Jason Rebholz - TeachMeCyber
Jason Rebholz - TeachMeCyber
  • 66
  • 762 491
What is SPF, DKIM, DMARC, and BIMI | Easy Explanations
Attackers want to spoof your email domain to sending phishing emails. If you don't take the right steps to secure your email and domain authentication, you are putting your organization at risk. Plus, major email providers, like Google, and new PCI-DSS require stronger controls.
In this video, we'll cover key email authentication protocols like:
- SPF (Sender Policy Framework)
- DKIM (DomainKeys Identified Mail)
- DMARC (Domain-based Message Authentication and Conformance)
- BIMI (Brand Indicator for Message Identification)
- MTA-STS (Mail Transfer Agent Strict Transport Security)
- TLS-RPT (TLS Reporting)
Get the latest in cyber security with my weekly newsletter: weekendbyte.teachmecyber.com
❤️ Leave a comment and hit the like button because it helps spread cyber security knowledge to more people.
Table of Contents
00:00 - Intro
00:30 - What is SPF (Sender Policy Framework)?
01:18 - What is DKIM (DomainKeys Identified Mail)?
02:33 - What is DMARC (Domain-based Message Authentication and Conformance)?
04:01 - What is BIMI (Brand Indicator for Message Identification)?
05:08 - What is MTA-STS (Mail Transfer Agent Strict Transport Security)?
06:14 - What is TLS-RPT (TLS Reporting)?
06:55 - Check out PowerDMARC
🔔If you found this helpful, subscribe to the channel!
www.youtube.com/@teachmecyber?sub_confirmation=1
🚀 Connect with me on LinkedIn
www.linkedin.com/in/jrebholz
มุมมอง: 4 692

