window.nitroFragments['2b6a7c5ecb9050fd1eb9f9df9eed88de'] = {"isLazyLoaded":true,"content":"<div id="av_section_15" data-section-bg-repeat="stretch" class="avia-section av-7ux4xa1-ae05f10917e85711dfbaff30884ff104 alternate_color avia-section-no-padding avia-no-border-styling avia-builder-el-207 el_after_av_section el_before_av_section u-padding--larger--ends u-padding--ends--portable avia-full-stretch avia-bg-style-scroll container_wrap fullsize nitro-lazy" nitro-fragment-parent><div class="container av-section-cont-open"><div class="template-page content  av-content-full alpha units"><div class="post-entry post-entry-type-page post-entry-19935"><div class="entry-content-wrapper clearfix"> <div class="hr av-7fryamx-1d5263b9c5c92e1931e25252c120236a hr-invisible  avia-builder-el-208  el_before_av_textblock  avia-builder-el-first  av-small-hide av-mini-hide"><span class="hr-inner"><span class="hr-inner-style"></span></span></div> <section class="av_textblock_section av-6xr8dw9-8e0393c1e9dbe0bea7b58a6da3d86172"><div class="avia_textblock av_inherit_color"><h2 class="p1" style="text-align:center;"><strong>Critical Errors Organizations in Canada are Making</strong></h2> <p style="text-align:center;"><span style="font-weight:400;">On analyzing 140 Canadian domains from various sectors and industries, it is evident that organizations in Canada are making some critical errors that can jeopardize their online reputation and the safety of their clients:</span></p> </div></section> <div class="flex_column av-6lbv9y1-f410d18d523b45f16833069d406b44b1 av_one_half  avia-builder-el-210  el_after_av_textblock  el_before_av_one_half  u-padding--large--ends--desk first flex_column_div av-zero-column-padding  column-top-margin"><div class="avia-icon-list-container av-670ow6x-16b1d4cce777aa2606943f27c324264a  avia-builder-el-211  el_before_av_hr  avia-builder-el-first"><ul class="avia-icon-list avia_animate_when_almost_visible avia-icon-list-left av-iconlist-big av-670ow6x-16b1d4cce777aa2606943f27c324264a avia-iconlist-animate"> <li><div class="iconlist_icon av-kv80dowa-45f3247299f1ae0b4832a32bd1106247 avia-font-entypo-fontello"><span class="iconlist-char" aria-hidden="true" data-av_icon="" data-av_iconfont="entypo-fontello"></span></div><article class="article-icon-entry"><div class="iconlist_content_wrap"><header class="entry-content-header"><h4 class="av_iconlist_title iconlist_title  av_inherit_color">Complete Absence of SPF and DMARC records</h4></header><div class="iconlist_content"><p><span style="font-weight:400;">Email authentication protocols like SPF and DMARC can help organizations mitigate a diverse collection of impersonation attacks, ransomware, and BEC to reduce the risk of identity thefts and data breaches. The absence of these records among a considerable number of Canadian domains was found.</span></p> </div></div><footer class="entry-footer"></footer></article><div class="iconlist-timeline"></div></li> <li><div class="iconlist_icon av-5vj7ck9-d1ed2ae6a0d716bb1c60c73e38a9ca98 avia-font-entypo-fontello"><span class="iconlist-char" aria-hidden="true" data-av_icon="" data-av_iconfont="entypo-fontello"></span></div><article class="article-icon-entry"><div class="iconlist_content_wrap"><header class="entry-content-header"><h4 class="av_iconlist_title iconlist_title  av_inherit_color">Presence of Invalid SPF and DMARC records</h4></header><div class="iconlist_content"><p><span style="font-weight:400;">A surprisingly high number of domains operated by Canadian organizations were misconfigured or had invalid SPF and DMARC records. This meant that email administrators were unable to detect and filter mail from these sources as it was not possible to identify their source. These completely rendered the process of setting up email authentication futile.