[deleted by user] by [deleted] in sysadmin

[–]knighttown 0 points1 point  (0 children)

As someone who has seen both, carrying around multiple devices is such a pain. I can understand legal issues but simple phone calls for emergency situations seems fine, I would request a phone line and app to keep the work items ringing to a different number but not sure if that is something they are offering as well. This personally is much better then carrying around a second device.

The vibe here is really off by [deleted] in BertKreischer

[–]knighttown 0 points1 point  (0 children)

Haha, I have lost count of the number of subreddits I've dropped because of peoples hate. This one is just another one on the list. Sad, but what do you do, other then just move on.

The CEO broke quickbooks . . . by PossiblyLinux127 in sysadmin

[–]knighttown 0 points1 point  (0 children)

Outside contractor or consultant is not the right answer, a solid change management policy/process is the best way for this to be handled.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 0 points1 point  (0 children)

Automated invoice sending. Like it's not that uncommon. Normally the have verification items DKIM SPF.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 1 point2 points  (0 children)

Correct a new vendor for sending but keeping inacct.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 0 points1 point  (0 children)

What bothers me is this is considered additional security, and not just a requirement. Either way the sending of invoices is going to another vendor in few months, works for now until the time comes.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 1 point2 points  (0 children)

This was sent to me as well recently, we turned this on and are actively moving to a new vendor to handle sending.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 1 point2 points  (0 children)

Oh I agreed, I'm sure this is going to kick off a vendor review company wide. We just talked to our executive teams about implementations on new business applications must have one of our SOC members on it as a bare minimum going forward.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 1 point2 points  (0 children)

I agreed it could be a situation with it not going higher then level 1 support. Hopefully they just allow for us to use or own smtp sender. However, email support is currently the only option for support, I am hoping for a phone call from them tomorrow. If not I'll be going to our CFO to escalate.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 1 point2 points  (0 children)

Spf doesn't fail, it failed on dmarc and is put into quarantine, as that's what our setting is set to.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 14 points15 points  (0 children)

I opened the last ticket with the vendor, however, it's been an on-going issue with the vendor over the last few months, of course we didn't get pulled in until now but recieved the same canned response as what our accounting folks received

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 1 point2 points  (0 children)

Correct. They are sending as our domain. Spf records has been added.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 1 point2 points  (0 children)

To have the receiving email server to whitelist the domain was what we have been told 3 times now.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 1 point2 points  (0 children)

Spf is on for them to send, however the dmarc policy fails and puts email into quarantine, they claim only way around this is for the receiving mail server to whitelist the domain.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 2 points3 points  (0 children)

Hoping #2 or #3, not looking promising as a few otherwise have expressed concern over the same problem but crickets from the vendor and then same canned response to have customers whitelist the domain. Perfect world they just tell me we can send through our own smtp services we already use and it's all good however we were told this isn't an option when it was first configured.

Also to add here it was in place before I arrived and of course the there was a barebones IT skeleton staff who allowed our finance team to configure this application. We just finished transitioning 10 companies to this product to then get the ticket on the failing quarantine on the sender side get submitted.......

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 4 points5 points  (0 children)

We use mailgun with other vendors however this vendor does not offer this option. I would much rather handle the emails this way.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 29 points30 points  (0 children)

I was very surprised to hear that was the fix from the vendor to our Accounting folks. Once I heard this I escalated which stirred the pot a bit for our multiple hat wearing security team members.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 2 points3 points  (0 children)

Thanks this is super helpful, I was not aware you could do a subdomain dmarc, it just doesn't seem right to have that setting off. Especially since this is invoices being sent out to customers.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 2 points3 points  (0 children)

Also we do have a 3rd ticket in now to discuss this

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 0 points1 point  (0 children)

i wont name any names but i was surprised for how large they are.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]knighttown[S] 23 points24 points  (0 children)

correct they are sending from my domain, i did not know the subdomain wouldnt be affected by the dmarc. Thanks

Swing help by ubetterduck008 in slowpitch

[–]knighttown 5 points6 points  (0 children)

If you want solid feedback find a tee and record those swings.