Jason Rebholz - TeachMeCyber
Jason Rebholz - TeachMeCyber
  • 67
  • 816 385
What is SPF, DKIM, DMARC, and BIMI | Easy Explanations
Attackers want to spoof your email domain to sending phishing emails. If you don't take the right steps to secure your email and domain authentication, you are putting your organization at risk. Plus, major email providers, like Google, and new PCI-DSS require stronger controls.
In this video, we'll cover key email authentication protocols like:
- SPF (Sender Policy Framework)
- DKIM (DomainKeys Identified Mail)
- DMARC (Domain-based Message Authentication and Conformance)
- BIMI (Brand Indicator for Message Identification)
- MTA-STS (Mail Transfer Agent Strict Transport Security)
- TLS-RPT (TLS Reporting)
Get the latest in cyber security with my weekly newsletter: weekendbyte.teachmecyber.com
❤️ Leave a comment and hit the like button because it helps spread cyber security knowledge to more people.
Table of Contents
00:00 - Intro
00:30 - What is SPF (Sender Policy Framework)?
01:18 - What is DKIM (DomainKeys Identified Mail)?
02:33 - What is DMARC (Domain-based Message Authentication and Conformance)?
04:01 - What is BIMI (Brand Indicator for Message Identification)?
05:08 - What is MTA-STS (Mail Transfer Agent Strict Transport Security)?
06:14 - What is TLS-RPT (TLS Reporting)?
06:55 - Check out PowerDMARC
🔔If you found this helpful, subscribe to the channel!
www.youtube.com/@teachmecyber?sub_confirmation=1
🚀 Connect with me on LinkedIn
www.linkedin.com/in/jrebholz
Переглядів: 5 345

