New: MX Logging

New: MX Logging

We’ve recently updated Rawstream Network Security to collect and report DNS MX requests. This matters because it can help organisations detect potential security breaches.

Mail Exchanges

DNS is the internet’s telephone directory. When you to browse to example.com, the browser looks up “example.com” against DNS servers, and the DNS server returns the address of example.com in a format that a browser can use to display the requested page. These requests are called A record DNS queries because the browser requests a page’s address.

However, there are different types of resources that are available over the internet. A highly requested resource is email. To send an email, your mail server needs to know the address of the server handling the receipient’s email. These DNS queries are MX (“mail exchanger”) requests.

In a most organisations, staff use the organisation’s mail service to send out email. There are good reasons for centralising email handling:
1. enforcing standards like templates and attachment sizes
2. archiving email for complaince purposes
3. scanning email for security threats

There are very few good reasons why email should not be sent via the central mail server. Indeed, MX requests from individual machines is highly unusual.

You’ve Sent Mail

Individual machines trying to contact MX servers directly usually indicates a security issue. Malware on the machine may be trying to send phishing email to external victims, sending email spam, or acting in concert with other infected machines as part of a DDOS attack.

The new Rawstream reporting helps identify suspicious MX DNS requests. The report shows the looked up domains, the number of lookups for that domain, the domain’s category, and the country where the domain is hosted.

MX Logs Report

MX Logs Report

The above screenshot shows a sample report for a Google Suite hosted mail server (google.co.uk) which receives the vast bulk of lookups, as well as two potentially suspicious lookups. One is for Hotmail, the second is for a China hosted mail server. Depending on your organisation’s communication patterns, these lookups may warrant further investigation.

About Rawstream Network Security

Rawstream Network Security is the fastest DNS filtering in the cloud, with intuitive user interface, real-time reporting and zero log retention limits. You can sign up for a free trial, or learn more here.

Related posts

Track Desktop Applications

Content filtering products limit themselves to reporting websites browsed. Not Rawstream! We track desktop applications used and the time spent in them. This is valuable data for at two reasons: license management, and tracking shadow IT. Rawstream's Application Usage data help you...

Product Update: New Reporting for Rawstream Web Filtering

Rawtream Web Filtering is a powerful web security solution for all your endpoints. A new report has been added that makes it very simple to track agent activity and deployed versions. Last Agent Activity The Last Seen column shows the last time each agent was active. Time is in the...

Blocking Zoom

Blocking Zoom

Rawtream Network Security is a powerful DNS-based filter for network-wide security. The EU is just the latest in a long and growing list of institutions either advising against, or outright banning Zoom. Google and SpaceX have banned Zoom from their networks, as has Taiwan, US school...