# Milepost 42 > I'll take care of your website, so you can take care of your business Language: en URL: https://milepost42.com/ All pages on this site are available as clean Markdown by adding the header `Accept: text/markdown` to any HTTP request, or via the REST API: REST API: https://milepost42.com/wp-json/mescio-for-agents/v1/markdown?url={page_url} REST API (by id): https://milepost42.com/wp-json/mescio-for-agents/v1/markdown?id={post_id} ## Pages - [Terms of Service](https://milepost42.com/terms-of-service/): TERMS OF SERVICE Milepost 42 LLC BY VISITING milepost42.com, YOU ARE CONSENTING TO OUR TERMS OF SERVICE. OVERVIEW By using milepost42.com, referred to as this “Site”, all visitors, referred to as “user”, “you” and “your” are bound by these Terms - [Please confirm that you wish to sign up](https://milepost42.com/sign-up-confirmation/): Thank you for signing up to the email list. Before I can send you the information you requested, I need to make sure I have permission to email you. You'll receive an email asking you to confirm your subscription. If - [Thank you for signing up](https://milepost42.com/thank-you-for-signing-up/): Thank you for signing up to my email list. I know, I know, one more email list...I warn you up front, I don't actually email that often (probably not as often as I should). My business is all about helping - [10 Steps to Email Authentication](https://milepost42.com/10-steps-to-email-authentication/): Will your emails pass authentication and make it to the inbox? New email authentication requirements from Google and Yahoo are shining a light on email best practices that have been stuck in the back room with IT for years. Starting - [Google Analytics 4 Setup](https://milepost42.com/google-analytics-4-setup/) - [Disclaimer](https://milepost42.com/disclaimer/):   - [Blog](https://milepost42.com/blog/): Blog Are you ready for the new email authentication requirements? 11 Jan 2024 | techstuff I recently read a statistic saying that 85% of emails sent in 2023 were spam. That seems like a lot, but I know I get - [About Me](https://milepost42.com/about-me/): About Me You don't have to know how to do everything. You just need to know someone who can do what YOU need done. My name is Stacy Clements, and I take care of the web stuff you don't want - [Contact](https://milepost42.com/contact/): Contact Send A Message - [Work On Your Business, Not Your Website](https://milepost42.com/): Are you wasting weekends working on your website? You started a business so you could do what you love.  Your business needs a website, but it doesn't need to be your weekend job. What if you had someone to take - [Services](https://milepost42.com/services/): Book Technical Service Package - [Presentations](https://milepost42.com/presentations/) - [Let’s Talk About Your Project](https://milepost42.com/lets-talk-about-your-project/): Whether you're looking for a brand new website, or it's time to refresh or update your existing site, I'd love to learn more. You may not be an expert on websites, but you are the expert on your business!  Are - [Milepost 42 Privacy Policy](https://milepost42.com/privacy-policy/) - [Serving Those Who Serve](https://milepost42.com/serving-those-who-serve/): My family believes in serving, and that's a core value of Milepost 42.  I've spent most of my life in military service, as my father and grandfather did before me, and my extended family is full of those who serve ## Blog Posts - [Phishing – Don’t Take The Bait](https://milepost42.com/phishing-what-to-do/) (2024-10-02): Can you spot the phish? One of the main ways cybercriminals steal funds and information or spread ransomware is by gathering information through phishing emails. Not all phishing emails are full of spelling errors and sent from people purporting to - [Email Authentication Questions and Tips](https://milepost42.com/email-authentication-questions-and-tips/) (2024-02-21): Email authentication using SPF and DKIM, and enforced with a DMARC policy, has been a best practice for years.  However, there's been a lot of buzz lately about SPF, DKIM, and DMARC, due to the announcements by Google and Yahoo - [Red roses or red flags? Watch out for romance scams](https://milepost42.com/red-roses-or-red-flags-watch-out-for-romance-scams/) (2024-02-13): Almost one-third of Americans have used an online dating site or app, and that percentage climbs with younger people, with over half of those under 30 using these services. It's great that technology gives us tools to connect with people - [I set up DMARC – now what?](https://milepost42.com/set-up-dmarc-what-now/) (2024-02-09): You set up DMARC records, but what is DMARC supposed to do again? And what are you supposed to do with those reports? - [Data Privacy Day – 3 Things You Should Do Today](https://milepost42.com/data-privacy-day-3-things-you-should-do-today/) (2024-01-28): It's Data Privacy Day - here are three things to do today to protect your privacy. - [SPF, DKIM, and DMARC, oh my! (part 2)](https://milepost42.com/spf-dkim-dmarc-part-2/) (2024-01-27): Ok, you've got an idea of what you need to do to get your emails to the inbox, so let's take that first step on the road toward the Email AuthentiCity... Who are your trusted senders? They say the first - [SPF, DKIM, and DMARC, oh my! (part 1)](https://milepost42.com/spf-dkim-dmarc-part-1/) (2024-01-26): There you are, a happy web designer doing your thing and starting to implement your plans for 2024, and all of a sudden, there's a tornado of chatter about new email authentication requirements. "I/my client got an email from Mailchimp - [Take Control of Your Data During Data Privacy Week 2024](https://milepost42.com/take-control-of-your-data-during-data-privacy-week-2024/) (2024-01-23): Data Privacy Week is an annual campaign to spread awareness about data privacy and educate individuals on how to secure their personal information. This year’s theme is “Take Control of Your Data”. All your online activity generates a trail of - [Are you ready for the new email authentication requirements?](https://milepost42.com/are-you-ready-for-the-new-email-authentication-requirements/) (2024-01-11): I recently read a statistic saying that 85% of emails sent in 2023 were spam. That seems like a lot, but I know I get a lot of spam in my email. Google and Yahoo know that, too. You may - [20 Years of Cybersecurity Awareness Month](https://milepost42.com/20-years-of-cybersecurity-awareness-month/) (2023-10-31): As we wrap up the 20th Cybersecurity Awareness Month, let's take a look at this year's themes and reminders on the threats out there and actions we can take to help stay safe online. Passwords One of the themes of - [Back That Up – Do It!](https://milepost42.com/back-that-up/) (2023-03-30): March 31st, World Backup Day! Well, really every day should be Backup Day, but if you've been living on the edge, today is the day to back up and get a plan together to guard against potential mishaps. No one - [State of WordPress Security Whitepaper Shows 328% Increase in Security Bugs](https://milepost42.com/state-of-wordpress-security-whitepaper-328-increase-in-security-bugs/) (2023-03-10): According to Patchstack's State of WordPress Security In 2022 whitepaper, there was a 328% increase in WordPress security bugs last year. But don't panic! This doesn't mean WordPress is less secure; in fact, this indicates there are lots of folks - [Love Is Blind – Keep Your Eyes Open To Avoid Romance Scams](https://milepost42.com/avoid-romance-scams/) (2022-02-13): Ever hear Brad Paisley's song about the short, chubby, "hero" who's "so much cooler online"?  The internet makes it easy for people to pretend to be something they're not.  