Відео

The Fastest (AND EASIEST) Email Security | Configure Email and Domain Authentication with PowerDMARC
Переглядів 1,9 тис.10 місяців тому
Get started with PowerDMARC today: Sign up: app.powerdmarc.com/en/members/register Homepage: powerdmarc.com Overview: Attackers want to spoof your email domain to sending phishing emails. If you don't take the right steps to secure your email and domain authentication, you are putting your organization at risk. Plus, major email providers, like Google, and new PCI-DSS require stronger controls....
Best VPNs in 2024 | Do You Need a VPN?
Переглядів 1,6 тис.11 місяців тому
As a security expert, I'm often asked whether you need a VPN and which ones are the best. In this video, I'll explain how a VPN works, the key use cases for VPNs (and whether you should use one), and discuss the top five VPNs on the market right now. 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links VPN Providers NordVPN: go.nordvpn.net/aff_c?offer_id=15&aff_...
Hackers Targeting Bitwarden Vaults | Easy Steps to Protect Your Passwords
Переглядів 24 тис.Рік тому
Hackers are targeting Bitwarden password vaults and selling them on the dark web. You can protect your account with these easy steps. Take action now to set up your FIDO2 WebAuthN passkeys today! 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links Bitwarden: bitwarden.com/ Hudson Rock Blog Post: underthebreach.medium.com/infostealer-credentials-compromise-passw...
Faster Logins with Passkeys | Bitwarden Passkey Tutorial
Переглядів 30 тис.Рік тому
Bitwarden finally supports passkeys! It's available for all Bitwarden accounts, including their free version. Bitwarden's synchronized passkey feature allows you to use passkey across multiple devices. Take action now to set up your FIDO2 WebAuthN passkeys today! 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links Bitwarden: bitwarden.com/ Bitwarden Tutorial: u...
1Password Passkey Tutorial | How to Use Passkeys in 1Password
Переглядів 26 тис.Рік тому
1Password just dropped a huge update! They are one of the first password managers to support managing passkeys. This allows you to use passkeys on multiple devices. You'll never get caught without it again. Take action now to set up your FIDO2 WebAuthN passkeys today! 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links 1Password: 1password.com/ 1Password Tutori...
Proton Pass Tutorial | Is it Worth Switching Your Password Manager?
Переглядів 56 тис.Рік тому
Download Proton Pass Today: go.getproton.me/SHkz There is one killer feature in Proton Pass, but how does the full solution stack up against competitors like Bitwarden and 1Password. Proton Pass is a relatively new player in the password manager space. Branching out from its core products (Proton Mail and Proton VPN), it's jumping into the identity protection game...yes, the identity protection...
The Easiest (and MOST SECURE) Way to Log into Bitwarden
Переглядів 38 тис.Рік тому
Bitwarden is winning the security game against other password managers. They recently updated their security settings to allow anyone (paid or free) to implement FIDO2 WebAuthn as 2FA. This makes it easier to log in AND more secure. Update your settings today! 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links Bitwarden: bitwarden.com/ Passkeys Overview: ua-ca...
Is Passbolt The Best Password Manager For Teams? | Passbolt Deep Dive
Переглядів 3,4 тис.Рік тому
Is Passbolt The Best Password Manager For Teams? | Passbolt Deep Dive
Secure Your Google Account Like a Security Pro
Переглядів 12 тис.Рік тому
Secure Your Google Account Like a Security Pro
1Password Tutorial | The Full Beginners Guide
Переглядів 112 тис.Рік тому
1Password Tutorial | The Full Beginners Guide
WormGPT - A Hacker's New Best Friend?
Переглядів 1,5 тис.Рік тому
WormGPT - A Hacker's New Best Friend?
The Most Important Bitwarden Setting You Never Heard Of
Переглядів 64 тис.Рік тому
The Most Important Bitwarden Setting You Never Heard Of
Google Passkeys Tutorial | Step by Step Guide to Set Up Google Passkeys
Переглядів 71 тис.Рік тому
Google Passkeys Tutorial | Step by Step Guide to Set Up Google Passkeys
What are Passkeys? | Are Passwords Dead? | A Security Expert Explains
Переглядів 29 тис.Рік тому
What are Passkeys? | Are Passwords Dead? | A Security Expert Explains
Bitwarden Tutorial | The Full Beginners Guide
Переглядів 171 тис.Рік тому
Bitwarden Tutorial | The Full Beginners Guide
Hackers Join Reddit API Protesters
Переглядів 623Рік тому
Hackers Join Reddit API Protesters
Don't Fall For This Bitcoin Phishing Scam
Переглядів 531Рік тому
Don't Fall For This Bitcoin Phishing Scam
I’m Never Using An Offline Password Manager Again
Переглядів 9 тис.Рік тому
I’m Never Using An Offline Password Manager Again
Is MFA Still Safe? | How Hackers Bypass MFA
Переглядів 7 тис.Рік тому
Is MFA Still Safe? | How Hackers Bypass MFA
Why Cyber Security Awareness Fails | #security #securitytraining
Переглядів 847Рік тому
Why Cyber Security Awareness Fails | #security #securitytraining
The Best Way To Run Windows Programs On Your Mac
Переглядів 10 тис.Рік тому
The Best Way To Run Windows Programs On Your Mac
Bitwarden Passwords At Risk? | A Security Expert Explains
Переглядів 40 тис.Рік тому
Bitwarden Passwords At Risk? | A Security Expert Explains
Lockheed Martin Cyber Kill Chain | The Defender's Mini Playbook
Переглядів 704Рік тому
Lockheed Martin Cyber Kill Chain | The Defender's Mini Playbook
Security Experts Know This About VPNs
Переглядів 941Рік тому
Security Experts Know This About VPNs
DDOS Attack Explained
Переглядів 475Рік тому
DDOS Attack Explained
Coinbase Hacked | A CISO Explains How
Переглядів 1,3 тис.Рік тому
Coinbase Hacked | A CISO Explains How
What is a Business Email Compromise Attack | A Security Expert Explains
Переглядів 1,5 тис.Рік тому
What is a Business Email Compromise Attack | A Security Expert Explains
35,000 Paypal Accounts Hacked: How to Protect Yourself | How Credential Stuffing Attacks Occur
Переглядів 8 тис.Рік тому
35,000 Paypal Accounts Hacked: How to Protect Yourself | How Credential Stuffing Attacks Occur
The Perfect Cyber Security Resume
Переглядів 1,4 тис.Рік тому
The Perfect Cyber Security Resume

КОМЕНТАРІ

  • @willyw9732
    @willyw9732 2 дні тому

    Thank you for the video. I'm thinking about switching my password manager to Bitwarden PM. However, I have read that bitwarden auto password fill is unsecured. How true is that, or how accurate is it? Thanks

    • @teachmecyber
      @teachmecyber 2 дні тому

      There was an old issue with bitwarden where the autofill could be tricked (I have a video on it). That has been fixed so it's no longer a problem!

    • @willyw9732
      @willyw9732 2 дні тому

      @@teachmecyber Thanks for the reply. Could you please point out the video you mentioned.Thanks

    • @teachmecyber
      @teachmecyber 2 дні тому

      @willyw9732 ua-cam.com/video/T46w0riVyc8/v-deo.html

  • @walkthedogs240
    @walkthedogs240 3 дні тому

    It should probably be noted that the Bitwarden mobile app now supports Passkeys, at least in iOS, as well as passkey cloning (as discussed in this video).

