Best practices, Dobre praktyki, Transactional Emails
Best practices, Dobre praktyki, Transactional Emails
mBank was the first bank in our country to declare war on cybercriminals’ activities and implement sender authentication in the most popular mailboxes used by their customers.
These solutions help visually distinguish genuine from forged correspondence. Both Polish (including Interia, Onet, WP/O2) and global (including Gmail) mail providers enable advanced sender authentication solutions.
Having these verified email address badges, which are visible in most popular email clients, means the message has been digitally signed using a certain security protocol, called S/MIME to be more precise.
Their proper implementation is rewarded by displaying distinctive graphics (a green shield), or the brand’s logo, next to the sender’s name in the mailbox and inside each authenticated email. This type of verification also has an impact on the brand’s reputation and message deliverability, preventing emails from ending up in spam.
” The additional security implemented by mBank as part of the fight against phishing allows message recipients to verify whether the email actually comes from this particular bank. Added safeguard, which appears in the form of graphics, is certainly a great convenience for ordinary users, thanks to which they can more easily distinguish a malicious message from a legitimate one. One should keep in mind, however, that every security measure will sooner or later be broken/dominated by cybercriminals, which is why it’s so important to constantly improve our systems and make sure they have the ‘latest’ safety features.”
Michał Błaszczak, Pentester at EmailLabs
CyberLabs #1- Phishing being one of the most popular cyber threats
The mBank Group is using Emailabs to handle transaction emails sent to users of Paynow payment gateway. The CTO of mElements (From the mBank Group) shared his comments on the changes brought by the implementation of Email API:
“We chose Emailabs, i.a. due to our customers’ data security,” Sebastian Sztajnert said at the time.
Today mBank goes further by launching the latest available sender authentication solutions. Characters or graphic elements allow users to easily verify the validity of communications received in most popular mobile applications or browser versions (they will not be available for Thunderbird or Outlook users).
How did we achieve the highest level of security for data storage servers? Read mElement and EmailLabs’ Case Study.
Mailbox providers require senders to have basic authentication like SPF and DKIM, without which messages will not reach users. However, besides the general solutions available to all, senders are offered access to premium features.
In the first step, sender checks ISPs’ structure in his contact list. If the vast majority of them use: WP, O2, Interia, Onet, Gmail, Yahoo, in each case these providers’ mailboxes can be configured for additional sender security.
Have you noticed that next to some email senders on your inbox you can see the badge of a verified email address?
WP, O2 have a Trusted Sender standard, Onet has a Verified Sender service, Interia gives you the option to run a Safe Sender and have the logo appear in your inbox.
You’ll see a green padlock icon and a notification in the message from the Safe Sender.
Gmail as well as Yahoo, and also Onet Mail recently, while by honoring the BIMI solution, with verified senders they display both on the mail listing and in the emails itself, notarized brand logos.
mBank communication secured by the BIMI standard.
The mailbox providers are responsible for the sender’s technical authentication settings. By verifying their email communication activities, they have the right to reject enabling the service if these practices raise any concerns. Most additional solutions also come at an extra cost and require a series of steps. To facilitate these steps, you can use EmailLabs – all of them are available in a single agreement.
Authenticated senders like Verified Sender, Safe Sender, BIMI or S/MIME are proven solutions for the most recognizable brands, especially those operating in the banking, fintech, courier services, e-commerce, retail or advertising industries.
Email Authentication, Security
DMARC is an email authentication protocol that is designed to give domain owners the ability to protect their domain from unauthorized use, commonly known as email spoofing. Spoofing occurs...
Cybercriminals are thriving in their attacks, using communication channels such as sms, push and email. Day by day, attacks aimed at obtaining sensitive information related to these channels are...
The Council of Ministers, Republic of Poland, has adopted the draft of the Act on combating abuses in electronic communication. Proposed solutions should combat the most popular forms of...
With the emergence of the Covid-19 pandemic, many brands have been challenged to adapt in a short period to the changed reality and new consumer attitudes. That meant reorganizing...
How Apple Mail privacy updates affect email open rates? Although the new privacy policy for Apple users was already introduced in September 2021 (with the launch of iOS 15...
Google has announced the release of a new feature to help users differentiate messages from verified senders from those trying to impersonate them. Google Workspace users and Gmail owners...
Although the term “return path” might seem self-explanatory, many companies aren’t familiar with the process it denotes. Simply put, the return path is a hidden header that indicates where the...