Got wind of a real-world phishing incident with a client today, leading to taking a closer look at mailbox authentication/security within Enhance.
That said, a customer received a very convincing phishing mail, represent a login form using their own website design/domain - claiming 13 emails had yet to verified in their account via a link
Fortunately, the customer was suspicious enough to reach out before entering any credentials.
This raising questions of what might be available to protect customers from such styles of attacks. ie, I was looking through the documentation and Community discussions but was not able to find anything specific to to the following;
Though I did find mention of things like SMTP rate limiting and spam filtering, I was not able to find anything on 2FA for email accounts themselves or third-party plugins with Roundcube /though 2FA type thing.
I did see some requests for IMAP 2FA, mailbox login monitoring, and more granular controls for compromised mailboxes.
That said, I'd be interested to know what Enhance feature are available that could protect customers from this such styles of phishing attacks - ie,
Second authentication factor on mailbox access itself, rather than only Roundcube?
Detecting or alerting on unusual IMAP/SMTP logins from other countries or IP addresses?
Disabling SMTP auth from a compromised mailboxes while continuing to receive mail?
WebAuthn/passkeys, or similar mechanisms planned for the Enhance email stack?
In addition to this, I would also like to submit broader feature requests for business email in particular, and as I believe a native protection layer could prove valuable in cases where phishing attacks are sufficiently convincing to have customers surrender their login credentials.
Even in cases where full MFA for traditional IMAP clients presents compatibility difficulties, features such as unusual login detection, administrator/customer alerts, per-mailbox access controls, app passwords or token-based authentication could substantially limit the consequences.
I'd be interested both in what is possible today and what others would like to see Enhance provide in this area.