And today's online dating landscape has made it easy for some - [3 Internet Safety Mistakes That Get You Hacked](https://milepost42.com/3-internet-safety-mistakes-that-get-you-hacked/) (2020-06-15): Just as personal hygiene can protect you from disease (wash your hands), practicing good cyber hygiene can help protect you from internet nasties.  Here are 3 common mistakes that compromise your internet safety, along with advice on what you can - [Don’t Trust, But Verify – Protect Yourself From Internet Crime](https://milepost42.com/dont-trust-verify-protect-against-internet-crime/) (2020-02-15): You may have heard the quote, "Trust, but verify," (made famous by Ronald Reagan), but based on the information in the FBI Internet Crime Complaint Center's 2019 Internet Crime Report, you'd do better to verify first. According to the FBI, - [National Cybersecurity Month Wrap-Up](https://milepost42.com/national-cybersecurity-month-wrap-up/) (2019-10-31): It's the last day of October, which means this year's National Cybersecurity Month is officially ending.  But that doesn't mean you should stop taking measures to #StayCyberSafe!  This year, the NCSAM theme was "Own IT, Secure IT, Protect IT" - - [Don’t Worry, Be (Safely!) Appy](https://milepost42.com/dont-worry-be-safely-appy/) (2019-10-23): There's an app for that! Nowadays, it seems like there really is an app for everything — games, shopping, fitness, hobbies, and more. No wonder almost 50% of all smartphone users download at least one new app a month. But - [Milepost 42 Will Promote Online Safety As A National Cybersecurity Awareness Month Champion](https://milepost42.com/milepost-42-will-promote-online-safety-as-a-national-cybersecurity-awareness-month-champion/) (2019-09-15): Milepost 42 is honored to join an initiative to promote awareness of online safety and privacy, by signing up as a Champion of National Cybersecurity Awareness Month (NCSAM) 2019. NCSAM is a collaborative effort among businesses, government agencies, colleges and - [Stay Safe While Shopping Online](https://milepost42.com/stay-safe-while-shopping-online/) (2019-07-08): Summer is here! Kids are out of school, and maybe you have a vacation planned - but cybercriminals never take a holiday. Whether you're booking a hotel room, buying concert tickets, picking up stuff for your garden, or taking advantage - [World Password Day 2019](https://milepost42.com/world-password-day-2019/) (2019-05-02): Happy #WorldPasswordDay!  The first Thursday of May is designated World Password Day, and it's intended to promote better password habits to help safeguard our digital identities.  With cybercrime on the rise and data breaches becoming almost commonplace, it's more important - [Shared Hosting: GreenGeeks](https://milepost42.com/shared-hosting-greengeeks/) (2019-03-09): Disclosure:  This post includes affiliate links to the recommended service, which means if you click on the link and make a purchase, I may receive a commission or bonus.  All my reviews and recommendations are based on my personal experience - [Data Privacy Day 2019](https://milepost42.com/data-privacy-day-2019/) (2019-01-23): Milepost 42 is proud to be a champion of Data Privacy Day 2019. The new year is well underway (already!?), and there's no better time to review the personal information you share and collect, and take steps to ensure it's - [Cybersecurity At Work: It’s Everyone’s Business](https://milepost42.com/cybersecurity-at-work-its-everyones-business/) (2018-10-15): It’s Week 3 of #CyberAware Month, and this week is all about tips and advice to ensure online safety at work.  No matter where you work - government, industry, academia - we all have a role in ensuring online safety - [In Demand: Consider A Career In Cybersecurity](https://milepost42.com/in-demand-consider-a-career-in-cybersecurity/) (2018-10-09): Week 2 of National Cybersecurity Awareness Month is focused on raising awareness about the need for cybersecurity professionals and inspiring students and those entering (or re-entering) the workforce to consider the many opportunities to contribute in this field. - [6 #CyberAware Tips to Protect Yourself and Your Family at Home](https://milepost42.com/6-cyberaware-tips-to-protect-yourself-and-your-family-at-home/) (2018-10-02): Autumn is here, and that means changing leaves, pumpkin spice, and Cybersecurity Awareness Month! The theme for the first week of Cybersecurity Awareness Month is Make Your Home A Haven for Online Safety.  Here are 6 things you can do to protect - [Milepost 42 Pledges to Support National Cybersecurity Awareness Month 2018 as a Champion](https://milepost42.com/milepost-42-pledges-to-support-national-cybersecurity-awareness-month-2018-as-a-champion/) (2018-10-01): Milepost 42 is proud to be a Champion of National Cybersecurity Awareness Month (NCSAM) 2018, joining a growing global effort among businesses, government agencies, colleges and universities, associations, nonprofit organizations and individuals to promote the awareness of online safety and --- # Full Content --- title: "Phishing – Don’t Take The Bait" url: "https://milepost42.com/phishing-what-to-do/" lang: "en-US" type: "post" description: "Can you spot the phish? One of the main ways cybercriminals steal funds and information or spread ransomware is by gathering information through phishing emails. Not all phishing emails are full of spelling errors and sent from people purporting to" last_modified: "2024-10-02T20:23:47+00:00" categories: [Cybersecurity] --- # Phishing – Don’t Take The Bait ## Can you spot the phish? One of the main ways cybercriminals steal funds and information or spread ransomware is by gathering information through phishing emails. Not all phishing emails are full of spelling errors and sent from people purporting to be Nigerian princes. Some are quite sophisticated, and emulate known and trusted brands. [Try this phishing quiz from Google to see if you can spot the phish.](https://phishingquiz.withgoogle.com/)   ### Common signs of phishing emails With the rise of AI, some of the signs we used to watch for in phishing emails aren’t as common.  Cybercriminals can use AI to sort through large amounts of data and personalize emails, rather than using a generic greeting.  AI writing tools can also reduce the grammar and spelling errors which used to be a hallmark of scam emails. Here are some red flags that still exist in many phishing emails: - **Urgent or threatening language:** Be wary of messages that try to rush you into taking action. Scammers often use pressure tactics to make you act before you think. - **Unfamiliar or mismatched email addresses:** Check the sender’s email carefully. If it looks odd or doesn’t match the organization it claims to be from, it could be a scam. - **Suspicious links or attachments:** Hyperlinks may look legitimate but lead to fraudulent websites, or attachments could contain malware. - **Requests for personal information:** Legitimate companies and those who care about protecting your data rarely ask for sensitive info through email. ### Not just email…  “Phishing” doesn’t just mean poorly written emails with bogus links – you also need to watch for phishing in other forms, such as: - **Vishing**: Phishing through telephone calls - **Smishing**: Phishing through texts/SMS - **Quishing**: Phishing using QR codes Warning signs for vishing and smishing are similar to those in email phishing – urgency, shortened links that you can’t verify, or requests for sensitive information. For quishing, be extra vigilant if you get a QR code in an email; using QR codes lets the bad guys bypass some of the filters in your email so they can sneak malware through. - Make sure any QR code you scan has context and is from a legitimate and expected source, and use a QR scanner that lets you check the URL before opening it. - If it’s a QR code in a public place, like a