Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: v20241211a
Table of Contents

2024-0812-20

Info

Rolling out throughout July 24th, 2024.

11

Status
colour

...

Blue
title

...

new feature
-

...

With this release comes the launch of INKY’s DMARC Monitoring as generally available.

INKY's DMARC Monitoring solution streamlines the DMARC process by offering a dedicated reporting address to collect these RUA reports. The service then aggregates and analyzes the data, presenting it in an intuitive dashboard. This empowers administrators to quickly identify issues and take appropriate action, ensuring robust email security and maintaining domain integrity.

DMARC Monitoring requires an extra entitlement, please reach out to support@inky.com or your account executive to get enabled for a trial.

Learn more: DMARC Monitoring

Status
colourPurple
titlenew threat Category
- Executable File

We’ve added a new threat category called Executable File which defaults to a yellow caution banner. While most organizations would never see these messages to begin with, due to default Microsoft and Google settings, some have requirements to process all emails. This category is given when one of the referenced filetypes is found in an email: Executable File Extensions Reference

Status
colourBlue
titlenew feature
- Wildcard Support for Outbound Mail Protection Approvers

Used primarily as a fall back for the approval flow INKY now supports the wildcard “*” pattern in the Sender Pattern qualification input.

The below screenshot is an example of a fallback approver set to matt@polvocapital.com where any email that doesn’t have a more specific approver setup will fall back to.

...

Team or Organization filter search

The Team search option within the Filters on the Dashboard has been updated to include an Organization search. This new search option allows you to search for a specific team or organization within the Dashboard. You can search using four different methods:

  1. Team Name: Search for a specific team by name.

  2. Organization Name: Search for a specific organization by name.

  3. Team ID: Search for a specific team by ID. This is the unique identifier for the team which is the same as organization ID.

  4. Domain Name: Search for a specific team by domain name.

...

Organizations are displayed in the search results with a building icon next to the name. This allows you to easily identify and filter by organization.

Status
colourBlue
titlenew feature
-

...

Found on the https://app.inkyphishfence.com/settings/signatures configuration page under the Styling & Formatting section is a new Maximum signature width option. This width defaults to 600px which is the maximum we’d recommend. Based on screen sizes of modern devices including laptops, tablets, and phones we’d recommend the following sizes below, but you can play around with whatever works for your organization.

  • Max: 600px

  • Best Fit: 450px

  • Min: 320px

If you have a banner image that is larger than the maximum width set, then it will extend past that boundary.

...

Status
titleENHANCEMENT
- QR Code Detection - HTML Table Phish

QR code phishing has become one of the most rapidly growing forms of phishing, especially since QR codes gained popularity during the global pandemic. Recently, INKY has observed a new evolution of this tactic, where QR codes are constructed using HTML tables and ASCII characters. We've noticed this technique emerging over the past few months and have implemented protections against it. Now, we’d like to share how it works and how we defend against it.

We’ve encountered this technique before, particularly when attackers impersonate the Microsoft brand. Take a look at the table below; it closely resembles the Microsoft logo. While Confluence might not fully capture the colors, it’s possible to get much closer in an email. Creating a logo using a table that closely mimics the standard Microsoft logo at a glance is an effective way to bypass detection platforms that don’t scan rendered images—unlike INKY, which employs Computer Vision (CV) checks. While it looks like a table when scanned by a machine, our CV checks reveal it as a brand impersonation of Microsoft.

...

Now, apply this concept to a QR code. QR codes are simply groups of black squares arranged in a way that allows users to scan them with a camera to navigate to a link. But what if you created a table of squares, filled in with black or white backgrounds, or even used the ASCII character █, to mimic a QR code?

While this technique might seem time-consuming, filling in the squares can be automated with simple scripting and then deployed at scale. Take a look at the examples below. The first image is the QR code without the table's grid lines—it looks exactly like a typical QR code but is incredibly difficult to detect because it’s not a standard image format. The second example reveals the grid lines, exposing the underlying technique.

INKY can detect this new technique in the same way we detect brand impersonations of Microsoft using tables—by analyzing the rendered DOM to see what the user sees. Although the email contains <table> or <pre> tags instead of an image in the HTML, our Computer Vision checks recognize that the user is actually seeing a QR code. INKY then scans the QR code and assesses whether it's dangerous. Even if it’s not classified as dangerous, INKY will still use the Email Assistant Banner to warn users with a message like “Beware of unexpected QR codes from unknown senders.” If the QR code is deemed dangerous, we’ll mark the email as malicious and send it to the admin quarantine based on your delivery settings.

...

Status
titleENHANCEMENT
- VIP List Authentication Checks

INKY has introduced a new checkbox option to enable authentication for VIP List checks. Previously, INKY would strictly match any "From" email address against the VIP list, considering it a match even if the email didn't pass authentication.

With this new option, the VIP list becomes more secure by requiring authentication for the "From" email address. This feature is currently rolling out to all customers and will become the default setting for all new teams in the future.

To enable this option, navigate to VIP List Settings.

...

Status
titleENHANCEMENT
- Block List applies to Reply-To

If an email address or domain listed on the block list is found within the Reply-To of a message then it will also match for that given block list entry.

For example, if a block list entry is added for tyler@productreport.ai or productreport.ai then it would apply to this email because the Reply-To is listed as that email address/domain.

...

Reinstall Option on Tenant Operations

On the Tenant Operations page Tenant Operations there is a new Reinstall option available. This option allows you to reinstall INKY for a specific tenant. To use this option, click the Reinstall button and confirm the action.

...

Note

This action will reinstall INKY for the selected tenant. All dashboard configuration will NOT BE modified. However, there may be a small window of time where messages are not processed by INKY. Only perform this action if you are sure you want to reinstall INKY for the tenant. If you have any questions reach out to INKY Support support@inky.com.

...

Status
colourBlue
titlenew feature
- Workflow Expiration Reminder Notifications

INKY’s Outbound Workflow includes notifications for messages held for review. Approval expirations can be set to 1, 2, 3, 5, 7, 14, 30, or 60 days, depending on the rule. However, longer approval periods carry the risk that the original approver might not act in time. To address this, we’ve introduced Expiration Reminders.

You can configure Expiration Reminders through the cog settings icon under the “Edit Rule” options. Simply select “Add Reminder” to set up the desired notifications. You can schedule up to two reminders with different intervals. For example, in the screenshot below, the 2 days and 4 hours option ensure the approver is notified 2 days and 4 hours before the original message’s expiration.

...

Status
titleENHANCEMENT
- Audit Log Updates

The Audit Logs has been updated to provide all accessible logs for the selected team or organization. INKY currently retains logs for the lifetime of the customer account (since June 2021). You can filter by the pre-selected timeframes or use the custom date range to view logs.

Find the audit logs at the bottom of this page: Admin Management - INKY

Status
titleENHANCEMENT
- Allow and Block List Comment Fields

The Allow and Block Lists have been updated to include a Comment field. This field allows you to add a comment to each entry in the list. Comments can be used to provide additional context or information about the entry. Comments cannot be changed once added, but you can delete and re-add the entry with a new comment if needed.

...