วีดีโอ

The Fastest (AND EASIEST) Email Security | Configure Email and Domain Authentication with PowerDMARC
มุมมอง 1.7K9 หลายเดือนก่อน
Get started with PowerDMARC today: Sign up: app.powerdmarc.com/en/members/register Homepage: powerdmarc.com Overview: Attackers want to spoof your email domain to sending phishing emails. If you don't take the right steps to secure your email and domain authentication, you are putting your organization at risk. Plus, major email providers, like Google, and new PCI-DSS require stronger controls....
Best VPNs in 2024 | Do You Need a VPN?
มุมมอง 1.5K10 หลายเดือนก่อน
As a security expert, I'm often asked whether you need a VPN and which ones are the best. In this video, I'll explain how a VPN works, the key use cases for VPNs (and whether you should use one), and discuss the top five VPNs on the market right now. 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links VPN Providers NordVPN: go.nordvpn.net/aff_c?offer_id=15&aff_...
Hackers Targeting Bitwarden Vaults | Easy Steps to Protect Your Passwords
มุมมอง 23K11 หลายเดือนก่อน
Hackers are targeting Bitwarden password vaults and selling them on the dark web. You can protect your account with these easy steps. Take action now to set up your FIDO2 WebAuthN passkeys today! 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links Bitwarden: bitwarden.com/ Hudson Rock Blog Post: underthebreach.medium.com/infostealer-credentials-compromise-passw...
Faster Logins with Passkeys | Bitwarden Passkey Tutorial
มุมมอง 29K11 หลายเดือนก่อน
Bitwarden finally supports passkeys! It's available for all Bitwarden accounts, including their free version. Bitwarden's synchronized passkey feature allows you to use passkey across multiple devices. Take action now to set up your FIDO2 WebAuthN passkeys today! 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links Bitwarden: bitwarden.com/ Bitwarden Tutorial: t...
1Password Passkey Tutorial | How to Use Passkeys in 1Password
มุมมอง 25Kปีที่แล้ว
1Password just dropped a huge update! They are one of the first password managers to support managing passkeys. This allows you to use passkeys on multiple devices. You'll never get caught without it again. Take action now to set up your FIDO2 WebAuthN passkeys today! 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links 1Password: 1password.com/ 1Password Tutori...
Proton Pass Tutorial | Is it Worth Switching Your Password Manager?
มุมมอง 52Kปีที่แล้ว
Download Proton Pass Today: go.getproton.me/SHkz There is one killer feature in Proton Pass, but how does the full solution stack up against competitors like Bitwarden and 1Password. Proton Pass is a relatively new player in the password manager space. Branching out from its core products (Proton Mail and Proton VPN), it's jumping into the identity protection game...yes, the identity protection...
The Easiest (and MOST SECURE) Way to Log into Bitwarden
มุมมอง 36Kปีที่แล้ว
Bitwarden is winning the security game against other password managers. They recently updated their security settings to allow anyone (paid or free) to implement FIDO2 WebAuthn as 2FA. This makes it easier to log in AND more secure. Update your settings today! 📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/ Links Bitwarden: bitwarden.com/ Passkeys Overview: th-ca...
Is Passbolt The Best Password Manager For Teams? | Passbolt Deep Dive
มุมมอง 3.2Kปีที่แล้ว
Get started with Passbolt today! www.passbolt.com/ Enjoy a 20% discount for Passbolt Pro or Cloud using the code: JASON-REBHOLZ Huge thanks to Passbolt for sponsoring this video! Passbolt is a popular open-source password manager for teams. With a security-first mindset, they are transparent about almost everything. They publish their security audits (they completed 10 in the last 24 months). T...
Secure Your Google Account Like a Security Pro
มุมมอง 10Kปีที่แล้ว
Secure Your Google Account Like a Security Pro
1Password Tutorial | The Full Beginners Guide
มุมมอง 107Kปีที่แล้ว
1Password Tutorial | The Full Beginners Guide
WormGPT - A Hacker's New Best Friend?
มุมมอง 1.4Kปีที่แล้ว
WormGPT - A Hacker's New Best Friend?
The Most Important Bitwarden Setting You Never Heard Of
มุมมอง 60Kปีที่แล้ว
The Most Important Bitwarden Setting You Never Heard Of
Google Passkeys Tutorial | Step by Step Guide to Set Up Google Passkeys
มุมมอง 61Kปีที่แล้ว
Google Passkeys Tutorial | Step by Step Guide to Set Up Google Passkeys
What are Passkeys? | Are Passwords Dead? | A Security Expert Explains
มุมมอง 28Kปีที่แล้ว
What are Passkeys? | Are Passwords Dead? | A Security Expert Explains
Bitwarden Tutorial | The Full Beginners Guide
มุมมอง 160Kปีที่แล้ว
Bitwarden Tutorial | The Full Beginners Guide
Hackers Join Reddit API Protesters
มุมมอง 621ปีที่แล้ว
Hackers Join Reddit API Protesters
Don't Fall For This Bitcoin Phishing Scam
มุมมอง 476ปีที่แล้ว
Don't Fall For This Bitcoin Phishing Scam
I’m Never Using An Offline Password Manager Again
มุมมอง 9Kปีที่แล้ว
I’m Never Using An Offline Password Manager Again
Is MFA Still Safe? | How Hackers Bypass MFA
มุมมอง 7Kปีที่แล้ว
Is MFA Still Safe? | How Hackers Bypass MFA
Why Cyber Security Awareness Fails | #security #securitytraining
มุมมอง 837ปีที่แล้ว
Why Cyber Security Awareness Fails | #security #securitytraining
The Best Way To Run Windows Programs On Your Mac
มุมมอง 9Kปีที่แล้ว
The Best Way To Run Windows Programs On Your Mac
Bitwarden Passwords At Risk? | A Security Expert Explains
มุมมอง 39Kปีที่แล้ว
Bitwarden Passwords At Risk? | A Security Expert Explains
Lockheed Martin Cyber Kill Chain | The Defender's Mini Playbook
มุมมอง 651ปีที่แล้ว
Lockheed Martin Cyber Kill Chain | The Defender's Mini Playbook
Security Experts Know This About VPNs
มุมมอง 924ปีที่แล้ว
Security Experts Know This About VPNs
DDOS Attack Explained
มุมมอง 459ปีที่แล้ว
DDOS Attack Explained
Coinbase Hacked | A CISO Explains How
มุมมอง 1.2Kปีที่แล้ว
Coinbase Hacked | A CISO Explains How
What is a Business Email Compromise Attack | A Security Expert Explains
มุมมอง 1.5Kปีที่แล้ว
What is a Business Email Compromise Attack | A Security Expert Explains
35,000 Paypal Accounts Hacked: How to Protect Yourself | How Credential Stuffing Attacks Occur
มุมมอง 7Kปีที่แล้ว
35,000 Paypal Accounts Hacked: How to Protect Yourself | How Credential Stuffing Attacks Occur
The Perfect Cyber Security Resume
มุมมอง 1.3Kปีที่แล้ว
The Perfect Cyber Security Resume

ความคิดเห็น

  • @globalfamilyyoga
    @globalfamilyyoga 18 ชั่วโมงที่ผ่านมา

    I don't need to do that 2-step authentication (about 4 min in) if I have a premium account?

