Security Policy: Email Communications and Anti-Phishing Standards
1. Objective
This policy defines the security standards applied to all automated email communications generated by the Platform. The purpose of this document is to ensure the authenticity of platform communications, protect user credentials, and mitigate risks associated with electronic identity theft (phishing).
2. Technical Domain Protection & DMARC Enforcement
To enforce strict brand authentication and prevent domain spoofing, the Platform has implemented a zero-tolerance email validation framework. Our global DNS records enforce the following cryptographic restrictions:
| DMARC Parameter | Setting | Security Enforcement Mechanism |
|---|---|---|
| v=DMARC1 | Protocol Version | Identifies the record as a DMARC record. Must be placed at the absolute beginning of the DNS configuration. |
| p=reject | Reject All | Instructs receiving mail servers (e.g., Gmail, Outlook) to immediately destroy and drop any email failing authentication. The message will not be delivered to the Inbox or Spam folder. |
| sp=reject | Subdomain Reject | Extends the strict rejection policy to 100% of subdomains, preventing attackers from sending emails from spoofed subdomains. |
| adkim=s | Strict DKIM | Requires an absolute, exact domain match between the visible sender address (From header) and the cryptographic DKIM signature. No subdomain variations are permitted. |
| aspf=s | Strict SPF | Requires an absolute, exact domain match between the visible sender address and the technical envelope sender (Return-Path address) authorized in our SPF records. |
| pct=100 | 100% Coverage | Guarantees that this defensive policy is applied to every single email transmission without exception. |
| fo=1 | Full Failure Alert | Generates an automated forensic incident report to our infrastructure if an email fails either the SPF or the DKIM check independently. |
| rf=afrf | AFRF Format | Standardizes the incident reporting format (Authentication Failure Reporting Format) across all global mail servers. |
| ri=3600 | Hourly Interval | Requests global mail servers to aggregate and transmit forensic and statistical reports to our platform every hour (3600 seconds). |
3. Zero-Marketing & User-Initiated Communication Rule
The Platform maintains a strict transactional-only communication policy to eliminate external spam vectors and protect user data integrity. Users must be aware of the following operational rules:
- User Action Triggered Only: Every legitimate email originating from the Platform is strictly initiated by a direct, real-time user action (e.g., requesting a password reset, generating a security token, or confirming an explicit configuration change).
- No Marketing Offers: The Platform will never transmit promotional materials, marketing offers, newsletters, surveys, or third-party advertisements via email.
- No Unsolicited Reminders: The Platform does not generate automated retention emails, system reminders, inactivity alerts, or unsolicited requests to update security credentials. If you receive an unexpected email claiming your account requires urgent validation that you did not initiate, it is an unauthorized phishing attempt.
4. Communication Format Standards
To minimize the attack surface and eliminate hidden graphical vectors used by malicious actors, the Platform strictly adheres to the following formatting rules:
- Plain Text Only: All automated service notifications and password resets are transmitted exclusively in plain-text format.
- No Rich Media: The Platform does not utilize HTML rendering, embedded images, inline styles, or hidden tracking pixels.
- URL Uniformity: No hyperlinks are masked behind descriptive text. The visible link text always corresponds exactly to the destination URL.
5. User Verification Requirements
When interacting with any communication purposed to originate from the Platform, users are advised to verify compliance with this security policy:
- Domain Inspection: Ensure the sender's domain matches the official platform infrastructure precisely. Be vigilant against look-alike domains or character substitutions.
- Format Verification: Treat any HTML-rendered email, graphical button, or styled layout claiming to represent a platform password reset as an unauthorized phishing attempt.
- Manual URL Entry: For enhanced security, copy the raw URL text provided in the plain-text email and paste it directly into your web browser's address bar rather than executing a direct click.
6. Incident Reporting
CRITICAL ALERT: If you receive a communication that violates any of the technical or formatting standards outlined in this policy, do not interact with its contents. Please immediately isolate the message and report the incident to the Platform.