restaurant, check the QR code for any signs of tampering before you scan it. Cybercriminals have been known to create their own QR codes on stickers and place them over legitimate QR codes. ### Four tips to protect yourself from phishing - **Verify identities**: If someone asks for sensitive information, especially through an unexpected message, take a moment to verify who they are. It’s a good idea to use a different method than the one they used to contact you—just to be sure! - **Be skeptical**: Be careful with urgent or unexpected messages that push for immediate action, especially when it comes to financial info. For instance, if you get a call from someone claiming to be your bank about credit card fraud, don’t share any details with the caller. Instead, hang up and call the number on the back of your card to confirm it’s legit. - **Practice email (and QR code) safety**: Before clicking on any links in emails or QR codes, check where the link is actually taking you by hovering over it. Better yet, go directly to the website to verify the information—it’s a safer bet. No more scanning QR codes you see in a TV ad! - **Use good cyber hygiene**: Protect your accounts with strong, unique passwords and multi-factor authentication. Make sure to keep your software up to date, and don’t forget to use anti-malware on your devices. These habits will help keep you safe, even if you accidentally click on a sketchy link or share your login by mistake. ## Taken the bait? If you think you’ve been a victim of phishing, take action as soon as you realize the problem.  Change your account login credentials, scan your system for malware, and report the phishing attack to the company that was impersonated. You may also want to notify your bank and credit card companies, and be sure to closely monitor your statements for unusual activity. ## Report phishing If you get a phishing email or text, you can help fight back by reporting it! - If you receive a phishing email, you can report it to the [Anti-Phishing Working Group (APWG)](https://apwg.org/reportphishing/), which is an international team that helps tackle cybercrime. Just forward the email to **reportphishing@apwg.org**—and if possible, forward it as an attachment so they can gather more info for tracking and analysis. - For phishing text messages, forward them to **SPAM (7726)**. Most wireless providers support this, and it helps them block similar messages down the line. You can also [report phishing texts through your messaging app on Android](https://support.google.com/messages/answer/9061432?hl=en) or [report them in the iPhone Messages app](https://support.apple.com/en-us/111104). - You can also report the phishing attempt to the FTC at [ReportFraud.ftc.gov](https://reportfraud.ftc.gov/). Every report makes a difference in the fight against cybercriminals. --- --- title: "Services" url: "https://milepost42.com/services/" lang: "en-US" type: "page" description: "Book Technical Service Package" last_modified: "2024-11-19T19:37:18+00:00" --- # Services _ ### Service and Fee Table _ 1 file(s) __ 167.20 KB Download ## Book Technical Service Package --- --- title: "Serving Those Who Serve" url: "https://milepost42.com/serving-those-who-serve/" lang: "en-US" type: "page" description: "My family believes in serving, and that's a core value of Milepost 42.  I've spent most of my life in military service, as my father and grandfather did before me, and my extended family is full of those who serve" last_modified: "2024-05-08T04:33:01+00:00" custom_fields: site-post-title: "disabled" --- # Serving Those Who Serve My family believes in serving, and that’s a core value of Milepost 42.  I’ve spent most of my life in military service, as my father and grandfather did before me, and my extended family is full of those who serve or have served in the military, law enforcement, medical, and education fields. The heart to serve is not limited to these fields.  Over the years, I’ve met a number of people in nonprofit organizations who serve those in need, often with very little in the way of monetary resources. Each year, we select one nonprofit organization to receive some “web stuff” at no cost.  These pro bono services range from a website review with recommended enhancements, to email setup assistance, to a complete website build. We provide pro bono discounts on additional nonprofit projects on a case-by-case basis. ## 2023 “Serving Those Who Serve” Recipient ![Light A Lamp logo](https://milepost42.com/wp-content/uploads/2024/05/Light-A-Lamp-logo-1024x1024.png) ![screenshot of Light A Lamp home page](https://milepost42.com/wp-content/uploads/2024/05/screenshot-lightalamp.org_-1024x713.jpeg) ### Past Projects ![JBird's Journey screenshot](https://milepost42.com/wp-content/uploads/2024/05/Jbirdsjourneyscreenshot-300x163.jpeg) #### JBird’s Journey Website for JBird’s Journey, a nonprofit created to spread awareness about Lacrimal Gland Adenoid Cystic Carcinoma and other rare illnesses, as well as give back to those in need. ![SpokaneDelivers](https://milepost42.com/wp-content/uploads/2024/05/SpokaneDelivers-300x212.jpg) #### Spokane Delivers Website created to help support restaurants (and other businesses) with restricted operations due to the COVID-19 pandemic. ![Victory For Veterans logo](https://milepost42.com/wp-content/uploads/2024/05/Victory-For-Veterans-logo.webp) #### Victory For Veterans Website evaluation and minor update services, as well as email and newsletter setup support for nonprofit organization focused on mental health support for military veterans. ### Apply for next year Pro Bono "Serving Those Who Serve" Application**Contact Information** --- First Name Last Name Email Phone/Mobile Are you the decision maker for website projects? Yes No, it's someone else **Website Information** --- Organization Name Please tell me a bit about your organization. Is your organization an established 501(c)3? Yes No **Organization Information** --- Does your organization currently have a website? Yes No What best describes the type of web project you are looking for? Build a new website Update or add features to an existing website Something else (please provide information in your message) Please tell me a bit about your organization. Submit Application --- --- title: "Please confirm that you wish to sign up" url: "https://milepost42.com/sign-up-confirmation/" lang: "en-US" type: "page" description: "Thank you for signing up to the email list. Before I can send you the information you requested, I need to make sure I have permission to email you. You'll receive an email asking you to confirm your subscription. If" last_modified: "2024-03-14T20:58:01+00:00" custom_fields: exclude_local_search: 1 --- # Please confirm that you wish to sign up Thank you for signing up to the email list. Before I can send you the information you requested, I need to make sure I have permission to email you. You’ll receive an email asking you to confirm your subscription. [![animated envelope icon](https://milepost42.com/wp-content/uploads/2024/03/loaf-mail-1.svg)](https://milepost42.com/wp-content/uploads/2024/03/loaf-mail-1.svg) If you don’t see the email within a few minutes, please check your spam folder. Your email provider wants to protect you and sometimes will put new and unknown emails into spam. If you still can’t find the email, please contact me and we’ll get it sorted out. Thank you! --- --- title: "Thank you for signing up" url: "https://milepost42.com/thank-you-for-signing-up/" lang: "en-US" type: "page" description: "Thank you for signing up to my email list. I know, I know, one more email list...I warn you up front, I don't actually email that often (probably not as often as I should). My business is all about helping" last_modified: "2024-02-27T06:27:21+00:00" custom_fields: exclude_local_search: 1 --- # Thank you for signing up Thank you for signing up to my email list. I know, I know, one more email list…I warn you up front, I don’t actually email that often (probably not as often as I should). My business is all about helping solopreneurs and small business owners (really small businesses, not the Small Business Administration’s definition of small) with tech related stuff. The core of my business is taking care of WordPress websites. It’s important to security and making sure things work. But there’s a lot more to making a website “work” than just doing updates. And a lot of times the technology just seems to get in the way of a small business, well, getting business done. So, when I have something that I think will help you or might be interesting, I’ll share it – one small business owner to another. And if you have something you’d like to share too, feel free to let me know! --- --- title: "10 Steps to Email Authentication" url: "https://milepost42.com/10-steps-to-email-authentication/" lang: "en-US" type: "page" description: "Will your emails pass authentication and make it to the inbox? New email authentication requirements from Google and Yahoo are shining a light on email best practices that have been stuck in the back room with IT for years. Starting" last_modified: "2024-03-11T22:00:29+00:00" custom_fields: ast-global-header-display: "disabled" ast-banner-title-visibility: "disabled" footer-sml-layout: "disabled" --- # 10 Steps to Email Authentication ![10 Steps to Email Authentication ebook cover](https://milepost42.com/wp-content/uploads/2024/02/10-Steps-to-Email-Authentication-cover.jpg) ## Will your emails pass authentication and make it to the inbox? New email authentication requirements from Google and Yahoo are shining a light on email best practices that have been stuck in the back room with IT for years. Starting this February, Google and Yahoo starting rolling out new requirements – if you want to send email to anyone with a gmail or yahoo email address (um, all of us, right?), you’ll need to have at least basic email authentication (SPF or DKIM).  For bulk senders who send emails to over 5,000 subscribers, DMARC will be required as well. The alphabet soup of email authentication can be tough to swallow for web professionals and email marketers.  Your email marketing solution provider probably sent you a notification and a page of directions, but how do you know if you did it right?  And have you thought about other places that use your domain email – like your website or your invoice solution? ### This short ebook will provide you 10 steps to follow to set up your email authentication. Bonus:  You’ll also get an Email Authentication Tracker (the same one I use for myself and my clients) to help you through the process. Please leave this field empty _We don’t spam! Read our [privacy policy](https://milepost42.com/privacy-policy/) for more info._ We've sent an email to confirm your subscription. If you don't see the email within a few minutes, please check your spam folder. If you don't receive the email, please contact me at support@milepost42.com and we'll get it sorted out. --- --- title: "Email Authentication Questions and Tips" url: "https://milepost42.com/email-authentication-questions-and-tips/" lang: "en-US" type: "post" description: "Email authentication using SPF and DKIM, and enforced with a DMARC policy, has been a best practice for years.  However, there's been a lot of buzz lately about SPF, DKIM, and DMARC, due to the announcements by Google and Yahoo" last_modified: "2024-03-25T23:34:45+00:00" categories: [techstuff] --- # Email Authentication Questions and Tips Email authentication using SPF and DKIM, and enforced with a DMARC policy, has been a best practice for years.  However, there’s been a lot of buzz lately about SPF, DKIM, and DMARC, due to the announcements by Google and Yahoo about stricter requirements for emails. There are a number of [guides to setting up SPF, DKIM, and DMARC](https://milepost42.com/spf-dkim-dmarc-part-1/) (including mine), but no tutorial can cover every nuance.  And while most major email services provide their own guides for what is needed for their particular setup, it can get confusing for those who haven’t been exposed to the innards of how email works. I’ve seen and answered several questions in social media groups, and also run across a few oddities while setting up email authentication for clients.  I decided to collect some of these questions and “gotchas” and tips into one place, in case this helps anyone working through their own email authentication setup. ### Google Workspace requires an extra step for DKIM authentication With Google Workspace, you have to actually go in and “enable” DKIM after you set up the DKIM record.  Even if you configure DNS with the DKIM record using _google._domainkeys.example.com_ (for example), Google will not use DKIM to sign emails using your domain as the signing domain. After the DKIM record is added and has propagated, you need to go back in and click “Start Authentication”. DMARC may still pass using SPF if you don’t do this, but DKIM will not pass – and some Google applications don’t use your domain as the “envelope-from” or return path.  An example – Google Calendar invitations use a return path of _calendar-server.bounces.google.com_, which will not align with your domain. ### One does not simply jump to p=reject Be careful when setting up DMARC reporting tool – you may not want to use the _dmarc TXT they provide as default. Some DMARC tools provide an example _dmarc record using p=reject.  Yes, that is the most “secure”, and you eventually want to get there, but don’t start there.  Start with p=none and monitor until you’re sure you aren’t going to be blocking any legitimate emails. Suggested method is to start with p=none, then move to quarantine, and before moving to a full reject policy, start with a small percentage, e.g. pct=10 and gradually ramp up to pct=100. ### I use Mailchimp, and their directions tell me to create a CNAME record for DKIM, not a TXT record.  Is this correct? For Mailchimp, using a CNAME record is correct.  You’re pointing to Mailchimp’s DKIM.  A benefit of this is that if/when they rotate keys, you don’t have to redo the DKIM record. --- --- title: "Red roses or red flags? Watch out for romance scams" url: "https://milepost42.com/red-roses-or-red-flags-watch-out-for-romance-scams/" lang: "en-US" type: "post" description: "Almost one-third of Americans have used an online dating site or app, and that percentage climbs with younger people, with over half of those under 30 using these services. It's great that technology gives us tools to connect with people" last_modified: "2024-02-14T05:55:43+00:00" categories: [Cybersecurity] --- # Red roses or red flags? Watch out for romance scams Almost one-third of Americans have used an online dating site or app, and that percentage climbs with younger people, with [over half of those under 30 using these services](https://www.pewresearch.org/short-reads/2023/02/02/key-findings-about-online-dating-in-the-u-s/). It’s great that technology gives us tools to connect with people and even find love, but that technology also makes it easy for scammers to take advantage. Romance scams are big business; in 2022, Americans [lost over $1.3 billion to romance scams](https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2023/02/romance-scammers-favorite-lies-exposed#ft1). Those who fall victim may end up unwittingly serving as “money mules” helping launder illegal funds, or they may end up losing their own money trying to “help” an online sweetheart, or invest in the “great deal” their new love interest tells them about. ## How does a romance scam