  • @DannySi
    @DannySi วันที่ผ่านมา

    Wish it would at least have some indicator that a passkey is associated with a login. Great feature regardless.

  • @salsuginusrex5196
    @salsuginusrex5196 2 วันที่ผ่านมา

    Great help! Liked and Subscribed. Gotta upgrade my very very dated cybersecurity knowledge/practice.

  • @nazzarenopisano652
    @nazzarenopisano652 2 วันที่ผ่านมา

    I understand having a backup method in case you lose your device, or your yubikey. However, couldn't a hacker also say "I lost my device", etc and use the "less secure" MFA?

  • @honnorjustice
    @honnorjustice 3 วันที่ผ่านมา

    I'm confused! Not computer savvy, sorry. So I set up my email and pass account. I entered a a name of a company that i normally shop at. Do I have to go and change my email address with the company to use my pass email instead of my actual email?

  • @user-bh1pg3ey5k
    @user-bh1pg3ey5k 3 วันที่ผ่านมา

    At end of day tho u still have to write down ur password somewere tho

  • @smartdecoder
    @smartdecoder 4 วันที่ผ่านมา

    Thanks for explaining ☺️

  • @daveschmidtlein8933
    @daveschmidtlein8933 5 วันที่ผ่านมา

    Excellent work, very well done. Older folks who were "introduced" to computers and our tech world half-way into our lives, really appreciate step-by-step tutorials. Bless you my friend!

  • @pichupich3941
    @pichupich3941 7 วันที่ผ่านมา

    Great advice, thanks.

  • @marta41553
    @marta41553 7 วันที่ผ่านมา

    I just got hacked with all my Etherum. who can help me fine were it went.i might never get it back. but they must be stop.. any one advice plz

  • @goodvalueservices-ys4kg
    @goodvalueservices-ys4kg 9 วันที่ผ่านมา

    How do you create a new password store for mobile apps?

  • @davesmith9188
    @davesmith9188 9 วันที่ผ่านมา

    My phone did not ask for a fingerprint or facial recognization. I think it did not set up right.

  • @uvw4249
    @uvw4249 11 วันที่ผ่านมา

    Can some1 recommend my a good/ funny master password?

  • @wildmanofborneo
    @wildmanofborneo 13 วันที่ผ่านมา

    Proton Pass just erased all logins in the entire vault. So frustrating.

  • @SteveCrowleyOCProperties
    @SteveCrowleyOCProperties 17 วันที่ผ่านมา

    Hi Jason, Thanks for the video. I was unable to create the two-step login as everytime I scanned the qr code, my iphone opened my apps and passwords section with the search section opened. I do not get any 6 digit verification code. When I attempt to download the Bitwarden Authenticator from my MacBook Pro to my chrome browser, or iphone 15 it says it is not recognized and cannot be downloaded.

  • @nad3359
    @nad3359 18 วันที่ผ่านมา

    That was so informative thank you. But who do you change a password when you used to not use Bitwarden, then set it up and need to change existing password to add them to the vault ?

  • @michaelpilger9251
    @michaelpilger9251 19 วันที่ผ่านมา

    Do I have to have a yubikey or what do I use instead

  • @SousDine
    @SousDine 21 วันที่ผ่านมา

    This seems generally well-presented, but as I haven't started to use 1Password yet I have several questions which are not obvious. For example, if I set up a 25 character password and I get logged out after a time-out, do I have to enter all 25 characters next time I want to log into a web site? And how long is the secret key? If 4-6 characters I can remember it, but if longer I cannot. So where do I store it? And then there is a reference to "a favourite authenticator". I don't know what this means. I don't have such a thing. Indeed some applications, including credit card transaction, sent a code to my 'phone, but does this mean something different? IS this "authenticator" an application on a device, or simply a mobile phone number? What is worrying is that I have (very) many years of computer experience. One of my friends invented WWW and I started computing by written a convolution integral in IBM 360 machine code! Thus, what people with no technical background will make of all this I can't imagine - but see comment below!

