank staff, tech support, or even law enforcement. They apply psychological pressure to extract OTP codes, account credentials, or authorize fund transfers.

With the rise of AI voice cloning, vishing is increasingly dangerous — attackers can clone a CEO's voice from just a few minutes of publicly available audio to call a finance employee.

Clone Phishing — Duplicating Legitimate Emails

Attackers clone a legitimate email the victim has already received (newsletter, order confirmation, notification from a real service), replace links or attachments with malicious versions, and resend it as an "updated version" or "resent due to a technical error."

Clone phishing is particularly dangerous because victims are already familiar with the format of the original email and are more likely to trust it.

Anatomy of a Fake Login Page

A typical fake login page follows this sequence:

Step 1 — Different URL, identical interface: The attacker creates a website with a pixel-perfect copy of the real site — logo, colors, layout, content. But the URL is different: accounts.g00gle.com, login-google.com, google-accounts-security.com, or using IDN homographs (see next section).

Step 2 — Victim enters credentials: Because the interface looks identical to the real site, the victim has no reason for suspicion and enters their username and password as normal.

Step 3 — Credentials sent to the attacker's server: Instead of logging into the real account, the form submission sends the credentials to the attacker's server, where they are stored.

Step 4 — Redirect to the real site: Immediately after collecting the information, the fake page redirects the victim to the real login page with a message such as "Session expired, please log in again." The victim logs in successfully and has no idea they were just compromised.

This entire process takes seconds — enough time for the attacker to capture credentials, but far too fast for the victim to notice anything wrong.

Techniques to Bypass Detection

IDN Homograph Attack

Internationalized Domain Names (IDN) allow domain names to use Unicode characters. This creates a vulnerability: many Unicode characters look identical to Latin characters but are technically different.

  • The letter а (Cyrillic U+0430) looks like a (Latin U+0061)
  • The letter е (Cyrillic U+0435) looks like e (Latin U+0065)
  • The letter ο (Greek U+03BF) looks like o (Latin U+006F)

Result: pаypal.com (with Cyrillic 'а') looks identical to paypal.com (Latin) on screen, but is an entirely different domain. Modern browsers counter this by displaying the punycode form: xn--pypal-4ve.com instead of pаypal.com, though this is not always shown proactively.

URL Shorteners

Links like bit.ly/abc123 or tinyurl.com/xyz completely conceal the true destination domain. Users cannot know where a shortened link leads just by looking at it. Attackers use URL shorteners to bypass email filters that rely on domain blacklists.

HTTPS on Fake Sites

Many users believe "the green HTTPS padlock means it's safe" — this is a widespread misconception. HTTPS only encrypts the connection; it does not verify the website is legitimate. Attackers can obtain a free SSL certificate from Let's Encrypt for any domain, including paypa1.com. The fake site still displays a green padlock.

Subdomain Tricks

A domain like paypal.com.attacker.com leads users who skim quickly to see "paypal.com" and trust the link. In reality, the actual domain is attacker.compaypal.com is merely a subdomain. This technique is particularly effective on mobile where URLs are truncated.

Personal Defenses Against Phishing

Check the Sender Domain — Not Just the Display Name

Email clients display the sender's name (display name), which an attacker can set to anything: "PayPal Security" or "Google Account Team." What matters is the actual email address inside <>: security@paypa1.com is not security@paypal.com.

Never trust the display name alone — always expand the email header to see the full address.

Before clicking any link in an email, hover your mouse over it to see the real URL appear in the browser's status bar at the bottom. If the URL does not match the organization contacting you, do not click.

On mobile, press and hold a link to see a URL preview before opening it.

The safest habit: never log into an account via a link in an email. Instead, open your browser and type the website address directly (or use a saved bookmark). If there is a genuine issue with your account, it will appear when you log in directly.

2FA — Your Shield Even When Passwords Are Stolen

Enable two-factor authentication (2FA) on all important accounts. Even if an attacker steals your password via phishing, they still need your OTP code or hardware key to log in. 2FA does not prevent phishing but significantly reduces the damage when a password is compromised.

Priority: Hardware key (YubiKey) > Authenticator app (TOTP) > SMS OTP (most vulnerable to SIM swap).

Password Managers — Automatically Detecting Fake Domains

Password managers like Bitwarden or 1Password store credentials tied to a specific domain. When you visit paypa1.com (fake), the password manager will not autofill your credentials because the domain does not match paypal.com (real) in its database.

This is an extremely effective automatic defense layer — even if a user fails to recognize a fake site, the password manager will not autofill, creating an implicit warning.

Organizational Defenses: SPF / DKIM / DMARC

To prevent attackers from spoofing your organization's domain (sending emails appearing to come from ceo@yourcompany.com), configure these three DNS records:

# DNS TXT records for domain example.com

# SPF — only Google and Sendgrid mail servers are authorized to send
example.com. TXT "v=spf1 include:_spf.google.com include:sendgrid.net -all"

# DKIM — public key to verify email signatures
google._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0G..."

# DMARC — reject if both SPF and DKIM fail; send reports to admin
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@example.com; pct=100"

SPF (Sender Policy Framework): The SPF record lists the mail servers authorized to send email on behalf of your domain. When a receiving server checks an email from yourcompany.com, it looks up the SPF record and verifies whether the sender's IP is in the authorized list. The -all at the end means reject all servers not listed.

DKIM (DomainKeys Identified Mail): DKIM adds a digital signature to each outgoing email. Your mail server signs the email with a private key; the receiving server verifies the signature using the public key published in DNS. This signature covers the email content, enabling detection of spoofed or tampered emails in transit.

DMARC (Domain-based Message Authentication, Reporting, and Conformance): DMARC specifies the policy to apply when SPF or DKIM fails:

  • p=none: Monitor only, no blocking — use when starting to deploy
  • p=quarantine: Move to spam/junk folder
  • p=reject: Reject the email entirely — the target configuration for production

DMARC also provides a reporting mechanism (rua): receiving servers send reports to your designated email address, allowing you to monitor who is sending emails impersonating your domain.

DMARC Deployment Roadmap:

  1. Start with p=none and rua to collect data (2–4 weeks)
  2. Analyze reports; ensure all legitimate mail servers are covered by SPF and have DKIM configured
  3. Switch to p=quarantine with pct=10 (10% of emails)
  4. Gradually increase pct to 100%
  5. Finally switch to p=reject

What is XSS? Cross-Site Scripting

What is Ransomware? Encrypting Malware and Extortion

What is 2FA? Two-Factor Authentication