unfold? Essentially, a scammer creates a fake online profile, strikes up a flirtation or conversation online, pretends to be interested in the victim, and after fostering a relationship, eventually asks for money. They may claim to be hurt or sick, or have a relative in trouble, and they just need some money to help. The bad actor may study the information a victim shares online in order to be able to fake shared interests. And the information they share about themselves contains some reason why they can’t meet in person – they may claim to be stationed overseas or on a ship. Different twists to romance scams may include things like asking for private information or photos (which can then be used to blackmail the victim). Or the scammer may offer to do the victim a “favor” by helping them invest in cryptocurrency, or sending a valuable package for which they just need payment for customs fees. ## Watch out for red flags Some of the common tactics romance scammers use are: - Asking for money for something urgent - Requesting you wire funds, send gift cards, or send payment using cryptocurrency - Claiming to live far away so they aren’t able to see you in person - Using fake profile photos – you can do a reverse image search on photos, and if the details don’t match up, it’s a scam for sure - Wanting to move the conversation from a dating app to another messaging platform like WhatsApp (which may be harder to trace) ## How to break up with a scammer If you suspect you (or someone you love) are being taken advantage of by a romance scammer, take action right away. - Stop communicating with the scammer immediately - If you have any identifiable information, such as an email or phone number, write it down, and take screenshots of any information you have - If you’ve sent money, or shared login information about your bank or credit card, contact the bank or credit card company - File a report with your local police department and report the scam to the [FTC ](https://reportfraud.ftc.gov/)and [FBI](https://www.ic3.gov/) - Alert the website, platform, or app where you met the scammer – they might be able to help investigators by providing more information on the scammer ## Love may be blind – you shouldn’t be Protect your heart – and your bank account. Be careful what you share online, and watch out for the warning signs that your online love may not have your best interests at heart. --- --- title: "I set up DMARC – now what?" url: "https://milepost42.com/set-up-dmarc-what-now/" lang: "en-US" type: "post" description: "You set up DMARC records, but what is DMARC supposed to do again? And what are you supposed to do with those reports?" last_modified: "2024-02-12T23:03:54+00:00" categories: [General] --- # I set up DMARC – now what? You got a DMARC record set up for your domain – so now what?  Why did you need DMARC anyway?  What are those DMARC reports for, and what do you do with them once you get them? ## What is DMARC for again? DMARC is a mechanism to allow you, as a mail sender, to let mail-receiving entities (like Google or Yahoo Mail) know what you’d like them to do with emails from your domain that don’t pass validation checks.  It also lets you define how you’d like to receive reports on email handling. In conjunction with SPF and DKIM, DMARC helps to prevent email forgery.  SPF and DKIM together let an email receiver know whether an email is from a legitimate sending source and whether it’s been tampered with, but without DMARC, there’s no way for the email sender to know how effective SPF and DKIM are. DMARC reports let you know what is happening to sketchy emails that fail SPF/DKIM authentication, and helps you confirm that emails from your legitimate senders are getting through. ### Wait, so you actually have to go read these reports? Doesn’t it just send an alert if there’s something nefarious? Not exactly.  There are some DMARC reporting services that will send you alerts for failed emails or changes in your records.  But the reporting service doesn’t have any way to know for sure whether those issues are nefarious. It’s like getting failed login or file change notifications for your website.  They COULD be indicators of malicious activity, or they could be legitimate.  It’s up to you to determine what’s going on and what action you need to take. ### Types of DMARC reports There are two types of DMARC reports:  aggregate reports and failure reports (sometimes called forensic reports).  Aggregate reports are the reports you are most likely to see, as most mailbox providers no longer support failure reports due to privacy concerns. #### Aggregate reports Aggregate reports contain information such as: - The number of messages sent on a particular date - The domain used to send the messages - The sending IP address and source - Message authentication data - The DMARC result and disposition of the message This information is sent to the email identified in the “rua” tag of your DMARC record.  The default interval for reports to be sent is 24 hours, but you can specify a different interval in your DMARC record with the “ri” tag. As mentioned, these reports are sent in XML format, which can be hard for humans to decipher.  Ideally, you’ll want these reports sent to an analyzing service, so you can get the information in a more easily digestible format. #### Failure reports You can also ask for failure reports to be sent to the email address specified in your “ruf” tag.  Failure reports are basically a text copy of the email, including the email headers, and are generated at the time the email fails SPF or DKIM verification. Most email providers no longer send failure reports, due to concerns with privacy, since failure reports may include the text of an email which could contain PII.  Also, if you had a large number of failure reports, your inbox could quickly be overwhelmed, as these reports are sent for each failure, not aggregated. Since you’re mostly likely to be dealing with DMARC aggregate reports, we’ll focus on those. ### Do I really have to set up reporting in my DMARC record? While it’s possible to set a DMARC policy WITHOUT reporting, it’s not a good idea, especially if you set your DMARC policy to quarantine or reject.  Without reporting, you’ll have no way of knowing if legitimate emails are being blocked. I’ve seen some recommendations to “check the box” for the Google and Yahoo email authentication requirements by creating a DMARC record of: v=dmarc1; p=none; While this may technically meet the requirement to have a DMARC policy for now, it does nothing to help protect your domain against forgery, and I suspect Google and Yahoo will change to require at least p=quarantine in the future. ## How do I read a DMARC report? If you set up DMARC reporting using your own email address, you may have received emails with XML files, that look something like this: ![excerpt of DMARC report in XML format](https://milepost42.com/wp-content/uploads/2024/02/DMARC-XML-excerpt.jpg) While you could try combing through all that, you have better things to do.  If you already have some XML reports and want to try to decipher them, there are some online services where you can upload an XML report, and the service will analyze it for you. ### Analyzing XML files If you just need to examine a few reports, you can use something like the [MX Toolbox DMARC Analyzer](https://mxtoolbox.com/Public/Tools/DmarcReportAnalyzer.aspx) or [EasyDMARC XML Report Analyzer](https://easydmarc.com/tools/dmarc-aggregated-reports).  These services let you upload an XML report, and they will decipher the gibberish for you. With MX Toolbox, you’ll get a basic table of information.  It shows you the sending IP address, the number of emails sent (37), the number  that passed SPF and DKIM authentication checks, and the number that passed DMARC.  