  • @BxhdhdGdrger
    @BxhdhdGdrger 22 วันที่ผ่านมา

    I’m also a victim who’s currently trying to complete the Recovry of my funds and account with the help of an expert named krudcracks cybertech they are the best in such services

  • @S10394
    @S10394 23 วันที่ผ่านมา

    @teachmecyber Thank You Love Your Channel

  • @randomdude5634
    @randomdude5634 23 วันที่ผ่านมา

    hmmmmmmmmmm

  • @daniilivanik5021
    @daniilivanik5021 23 วันที่ผ่านมา

    Sorry, bro, but saying that bitcoin is anonymous is definitely a lie. To make bitcoin anonymous you need to use ether mixers, ZK, or Monero. If you take pay with bitcoin from your Coinbase or Binance account, you are not anonymous at all

  • @whereisAdrian
    @whereisAdrian 23 วันที่ผ่านมา

    i dont want to use a passkey i want to type my password in ...... i want to be able to click forgot password and reset my password ..... i cant reset my password for a passkey if i have to ENTER the password to set the passkey.,......im SICK OF GOOGLE

    • @CH3D_SUP
      @CH3D_SUP 11 วันที่ผ่านมา

      Man fuck google all my homies hate google

  • @666dualsport
    @666dualsport 23 วันที่ผ่านมา

    what if you already have a username and password for the site and then you create a passkey?? cant the username and password still be hacked?? or is it deleted automatically once passkey created?

  • @Foxie.335
    @Foxie.335 24 วันที่ผ่านมา

    Thanks my friend that helped me a lot ❤

  • @Shinelacre
    @Shinelacre 25 วันที่ผ่านมา

    Reel that

  • @iupab
    @iupab 27 วันที่ผ่านมา

    I’m a last pass user and decided to trial 1Pass. What really concerns me is this one key that I have to save someplace ??!! What now I have to go buy a safe to keep it in? Seems like a security flaw to me!

  • @emason2e
    @emason2e 28 วันที่ผ่านมา

    I tried to set it up, but im clueless. I gave up and deleted it

  • @dongunderson9352
    @dongunderson9352 หลายเดือนก่อน

    Hold it! I don't save my passwords in any app. So I just have a handwritten list for my own use. So there is no files for me to "import". So how do I get my passwords into Bitwarden if I can't just import a file?

  • @ChinaAl
    @ChinaAl หลายเดือนก่อน

    How do I use my fingerprint? I don't have any wy on my Mac keyboard. I alo keep my iMac camera covered. Also I want to set this up onmy iPhone 14 as well.

  • @yusefmohamadi1341
    @yusefmohamadi1341 หลายเดือนก่อน

    Open source, Really? Can you share their backend server repo link?

  • @mikebloodworth9258
    @mikebloodworth9258 หลายเดือนก่อน

    I have a FritzBox 7590 modem I use to send daily PUSH notifications. It only supports SSL email and now has an authentication failure since moving from an ISP email to Gmail (login name pswd and smpt set correctly SSL port 587. How do I set up a passkey as you describe when google don't list the modem ?

  • @FoiIis
    @FoiIis หลายเดือนก่อน

    The corrupt American government organized crimes have a hacking tools and mill wire and soft wire and spy wire and they get access to the system and those hacking tools and wires is on the market the government are doing that to ripping money of the Americans people so they could buy new internet protection the same way he goes and sell spy cameras and then go to sell camera detectors whole that including the organized crimes is to interrupting peoples life and to keep them struggling.

  • @TomO-nx1bd
    @TomO-nx1bd หลายเดือนก่อน

    if you save your passkey on a Yubikey, will you have to have the Yubikey inserted anytime you use the PC from that point on? Or, will the login session stick on the PC until you explicitly log out of Google and only then would you need to use the Yubikey's passkey again?

    • @teachmecyber
      @teachmecyber หลายเดือนก่อน

      It just depends on the application. For Google, the default will be to keep you logged in on that device, so you won't need to put that yubikey in every time. The same way it works with your password and other MFA options

  • @Daniel_Haurich
    @Daniel_Haurich หลายเดือนก่อน

    Passbolt Self hosted is better !

  • @HalMinsky
    @HalMinsky หลายเดือนก่อน

    a passkey was setup on my Chrome but how do I find it and it is ?????

  • @NetBandit70
    @NetBandit70 หลายเดือนก่อน

    So a user has to enter their master password every time Passbolt fills a password? Password fatigue is a big problem, and people will invariably make mistakes, compromising their master password... the worst possible scenario.