    • @teachmecyber
      @teachmecyber 2 дні тому

      Bitwarden has been releasing some great features!

  • @unggoysolid4363
    @unggoysolid4363 4 дні тому

    this google feature is STUPID.. sorry

    • @teachmecyber
      @teachmecyber 2 дні тому

      Why is it stupid?

    • @unggoysolid4363
      @unggoysolid4363 2 дні тому

      @@teachmecyber aw sorry! am just mad, i will delete this if u like, but menn.. to us people who just watch yt in a small amount of time or using it to track people we subscribe and creat playlist for rewatch, this "Security" feature is TOO MUCH, for anything else must be right, but why put personal stuff in the internet? sorry men, doest ment to drop this i apologize.. Good luck in the channel, more power and Godbless

    • @teachmecyber
      @teachmecyber День тому

      @unggoysolid4363 I get it, it's not a feature for everyone but it does make logging into google more secure and faster

  • @Encentix
    @Encentix 4 дні тому

    Happened to me due to a Trojan. Paypal was not avalable during christmas so I had to wait 4 days to get a hold of them to report it! my email was changed, password and security questions too so they basically locked me out. I got it back now after finally getting through the hotline but the very little options they leave you if you are locked out is terrifying! They do save your register data so they can still undo a hack if you tell them about your account and the data you have such as email, phone number etc. So don't slack off and always keep these up to date and the more 2FA the better. NEVER SAVE PASSWORDS ON YOUR BROWSER! And any download you do on websites that seem a bit shady should only be done on virtual machines. I do a daily virus scan now and also back up your PC and files. If i didn't my art stuff would all be gone with this Trojan nightmare I endured this Christmas. Don't ever be lazy with your internet security and also know that you are not immune to cyber attacks! My family sees me as the most tech savvy person but I still got hacked via a Virus. Money they drained is also still in Limbo. They used a throwaway Email service to not get reported as the Paypal worker explained and the way they stole is via a "Authorization Payment" Wich is a big problem as these cannot be set to be investigated by paypal like other transfers. They did it on purpose so I can't defend myself most likely. A huge oversight and loophole with Paypal they need to fix! Cause hackers probably use this to prevent you from cancelling that illegal theft of your money. The transfer is also sent to what seems like a legit US business. But I am not american, do not live there and my listed adress is some abandoned house in the US. I let the company that is the recipient know of this. And Paypal does know of the hack also and the time the transaction was done in my name. So I am hopeful that they will get me my money back or have that transfer cancelled. Hopefully. It does frustrate me though. Paypal did not ask me for 2fa on chrome and since i saved my password (wich i don't do now after fixing everything to make it safe again) So there was no way for them to hit a wall when they could access my pc. Literally less important accounts ask you for 2fa every time you log in. so why not paypal? It feels like an insane choice especially when they know that this is a risk for ppl with virus infections hence why 2fa exists. If you have struggled with a hack on paypal or worry please listen, Do not give up! Try to access paypal's customer service. Have your registration data ready (they keep this so hackers cannot change these as it is on paypal's end not yours.) always enable all 2fa's avalable be that face Id, finger print and phones. maybe even more backup devices if you can. Also keep your ID ready too but do make sure the number is legit. do cross reference and check for the correct website url. Never use email links always go to paypal manually after you get an email. And also do not lie down and take it. Sue paypal if you can afford to and they didn't help enough. Hold them accountable. Finance services cannot afford to be this easy to breach. Especially with linked bank details. You have 180 days to report a illegal payment you did not make. So remember that too. Especially if it says that in the transaction email or the transaction info. Another important thing! CHECK YOUR ARCHIVED TRANSFERS BY FILTERING ARCHIVED TRANSACTIONS!!! They hid mine in archived transfers. I knew this was a thing so I unarchived it to make it visible. Please be safe and please do not let these pathetic greedy worms take from you without a serious fight! You deserve to not be stolen from! remember that always!

  • @fabio.lor.
    @fabio.lor. 4 дні тому

    How to use mail fowarding with Gmail?

