


{"id":5517,"date":"2019-05-14T12:21:50","date_gmt":"2019-05-14T19:21:50","guid":{"rendered":"https:\/\/xmission.com\/blog\/?p=5517"},"modified":"2020-06-12T14:44:24","modified_gmt":"2020-06-12T21:44:24","slug":"our-new-compromised-email-policy","status":"publish","type":"post","link":"https:\/\/xmission.com\/blog\/2019\/05\/14\/our-new-compromised-email-policy","title":{"rendered":"Our New Compromised Email Policy"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-5552\" src=\"https:\/\/xmission.com\/blog\/wp-content\/uploads\/2019\/05\/xmisison-long-passwords.png\" alt=\"\" width=\"245\" height=\"213\" \/>This blog acts as notice to all XMission email customers, both residential and business, that our policy has recently been updated to include compromised email accounts.<\/p>\n<p style=\"margin: 0 10 0 0;\"><strong><span id=\"Policy_Page_Language:\" class=\"mw-headline\">Policy Language:<\/span><\/strong><\/p>\n<p style=\"margin: 0 10 0 0;\">The Compromised Mail Account policy addition is found on the XMission Policy page: <a class=\"external free\" href=\"https:\/\/xmission.com\/legal_policies#compro\" rel=\"nofollow\">https:\/\/xmission.com\/legal_policies#compro<\/a><\/p>\n<blockquote>\n<p style=\"margin: 0 10 0 0;\">Due to serious problems stemming from compromised mailboxes, XMission will handle the first compromise on any unique customer mailbox at no cost. At the time of the compromise the mailbox owner, or mail domain administrator, will be informed of the consequences of another compromise of the same mailbox within the next 24 months, including a nominal $25 Email Compromise Cleanup Fee per instance. The damage and considerable labor required to remedy these compromises is substantially more significant to XMission. The nominal fee is simply intended to incentivize responsible data protection practices by mailbox holders. Additionally, any mailbox suffering more than 3 compromises in a lifetime will be either permanently suspended or required to utilize a very secure 30+ character password.<\/p>\n<\/blockquote>\n<p style=\"margin: 0 10 0 0;\"><strong><span id=\"Overview:\" class=\"mw-headline\">Overview:<\/span><\/strong><\/p>\n<p style=\"margin: 0 10 0 0;\">Compromised mailboxes resulting in unwanted (spam) email message runs are impactful in that they can and do affect mail delivery for all customers and require substantial resources to resolve.<\/p>\n<p style=\"margin: 0 10 0 0;\"><strong><span id=\"Details:\" class=\"mw-headline\">Details:<\/span><\/strong><\/p>\n<p style=\"margin: 0 10 0 0;\">XMission staff spend a minimum of 30 minutes dealing with <em>each and every<\/em> mailbox compromise. This includes cleaning up the outbound mail server message queues, researching the extent of the compromise, discovering and getting servers and domains removed from blocklists, and contacting customers to change their password or repair their compromised machine.<\/p>\n<p style=\"margin: 0 10 0 0;\">XMission&#8217;s mail server reputation is damaged <i>every time<\/i> which means all customer email delivery can be hindered, including yours!<\/p>\n<p style=\"margin: 0 10 0 0;\">Standard practice is to the suspend the mail account, require a password change, and request the customer verify their machine or device is not infected with malware or a rootkit. Often this is sufficient and we never have a repeat from the same mailbox again.<\/p>\n<p style=\"margin: 0 10 0 0;\">Then there are the repeat offenders who are consistently compromised. These are customers who may not understand how to clean up after a malware compromise, who do not take personal or business data security seriously, or who are simply &#8220;too busy&#8221; to address the issue.<\/p>\n<p style=\"margin: 0 10 0 0;\">In some business cases they may have a mail domain administrator who is lax and resets the previously compromised password. All of these spell disaster for email server and the domain reputation. It is not safe, it is resource costly, and it requires immediate attention.<\/p>\n<p style=\"margin: 0 10 0 0;\">In order to require secure email practices and adequately educate customers on the consequences tied to email compromises XMission has implemented a $25 Compromised Email Cleanup fee as quoted and linked in the policy above.<\/p>\n<p>We encourage all customers to read and understand the policy. Should you have any questions please direct them to <a href=\"mailto:support@xmission.com\">support@xmission.com<\/a> or post a comment below.<\/p>\n<p>Additional XMission posts around email security:<\/p>\n<p style=\"padding-left: 40px;\"><a href=\"https:\/\/xmission.com\/blog\/2017\/10\/17\/best-practices-for-zimbra-email-security\" target=\"_blank\" rel=\"noopener noreferrer\">Best Practices for Email Security<\/a><\/p>\n<p style=\"padding-left: 40px;\"><a href=\"https:\/\/xmission.com\/blog\/2017\/12\/21\/sane-password-management\" target=\"_blank\" rel=\"noopener noreferrer\">Sane Password Management<\/a><\/p>\n<p>Your attention to this important issue is greatly appreciated.<\/p>\n<p><em><a title=\"Connect with me on LinkedIn, john801\" href=\"mailto:john@xmission.com\" target=\"_blank\" rel=\"noopener noreferrer\">John Webster<\/a>, \u00a0XMission Email Product Manager and Zimbra evangelist, has worked at <a title=\"Go, XMission!\" href=\"https:\/\/xmission.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">XMission<\/a> for over 23 years doing his favorite thing: helping companies securely communicate with customers through technology to grow their business. When he\u2019s not uncovering <a title=\"More Zimbra tips from John\" href=\"http:\/\/xmission.com\/blog\/?s=zimbra&amp;searchsubmit=Search\" target=\"_blank\" rel=\"noopener noreferrer\">Zimbra\u2019s secrets<\/a>\u00a0you might find him in our beautiful Utah mountains. \u00a0<a title=\"Connect with me on LinkedIn, john801\" href=\"https:\/\/www.linkedin.com\/in\/john801\" target=\"_blank\" rel=\"noopener noreferrer\">Connect with him on LinkedIn today!<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This blog acts as notice to all XMission email customers, both residential and business, that our policy has recently been updated to include compromised email accounts. Policy Language: The Compromised Mail Account policy addition is found on the XMission Policy page: https:\/\/xmission.com\/legal_policies#compro Due to serious problems stemming from compromised mailboxes, XMission will handle the first [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[657,253,396,269,270,3,5,39,615],"tags":[682,680,683,600,679,45,681,684],"class_list":["post-5517","post","type-post","status-publish","format-standard","hentry","category-education","category-email-2","category-mail-server","category-new-requirements","category-please-read","category-security-safety","category-tips-helpful-information","category-zimbra","category-zimbra-8-8","tag-business-security","tag-compromised-email","tag-malware","tag-password","tag-password-manager","tag-phishing","tag-policy","tag-rootkit"],"_links":{"self":[{"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/posts\/5517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/comments?post=5517"}],"version-history":[{"count":33,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/posts\/5517\/revisions"}],"predecessor-version":[{"id":6123,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/posts\/5517\/revisions\/6123"}],"wp:attachment":[{"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/media?parent=5517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/categories?post=5517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/tags?post=5517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}