In this instance, all the emails sent for this period of time passed. ![MX Toolbox parsed XML report](https://milepost42.com/wp-content/uploads/2024/02/MX-Toolbox-parsed-XML-report.jpeg) EasyDMARC gives you a prettier report with a little more information.  This is the same XML report uploaded into EasyDMARC’s XML analyzer.  Here you can see the source as well as the associated IP, and a visual depiction of the status of SPF, DKIM, and DMARC, along with the disposition of the email (since it passed DMARC, it was delivered). ![EasyDMARC parsed report from XML upload](https://milepost42.com/wp-content/uploads/2024/02/EasyDMARC-parsed-report-from-XML-upload.jpeg) ### DMARC Report Analyzer Service Rather than sifting through XML reports or uploading them one by one, I recommend signing up for a service to monitor and analyze your DMARC reports. While you can have DMARC reports sent directly to an email address, the XML format those aggregate reports are sent in is really meant to be read by a computer, not a human!  A DMARC service will also collate the reports sent from the different email receivers, so you don’t have to collect them all yourself. #### Free Options If you don’t send a lot of email, and you don’t need alerts or other features, there are some services which will give you the basics for free. Cloudflare has recently created a DMARC Management service, and [Postmark](https://dmarc.postmarkapp.com/) has a service which will send a weekly report for one domain.  [Valimail](https://www.valimail.com/) also offers a DMARC monitoring service; it was originally meant for Office 365 customers, but now has a free basic service for all. Here’s an example of the report you get from Cloudflare’s service.  Like MX Toolbox’s analyzer, it provides the basic information in tabular format. ![Example of Cloudflare DMARC report](https://milepost42.com/wp-content/uploads/2024/02/Example-of-Cloudflare-DMARC-report.jpeg) #### Paid Options If you need particular features, or you send a lot of email, you’ll want to invest in a paid service, such as [EasyDMARC](https://easydmarc.com/), [DMARC Report](https://dmarcreport.com/), [MailHardener](https://www.mailhardener.com/), [Uriports](https://www.uriports.com/) – there are lots of options.  Choose one with the features you need and an interface you like. Most of the paid services base their pricing on the number of domains you manage as well as the number of emails sent, so make sure you choose one that meets your needs (you may be surprised how many emails are sent when you add up ALL your email sources). Many of these services have a free tier for personal use or for a single domain with limited emails, and most offer a free trial as well. Below is an example of a dashboard report from DMARC Report, followed by a drilldown into the listings. ![Example of DMARCReport dashboard](https://milepost42.com/wp-content/uploads/2024/02/Example-of-DMARCReport-dashboard-1024x299.jpeg) ![Example of DMARCReport view](https://milepost42.com/wp-content/uploads/2024/02/Example-of-DMARCReport-view.jpeg) ## Okay, but what am I supposed to do with these DMARC reports? Remember the reason for DMARC.  No, not just [because Google and Yahoo are requiring it](https://milepost42.com/are-you-ready-for-the-new-email-authentication-requirements/); it’s a standard to help protect your domain from email spoofing.  DMARC reports give you information to help you identify whether your email authentication setup is working correctly. Essentially, what you want to do with a DMARC report is: - Check the “senders” to make sure the ones you recognize and know should be sending email are passing DMARC - Check if any senders you DON’T recognize are getting through when they shouldn’t - Look at the emails failing DMARC and make sure those aren’t something that SHOULD be getting through - Generally check for things out of the ordinary – for example, if you’re suddenly getting a significant spike in your overall email sending, or a big increase in DMARC failures.  This could indicate your domain is “under attack” or a problem with errors in your SPF or DKIM. ### Example of DMARC report with all emails passing Here is an example of a DMARC report (from the aptly named system DMARCReport) for my domain for the past 7 days. ![Example DMARC report all passing](https://milepost42.com/wp-content/uploads/2024/02/Example-DMARC-report-all-passing-1024x809.jpeg) This tells me that there have been 26 emails sent from my domain name in the past 7 days; all have been DMARC compliant. The senders are Zoho CRM (my email system), sendingservice.net (the MailPoet sending service, which I included as an example), mtasv.net (which I know is Postmark, the transactional email service I use to send emails from my website), and transmail.net (a system that Zoho uses to send emails from some of their other products). I recognize all these senders, so I’m not concerned about someone sending emails pretending to be me. You’ll notice that sendingservice.net failed the SPF check.  Let’s take a closer look at that. ![Example of sender failing SPF alignment](https://milepost42.com/wp-content/uploads/2024/02/Example-of-sender-failing-SPF-alignment-1024x281.jpeg) There’s a [technical explanation for SPF alignment](https://datatracker.ietf.org/doc/html/rfc7489#page-56) which you can read if you’re so inclined.  But what it comes down to is that the MailPoet sending service is sending emails “from” my domain, but the return-path or “envelope from” address used by the email service is sendingservice.net.  Since these domains don’t match, the email will fail SPF alignment. However, since the email is validated with DKIM, it will pass DMARC.  Therefore, I’m not too worried about this – the email should still be getting through. Conversely, Postmark allows you to set up a custom “return-path” so the emails from your website can pass SPF alignment.  I have set up and tested my custom return-path, so the emails my website sends (mtasv.net in this example) pass both SPF and DKIM. ### Example of DMARC report with emails failing – as they should Here is an example of a DMARC report showing emails which failed DMARC checks. ![Example DMARC report with failing emails](https://milepost42.com/wp-content/uploads/2024/02/Example-DMARC-report-with-failing-emails-1024x488.jpeg) This report shows senders I do NOT recognize.  In this example, there is an IP 23.131.185.18, which resolves to jocularity.mammothswipe.com.  I have no idea what this domain is, and it’s nothing I’ve authorized. They have tried to send 3 emails using my domain, but those emails do not pass SPF or DKIM, so fail DMARC, and my DMARC policy of “quarantine” has been applied. If I saw a large amount of these emails, I might want to warn my customers that someone might be trying to launch phishing attacks with my email.  You can’t be 100% sure that the receiving email provider is actually quarantining or rejecting these fake emails (think how much spam you get in your inbox).  Unfortunately, you don’t know who the scammer might be sending emails to in your name, so there’s not much you can do about that, but you can warn your customers and contacts.  You can also do a WHOIS lookup  and try to report these attempts to the “abuse@” email address. ### Example of DMARC report with emails failing – potential problem This is another example of a DMARC report showing emails which failed DMARC checks, but in this case, it could be a problem. ![Example of DMARC report with failed emails](https://milepost42.com/wp-content/uploads/2024/02/Example-of-DMARC-report-with-failed-emails.jpeg) This report shows a large number of emails failing SPF and DKIM alignment, and therefore failing DMARC. Investigating the senders with the large amounts of failures, e.g. mcdlv.net, we find that they are associated with Mailchimp, an email marketing platform. In this case, it appears the client is sending emails through Mailchimp, but has not properly set up the SPF and DKIM records.  