Sign in or Register
Listing cover image

eMail Spoofing Test

80% of attacks start via E-Mail. Let us test your e-Mail spoofing detection.

  • Monitoring
    249 € / quarterly
  • Single Test
    349 €
  • Activity
  • prev
  • next
  • Your effort: 15 min
  • Extensions possible
  • Request Quote & Start
  • prev
  • next
Steps

E-Mail is the most common attack path for hackers and CEO Fraud. It is of paramount importance to test & improve your spoofing detection. We test your security from an independent perspective and provide a roadmap of actionable recommendations to harden your spoofing detection.

💡 Recommendation

To perform our E-Mail spoofing test, clients typically provide us with two test E-Mail inboxes and access to the mailboxes via remote access (e.g. TeamViewer, WebMail) or POP3.

Step 1

Order

Just order this module and we will immediately start to test the spoofing detection of your E-Mail system.

Test Inbox (optional): You can provide us E-Mail inbox for our testing. Otherwise we can use your personal Business E-Mail.

Step 2

Spoofing Test

We will send about 60 spoofed eMails to your inbox. The senders will be tailored to your business enironment (e.g. spoofing of bank or partner identity).

Tailored: Our tests are personalized for you. Instead of using generic templates, we imitate relevant senders (e.g., local banks, business partners, or even your own domain). This ensures maximum practical relevance and actionable result

In-Depth-Analysis: Afterward, you can evaluate which emails were delivered, quarantined, or flagged as potentially dangerous. You can then analyze the specific reasons (SPF/DKIM/DMARC, content scoring, filter rules, gateway policies, etc

Hint: Please do not delete the E-Mails. Keep them as they are for follow-up.

Step 3

Report & Closing meeting

We will present you the results in an closing meeting. You will receive a management summary and the spoofing protocols with concrete eMail IDs.

Step 4

Repeat (recommended)

E-Mail threats are fast evolving. We recommend to repeat this test quarterly and adapt the scope to stay up to date.

Request Your Custom Assessment

    Sheet
    • Category
      Security Test
    • Your internal effort (~)
      15 min
    • Duration
      2 days
    • Compliance & Accountability relevant?
      ✅
    • Applicable to/at

      All public institutions & industries of any size

    • EUSEC®-Module

      EUSEC®-eMail-Spoofing-26A

    Details
    • Key Outcomes & Deliverables
    • Scope / Out-Of-Scope

    Key Outcomes (What you achieve)

    • Independent Validation: Your eMail spoofing detection is objectively assessed by top-tier experts.
    • Risk Reduction: Critical vulnerabilities are known and eliminated, significantly reducing your Cloud Security risks.
    • Improvement Started: Your company is empowered to implement effective Spoofproof Security measures to detect, withstand, and recover from spoofing attacks.

    Deliverables (What you receive)

    • Traceable Evidence: Comprehensive documentation of your technical and organizational measures (TOMs) for eMail Spoofing
    • Spoofing Protocol: You will receive a detailed shipping log in an Office spreadsheet format (e.g., Excel/CSV) for seamless further processing and analysis

    In-Scope

    • Closing Meeting: 1-hour
    • 60 spoofed emails tailored to your requirements
    • Diverse Sender Identities: Utilization of various senders and identities to test a wide range of spoofing scenarios.
    • Tailoring test cases to your business environment (e.g. spoofing of specific senders)
    • High Variance: Variation of attachments, keywords, content, and links to accurately represent realistic threat patterns.
    • Spoofing Protocol: You will receive a detailed shipping log in an Office spreadsheet format (e.g., Excel/CSV) for seamless further processing and analysis

    Out-of-Scope

    • Comprehensive PDF Report
    • Create Tickets in your ticket management system (e.g. JIRA), instead of list / report based documentation (optional)
    • Onsite or observed testing (e.g. via online conference tools and screen sharing) is costly and offered optional.
    • Additional effort if your company can not provide remote access to test inboxes (e.g. additional software required).
    • Group/Corporate Entities: Corporate groups or companies with multiple subsidiaries may require a separate package for each (legal) entity.
    • Implementation of corrective actions.
    • General exclusion: Everything else not explicitly mentioned as In-Scope is strictly Out-of-Scope.
    • Imprint
    • Data Privacy

    Basket