  • @Duducatalin
    @Duducatalin 5 днів тому

    i like skulls

  • @HaleematAbdullahi
    @HaleematAbdullahi 5 днів тому

    Nice innovation

  • @MyLadybug57
    @MyLadybug57 6 днів тому

    How do I know if account has be hacked or a glitch

  • @yt.grahame.martin
    @yt.grahame.martin 8 днів тому

    Very, very good. Unlike most you produced a video that gave clear directions towards setting the different Apps up. This can be very confusing, in my opinion at least. And I am by no means a beginner in the online world. By the time the video is over we are also relatively familiar with the interface and feeling more at home with 1Password. Also, what really annoys me, is that in most cases it comes across strongly that the only objective of the videos that most creators make is to hopefully make money. As their speaking at 100 mile an hour and it seems like they just want to get it over with. It feels that that’s not the case with you Jason and you really want to make the process clearly understood. That that is your main objective. Anyway, without watching your video I know I would have struggled to set it all up. Thanks for that. I can’t wait for 1Password 2 - Rebholz Reloaded Cheers Mate

  • @kaara-chan
    @kaara-chan 9 днів тому

    I mean does it matter? Most password managers won't login the account unless it passes MFA. So if anything, it's a sign to change the master password.

  • @umeshranasinghe
    @umeshranasinghe 16 днів тому

    Thanks for this great video.

  • @silvieb2024
    @silvieb2024 16 днів тому

    You really want me to trust Google with my passkeys???

  • @colinbluth5461
    @colinbluth5461 17 днів тому

    thank you for the tutorial

  • @UsmanaUmar-n9z
    @UsmanaUmar-n9z 17 днів тому

    Good innovation

  • @UsmanaUmar-n9z
    @UsmanaUmar-n9z 17 днів тому

    Good

  • @user-di3oq7fb7i
    @user-di3oq7fb7i 22 дні тому

    This is actually a Tutorial. THANKS

  • @dreamer6471
    @dreamer6471 22 дні тому

    Sir, can i have a full structure for Cyber security Analyst or Network Architecture.

  • @dreamer6471
    @dreamer6471 22 дні тому

    Thank you, Sir.

  • @Arg0n_
    @Arg0n_ 22 дні тому

    I like how you blur the email address in the email address field, but the email address is still in the url :D

  • @daphney_hey3142
    @daphney_hey3142 23 дні тому

    Thank you so much ,you explain it so well and clear

  • @Lyle-In-NO
    @Lyle-In-NO 23 дні тому

    I have to say, this video is absolutely awesome. The terms & methods are clearly explained AND you provide the technical terms/names I'll need to learn if I want gain a deeper understanding. You've definitely gained one more fan & sub!

  • @rickrounds5150
    @rickrounds5150 26 днів тому

    Too confusing.

  • @MelodyReed-i7i
    @MelodyReed-i7i 26 днів тому

    I need a passkey to do a two-step verification for a specific company company for pre on boarding and it keeps saying I don't have a passkey for this specific company HELP

  • @michaelkalman6912
    @michaelkalman6912 27 днів тому

    So poorly done for a so-called "beginner". What's a hardware key? What does MFA mean?

  • @hajomi12
    @hajomi12 28 днів тому

    It really helps to know more about domain

  • @valeriethompson6031
    @valeriethompson6031 29 днів тому

    My husband account was hacked

  • @outkst012l
    @outkst012l Місяць тому

    If I use WebAuthN, is it ok to stop using the 2FA or do you recommend using both? My only gripe is in case I lose/damage my device, that has authenticator app set up for 2FA, having to use the recovery key is bit worrisome.

  • @darin.nancymathews635
    @darin.nancymathews635 Місяць тому

    My Passkey page has a large yellow shield at the top of the page stating "A Passkey cannot be created on this Device". Otherwise, it looks like your. Any idea what would cause this?

  • @bob-p7x6j
    @bob-p7x6j Місяць тому

    You said "using an online password manager, is still better than not using one", so, are you saying that a password manager is safer than writing my passwords down on paper and putting them in manually? Don't really know which way is safer, obviously doing it manually takes longer.....But these aren't accounts I need every day or all at once...

  • @bob-p7x6j
    @bob-p7x6j Місяць тому

    Thanks for the tutorial! So, does that mean if we don't add the security features that you did in the beginning that Bitwarden is unsafe to use?

  • @TRD_Mike
    @TRD_Mike Місяць тому

    Great explanation, thank you!

  • @BitfarmLimited
    @BitfarmLimited Місяць тому

    Fantastic

  • @soniaandre4568
    @soniaandre4568 Місяць тому

    How about for IPhone?

  • @aikhanam2
    @aikhanam2 Місяць тому

    Its not letting me set up bitwarden authenticator app, or google one, so I have set up the email option for 2 step authentication.

