Blog

Posted April 10, 2019

New: MX Logging

Share:

LinkedIn Icon

New: MX Logging

We’ve recently updated Rawstream Network Security to collect and report DNS MX requests. This matters because it can help organisations detect potential security breaches.

Mail Exchanges

DNS is the internet’s telephone directory. When you to browse to example.com, the browser looks up “example.com” against DNS servers, and the DNS server returns the address of example.com in a format that a browser can use to display the requested page. These requests are called A record DNS queries because the browser requests a page’s address.

However, there are different types of resources that are available over the internet. A highly requested resource is email. To send an email, your mail server needs to know the address of the server handling the receipient’s email. These DNS queries are MX (“mail exchanger”) requests.

In a most organisations, staff use the organisation’s mail service to send out email. There are good reasons for centralising email handling:
1.enforcing standards like templates and attachment sizes
2.archiving email for complaince purposes
3.scanning email for security threats

There are very few good reasons why email should not be sent via the central mail server. Indeed, MX requests from individual machines is highly unusual.

You’ve Sent Mail

Individual machines trying to contact MX servers directly usually indicates a security issue. Malware on the machine may be trying to send phishing email to external victims, sending email spam, or acting in concert with other infected machines as part of a DDOS attack.

The new Rawstream reporting helps identify suspicious MX DNS requests. The report shows the looked up domains, the number of lookups for that domain, the domain’s category, and the country where the domain is hosted.

The above screenshot shows a sample report for a Google Suite hosted mail server (google.co.uk) which receives the vast bulk of lookups, as well as two potentially suspicious lookups. One is for Hotmail, the second is for a China hosted mail server. Depending on your organisation’s communication patterns, these lookups may warrant further investigation.

About Rawstream Network Security

Rawstream Network Security is the fastest DNS filtering in the cloud, with intuitive user interface, real-time reporting and zero log retention limits. You can sign up for a free trial, or learn more here.

About Author

By Rawpress

Share:

LinkedIn Icon

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nunc sagittis porttitor felis sit amet vitae elit fermentum. Quisque vitae elit orci. Proin at mi efficitur, venenatis massa sed, porta nisi. In lobortis est et velit vehicula, nec dictum. Proin at mi efficitur...

Agent

Track Desktop Applications

Content filtering products limit themselves to reporting websites browsed....

April 9, 2021
By Rawpress
End-Point

Product Name Update

The Rawstream Web Filtering agent provides web security and filtering on end-point...

April 15, 2019
By Rawpress
DNS

Blocking Zoom

Rawstream Network Security is a powerful DNS-based filter for network-wide security...

April 15, 2020
By Rawpress