The DMARC policy for this domain is currently set to “none”, so the emails may be getting delivered; however, with the recent Google and Yahoo requirements for email authentication, I’d expect they are going to start seeing failures in their email campaigns soon. There are also some other unknown senders that are using their domain to send email, and those emails may also be getting through – these could be phishing emails or just spam, but it has the potential to damage their reputation.  (They really should hire me to fix this issue 😉) What we should do in this case is set up the appropriate records for the third party that should be allowed to send emails (Mailchimp), then once we’ve identified and authenticated all the known senders, slowly tighten the DMARC policy until the attempted spoofers get their emails rejected. ## Set up DMARC, and actually use it to make things better! Maybe you never heard of DMARC before the Google and Yahoo requirements, or maybe you decided to set up email authentication as one more layer of cybersecurity for your business.  Either way, properly setting up and monitoring DMARC helps to reduce spam and can help protect your domain reputation. Set up your DMARC record and sign up for an analyzing service to send the reports to.  Start with a DMARC policy of p=none, then monitor your reports for a while until you’ve identified all your legitimate senders. Once you see that your approved senders are all passing DMARC, move to p=quarantine and eventually p=reject to stop scammers from using your domain.  You want to continually monitor your DMARC reports to be sure your legitimate emails continue to get through, and that no spoofers have been able to sneak through your defenses. ## Need help with DMARC? If this really isn’t your thing, and you want someone else to handle it for you, or you’d like to offer this service to your clients, get in touch and let’s talk about how I can help. Contact FormFirst Name Last Name Email Subject Your Message Get In Touch! --- --- title: "Data Privacy Day – 3 Things You Should Do Today" url: "https://milepost42.com/data-privacy-day-3-things-you-should-do-today/" lang: "en-US" type: "post" description: "It's Data Privacy Day - here are three things to do today to protect your privacy." last_modified: "2024-01-28T17:14:30+00:00" categories: [Privacy] --- # Data Privacy Day – 3 Things You Should Do Today Today is Data Privacy Day, an international day of recognition to promote best practices in safeguarding data and respecting privacy. There’s a lot of talk in the news about new privacy laws and the rights of individuals.  While many businesses are taking a look at their practices and privacy policies, there are also several organizations under fire for real or perceived violations of individuals’ privacy. ## Why do I have to share information anyway? You do have to give up some private information in order to have some of the conveniences you may enjoy. - You can’t get “local deal alerts” or “check in” on your phone unless you allow the device to know your location. - You can’t get local weather from your smart home speaker, unless you are willing to share your address with the owning company. - And you can’t get special offers on your favorite products without sharing your preferences. But in many cases, you do have control of the data you choose to share. ## Take control of YOUR data privacy. Here are three things you can do today to celebrate Data Privacy Day and take action to protect and control your data. ### 1. Set up multi-factor authentication Privacy and security aren’t exactly the same thing, but they are related. Using multi-factor authentication is absolutely necessary on things like your financial accounts, in order to protect you from fraud. However, it’s also a good idea to secure your email and social media accounts, so your personal information isn’t exposed. ### 2. Review your privacy settings You read all those privacy policies for every site where you set up an account, right? It’s easy to just ignore or gloss over those long legalistic policies, but take a few moments to read them and make sure you really do understand and agree with how the company can use your data. Often, they also give information on how you can limit the data you share. Spend a little time today to examine and update your privacy settings, and take control of your data. Not sure where to find the privacy and security settings? [Check out this great resource with links to change privacy settings on many popular services and devices](https://staysafeonline.org/stay-safe-online/managing-your-privacy/manage-privacy-settings/). ### 3. Delete recorded conversations Most personal assistants keep records of your queries and requests. There have been instances where personal data was inadvertently revealed to a person other than the device owner. While most of these recordings are innocuous, it’s a little creepy to think about, and all these little snippets of information could be collated and become a bigger privacy issue. Take a few minutes and clean your digital house today by deleting those recordings, and make sure you’re comfortable with how long the recordings are kept. [This Consumer Reports article provides information on how to control what’s heard and recorded on the “big three” devices, Amazon Alexa, Apple Siri, and the Google Assistant.](https://www.consumerreports.org/privacy/smart-speaker-privacy-settings/) Take action today, and Own Your Privacy! You can [learn more about Data Privacy Week at StaySafeOnline.org](https://staysafeonline.org/programs/data-privacy-week/about/). ![](https://milepost42.com/wp-content/uploads/2019/01/Champion-Badge.png)_Milepost 42 is proud to be a [Data Privacy Week Champion](https://staysafeonline.org/programs/2024-data-privacy-week-champions/)._ --- --- title: "SPF, DKIM, and DMARC, oh my! (part 2)" url: "https://milepost42.com/spf-dkim-dmarc-part-2/" lang: "en-US" type: "post" description: "Ok, you've got an idea of what you need to do to get your emails to the inbox, so let's take that first step on the road toward the Email AuthentiCity... Who are your trusted senders? They say the first" last_modified: "2024-03-23T18:13:14+00:00" categories: [General, techstuff] custom_fields: ast-featured-img: "disabled" --- # SPF, DKIM, and DMARC, oh my! (part 2) Ok, you’ve got an idea of what you need to do to get your emails to the inbox, so let’s take that first step on the road toward the Email AuthentiCity… ## Who are your trusted senders? They say the first step is always the hardest, but this initial planning step is critical to properly setting up your email authentication. Take some time to think through EVERY system that sends email with “somename@yourdomain.com”.  Your ESP is the biggest one, but as a web professional, I can almost guarantee you have at least two other sources – your “regular” email and your website. If your email is set up with one of the big providers (e.g. Google, Outlook, Zoho), then your DNS records are probably already set up; this would have been part of the initial configuration with adding MX records and the other associated records. Start by making a list of all the systems you send email from.  You’ll then need to determine if they send email from YOUR domain. Some systems may let you put in your name as a “display name” but actually send from their domain.  