  • @donsaelzler9255
    @donsaelzler9255 Місяць тому

    Thanks for the effort it surely takes to make this video. However, the something I wanted to understand but it does not seem to be discussed. In the event I shut my computer down, or reboot (chromebook) I must provide my chromebook logon. I can manage to remember ONE goofy set of letters and numbers. But the ONE THING I could not seem to learn from the tutorial, or the comments was ... What is the procedure after a reboot or shutdown? MUST I TYPE IN the cumbersome secret key and the cumbersome password (some crazy thing like 1lI0O.z$yY ) before beginning my day of surfing to my favorite websites? OH wait... TWO THINGS NOT DISCUSSED... sometimes accounts have a pin number (Personal Identification Number) or questions like what is your dog's name. Is there any way to keep track of that info?

  • @kryssalon2731
    @kryssalon2731 Місяць тому

    I've watched four videos on 1 Password. None has shown me how I use this app when I am actually trying to input a password on a website.

  • @lotsa2000
    @lotsa2000 Місяць тому

    You look excited, I'm more disheartened. Here's why: I've been diving deep into security these days and the more I look, the more scared I am to start using it because 1) it's hard and 2) I may lock myself out forever. At this point, risk(ignorance/making a mistake) > risk(hacker getting my password). I want to get where you are, but I can't as long as I don't have a holistic, easy-to-understand, fool-proof way of doing personal security. Simple, one-off videos here and there doesn't get me where I need to be. There are so many pieces and I get more and more overwhelmed. I started using 2FA and passkeys. But am I at risk of getting locked out of my Google account? This account? That account? Maybe I had a bad day and didn't follow the correct steps when I added one of my accounts? Oh, and there's my family. They're adding accounts in there, too. I don't want to have to be 100% perfect 100% of the time. At least with a password, as long as my password manager remembers it, I can get in. And if I lose all of my passwords, there's the password reset feature. Do you feel me? I want to use these security measures AND be confident using them. Thank you for listening. I've been banging my head at this stuff for a couple of weeks now and even bought a security course and am scared to move on to the next session without implementing the best practices, but to do that, I have to 1) pick an authenticator app 2) back up the codes 3) 2FA my bitwarden account 4) not mess that up 5) have a sane workflow 6) have A workflow... It seems endless...

  • @christinenibblettrealtor-k8056
    @christinenibblettrealtor-k8056 Місяць тому

    great tutorial! Thank you

  • @globalfamilyyoga
    @globalfamilyyoga Місяць тому

    I don't need to do that 2-step authentication (about 4 min in) if I have a premium account?

  • @DannySi
    @DannySi Місяць тому

    Wish it would at least have some indicator that a passkey is associated with a login. Great feature regardless.

  • @salsuginusrex5196
    @salsuginusrex5196 Місяць тому

    Great help! Liked and Subscribed. Gotta upgrade my very very dated cybersecurity knowledge/practice.

  • @nazzarenopisano652
    @nazzarenopisano652 Місяць тому

    I understand having a backup method in case you lose your device, or your yubikey. However, couldn't a hacker also say "I lost my device", etc and use the "less secure" MFA?

  • @honnorjustice
    @honnorjustice Місяць тому

    I'm confused! Not computer savvy, sorry. So I set up my email and pass account. I entered a a name of a company that i normally shop at. Do I have to go and change my email address with the company to use my pass email instead of my actual email?

  • @user-bh1pg3ey5k
    @user-bh1pg3ey5k Місяць тому

    At end of day tho u still have to write down ur password somewere tho

  • @smartdecoder
    @smartdecoder Місяць тому

    Thanks for explaining ☺️

  • @daveschmidtlein8933
    @daveschmidtlein8933 Місяць тому

    Excellent work, very well done. Older folks who were "introduced" to computers and our tech world half-way into our lives, really appreciate step-by-step tutorials. Bless you my friend!

  • @pichupich3941
    @pichupich3941 Місяць тому

    Great advice, thanks.

  • @marta41553
    @marta41553 Місяць тому

    I just got hacked with all my Etherum. who can help me fine were it went.i might never get it back. but they must be stop.. any one advice plz

  • @goodvalueservices-ys4kg
    @goodvalueservices-ys4kg Місяць тому

    How do you create a new password store for mobile apps?

  • @davesmith9188
    @davesmith9188 Місяць тому

    My phone did not ask for a fingerprint or facial recognization. I think it did not set up right.