</span></p> </div></div><footer class="entry-footer"></footer></article><div class="iconlist-timeline"></div></li> <li><div class="iconlist_icon av-54vn0vt-28b687614670c4871a47467a8c7acb8b avia-font-entypo-fontello"><span class="iconlist-char" aria-hidden="true" data-av_icon="" data-av_iconfont="entypo-fontello"></span></div><article class="article-icon-entry"><div class="iconlist_content_wrap"><header class="entry-content-header"><h4 class="av_iconlist_title iconlist_title  av_inherit_color">Lack of DMARC enforcement</h4></header><div class="iconlist_content"><p><span style="font-weight:400;">Another prominent finding from the examination of Canadian domains was that while DMARC records existed for a certain percentage of the domains, the rate of DMARC enforcement among them was low, that is the majority of the domains had their DMARC policy set to none, enabling monitoring only.&nbsp;</span></p> <p><i><span style="font-weight:400;">Note that a DMARC none policy doesn’t protect against spoofing, phishing, and ransomware attacks. Only an enforced policy of quarantine/reject can provide a certain level of immunity against impersonation. </span></i></p> </div></div><footer class="entry-footer"></footer></article><div class="iconlist-timeline"></div></li> </ul></div> <div class="hr av-46qscah-279526aa6cfe16baaa45f05e59cac9af hr-invisible  avia-builder-el-212  el_after_av_iconlist  avia-builder-el-last  av-small-hide av-mini-hide"><span class="hr-inner"><span class="hr-inner-style"></span></span></div></div><div class="flex_column av-3u2dfy1-1718c6eb890ee41bc427a31e348f8548 av_one_half  avia-builder-el-213  el_after_av_one_half  avia-builder-el-last  u-padding--large--ends--desk flex_column_div av-zero-column-padding  column-top-margin"><div class="avia-icon-list-container av-3o4xjkp-77b91e7771aa42649d65927ccd353fff  avia-builder-el-214  el_before_av_hr  avia-builder-el-first"><ul class="avia-icon-list avia_animate_when_almost_visible avia-icon-list-left av-iconlist-big av-3o4xjkp-77b91e7771aa42649d65927ccd353fff avia-iconlist-animate"> <li><div class="iconlist_icon av-2xq8kt5-104e45e3920ff8ee1d03cf7cef94fb91 avia-font-entypo-fontello"><span class="iconlist-char" aria-hidden="true" data-av_icon="" data-av_iconfont="entypo-fontello"></span></div><article class="article-icon-entry"><div class="iconlist_content_wrap"><header class="entry-content-header"><h4 class="av_iconlist_title iconlist_title  av_inherit_color">Too many DNS lookups for SPF</h4></header><div class="iconlist_content"><p><span style="font-weight:400;">Since SPF has a 10 DNS lookup limit, exceeding the limit can lead to SPF failure during authentication. One of the reasons for invalid SPF records spotted in the DNS of Canadian domains might be due to too many DNS lookups that can break SPF.</span></p> </div></div><footer class="entry-footer"></footer></article><div class="iconlist-timeline"></div></li> <li><div class="iconlist_icon av-2dftzvd-f06618d2cf3e071455d5392183ddb098 avia-font-entypo-fontello"><span class="iconlist-char" aria-hidden="true" data-av_icon="" data-av_iconfont="entypo-fontello"></span></div><article class="article-icon-entry"><div class="iconlist_content_wrap"><header class="entry-content-header"><h4 class="av_iconlist_title iconlist_title  av_inherit_color">Multiple SPF or DMARC records for the same domain</h4></header><div class="iconlist_content"><p><span style="font-weight:400;">Among best practices for email authentication, each domain must possess only one SPF or DMARC record for it to be considered valid. The presence of multiple records for the same domain can invalidate all of them.</span></p> </div></div><footer class="entry-footer"></footer></article><div class="iconlist-timeline"></div></li> </ul></div> <div class="hr av-268q5eh-4a479bf234d7c60219f844bf76d01eb3 hr-invisible  avia-builder-el-215  el_after_av_iconlist  avia-builder-el-last  av-small-hide av-mini-hide"><span class="hr-inner"><span class="hr-inner-style"></span></span></div></div> </div></div></div></div></div>"}; window.dispatchEvent(new CustomEvent('nitrofragmentloaded', {detail: "2b6a7c5ecb9050fd1eb9f9df9eed88de"}));