  • @mauM-b1h
    @mauM-b1h หลายเดือนก่อน

    Mr Adrian notch, I would like to sincerely thank you from the BOTTOM of my heart! So many from tough harsh living conditions that suffer and you helping and giving them something that they desperately need just to survive. I thank God for wonderful people like you that are making the differences that truly matter most! God bless you Strong widget!!! Love from Greenville NC

  • @ssigitas69
    @ssigitas69 หลายเดือนก่อน

    Yesterday I installed Bitwarden to my Android phone to my Windows computer, add extension to Firefox and even downloaded desktop application. Watch your video and some more, try to do something and can say. I don;t understand anything 😭 and why I needed and how to use it

  • @alanjones7815
    @alanjones7815 หลายเดือนก่อน

    What the heck ia uberkey!

  • @ssigitas69
    @ssigitas69 หลายเดือนก่อน

    Just today I downloaded this app on phone, on computer and webbrowser. And haven't clue how to use it. I used Claude to explain, but it is not enough. Thank you so much for this video. It is little bit helped me. Now I need to find more videos how to change passwords for my imported loggins, etc 😁

  • @sernani99
    @sernani99 หลายเดือนก่อน

    It's not really easy, especially when going 100 MPh. Also, you didn't show how to add our own established passwords and on how to use it on a mobile device.

  • @JonathanSwiftUK
    @JonathanSwiftUK หลายเดือนก่อน

    Plans are getting expensive, I just installed Proton Pass, I already used the freed email, from long past. The password manager is very limited in terms of fields, compared to 1Password, and features, looks like a first issue. But I'm hopeful so I will do more checking. Honestly, lack of a desktop clients pretty much rules it out for me, although maybe having on Android might, possibly, be enough. It's possible I need to go to the paid level and eval for a year and make a significant assessment. Importing probably won't work, I have 2FA in my existing password manager - would that transfer ok.

  • @loungeindustries
    @loungeindustries หลายเดือนก่อน

    So how do you update your old passwords to a 1Password?

  • @SojourningOnline
    @SojourningOnline หลายเดือนก่อน

    Update: Since this was recorded Proton Pass now do have desktop apps for Windows, Apple Mac and Linux. They also have Passkeys and a built in authenticator which you just have to click on to autofill the authenticator code.

  • @WilliamFloyd-q5z
    @WilliamFloyd-q5z หลายเดือนก่อน

    Rosalinda Summit

  • @PixelMotionHD
    @PixelMotionHD หลายเดือนก่อน

    Do you have any hints why I can't get the key on Linux Ubuntu? Firefox forces me to touch my security key which i don't have, chromium wants me to use my android's phone key or other mobile device. Windows and Android phone worked flawlessly, and I don't know how to overcome this obstacle under Linux... :(

  • @HAL--ov4qu
    @HAL--ov4qu หลายเดือนก่อน

    I work in the IT field and specifically as a network admin for a big company and do a lot of cyber security. I hear many youtubers saying how Proton etc is worthless. They could not be more wrong (unless you are a criminal). Using one of the secure email providers is far superior to gmail, hotmail, yahoo etc. It is amazing how easy a hacker group can get all sorts of information from a garbage email provider. Using an email scrambler like Protons is a very good thing for many websites. Remember, if you use Tor, a VPN, a couple proxy servers and a secure email the FBI, InterPol, NSA etc will be able to read your emails. So before you decide to become the next Viktor Bout you might want to re-think your life. The safest way to email is to use burner accounts over Tor and through a series of proxies and a VPN's before you even go online. That is how Journalists and confidential informants do it. Sure there are things the CIA or NSA etc can do to create truly secure internal emails that will never go over a public server but we are not James Bond.

  • @bkid1776
    @bkid1776 หลายเดือนก่อน

    @Jason Rebholz very good job! Im curious when making the security key is it better to use a password generator offline and just copy and paste in a phrase or a bunch of random numbers and letters? Or make up my own? Also I wanted to know if you can take out passwords without it deleting the account for that password. Lets say i want 1password holding everything but not my gaming account and password if i dont want lets say that or a instagram account in there can i take it out without it deleting my account. Is it easy to basically import export One password at a time not all of them. So i can basically add only what i want.

  • @WatevaMelon
    @WatevaMelon หลายเดือนก่อน

    What's wrong with an excel sheet as your password manager?