For example, my booking system sends confirmation emails from “Stacy Clements”, but the email is not sent from MY domain; it uses the booking system domain, bookme.name. Once you’ve identified all your sending sources, let’s ease on down the road to the Email AuthentiCity. ## SPF Remember, the SPF record is a TXT record in your DNS that shows all the servers that are allowed to send using your domain name.  For the Feb 2024 Google/Yahoo changes, the focus is on ESPs, but if you set this up considering only your ESP, you’re potentially going to block other important emails. ### If I could send from this domain… Look at your list of platforms from which you send email.  For those that use YOUR DOMAIN to send email, check to see if they have an SPF record for you to include. Watch out!  You can only have one SPF record per domain. ### Combine SPF entries into one record The instructions from your ESP or other service may simply tell you to “add this TXT record to your DNS” and give you something like: v=spf1 include:_spf.google.com ~all But don’t add multiple records for your multiple services.  A domain can only have one SPF record; otherwise, SPF checks will return an SPF PermError (permanent error) which may lead to deliverability problems. If you have multiple SPF records to include, you’ll need to combine them. ### How to merge multiple SPF entries Now you’ve gathered up all the SPF entries you need to include.  How do you combine them into one record? The exact method for creating an SPF record varies slightly depending on what you use to manage your DNS, but essentially there are three main components: Record type:  This should be TXT.  There are still a few DNS management systems out there that still show an option for an “SPF” type record, but the DNS SPF record was deprecated in 2014, so be sure to use TXT. Name:  This is the domain name that you are “assigning” the SPF entries to. Content:  This is where you combine the entries you have. The content must start with “v=spf1”; this declaration should only be used once. Next you add the allowed domain names (or IP addresses).  Each must have an “include” statement for domain names, or if you have an IP to include, the entry shows the type of IP address (most likely ip4) and the IP. At the end, you add the enforcement rule.  This is typically ~a (softfail) or -a (hardfail).  I use ~a, for the [reasons recommended in this Mailharder article,](https://www.mailhardener.com/blog/why-mailhardener-recommends-spf-softfail-over-fail) although -a (hardfail) may be appropriate if stricter enforcement is needed (or if you have a domain that should not be sending emails). ### SPF example You send email from Google, you have Mailgun set up to send transactional email from your website, and you use Mailerlite for marketing emails.  Instead of three records: v=spf1 include:_spf.google.com ~all v=spf1 include:_spf.mlsend.com ~all v=spf1 include:mailgun.org ~all You will have one record: v=spf1 include:_spf.google.com include:_spf.mlsend.com include:mailgun.org ~all It’s unlikely unless you run your own server, but if you need to include an IPv4 address in your SPF record, you’ll add it with the ip4 mechanism, so your record might look like this: v=spf1 include:_spf.google.com include:_spf.mlsend.com include:mailgun.org ip4:188.241.151.48 ~all Watch out!  There are some other things to watch for with SPF records.  The ones you are most likely to encounter are: - Limited to 255 characters - Don’t use uppercase characters - Limit of 10 DNS lookup entries (not the same as the different “include” entries you added) ### Check your SPF record There are several services where you can check your SPF record for free.  A few of my favorites: - [Mimecast DMARC Analyzer](https://www.mimecast.com/products/dmarc-analyzer/spf-record-check/) - [Mailhardener SPF Validator](https://www.mailhardener.com/tools/spf-validator) - [EasyDMARC SPF Record Checker](https://easydmarc.com/tools/spf-lookup) I recommend adding a regular check to your business processes.  Sure, once you’ve set it up, as long as you don’t change anything with your email senders, it should be okay. But it’s possible your sending sources may make a change.  You’ll want to make sure there are no glitches that cause errors in your SPF record.  And especially if anyone else has access to your DNS records, you’ll want to monitor for changes (to any records). Also, if you do make changes to any of your services, remember to check and validate your SPF record. Plot twist! Not every sender that uses your domain will have an SPF entry for you to add.  Many of you use Postmark for transactional email, and may remember you did not have to set up SPF for Postmark.  Mailchimp is one example of an ESP which does not provide an SPF entry. Technically, you only need an SPF record for senders which use your domain for the Return-Path address (Postmark wrote a good explanation about this and [why you don’t need to add an SPF record for Postmark](https://postmarkapp.com/blog/why-we-no-longer-ask-for-spf-records)), but mostly what you need to know is just to check the verification methods for your specific sender. Typically, there will be some sort of “authenticate your domain” wizard which will tell you exactly what records you need to add to your DNS.  Instead of an SPF entry, some systems will have you create a CNAME entry which will include authentication information. Now that you’ve identified all your sending sources, and set up and checked your SPF records, let’s take a look at DKIM. ## DKIM Wait, my head’s all full of SPFing…what is DKIM about again? DKIM, or DomainKeys Identified Mail, is an email authentication standard that allows “digital signing” of emails to verify their integrity and authenticity. Ok, what does that mean in plain English?  Think of it like this: Say you get a letter, and the “from” address on the envelope says it’s from your friend.  But anyone can write your friend’s address on an envelope and put a letter in the mail. Think back to the days when royal decrees were sent out.  These documents had the royal seal on them, to prove they were signed by the monarch.  Sometimes documents were closed using wax, with the seal impressed into the wax.  As long as the seal was intact. the receiver of the document would know the documents were authentic and had not been tampered with. ### DKIM acts as your verified signature DKIM is used to “sign and seal” emails sent from your approved servers.  This verification is done using a public/private key pair. Did you ever have a “secret decoder ring” as a kid?  DKIM works something like that.  Servers authorized to send your emails use their “private key” to encode a message.  The “public key” then allows the receiver to verify and decode the message. ### DKIM private and public keys The email service provider is responsible for generating the private/public key pair.  The services you use will typically generate the key pair for you, and provide you a DKIM record to publish in your DNS. This DKIM record is a TXT record that includes the “public key” that is used to verify the DKIM signature on a message.  Unlike SPF records, you will likely have multiple DKIM records; a DKIM record also includes a “selector” specifying which public key should be used for verification. Some services will give you the option of choosing a 1024 or 2048 (or possibly even 4096) bit key.  Do not use a key any smaller than 1024 – shorter keys can be cracked in a short amount of time (kind of like using an 8 character password).  Be cautious when using a key larger than 2048; there may be limitations on the size allowed by your DNS provider, and there are still some older email systems out there that may not support DKIM keys with larger sizes. Pro tip:  When you add a DKIM record to your DNS, keep a note on what selector goes with what service.  Sometimes the selector you are given includes a clue, like “google” for Google Workspace email, but often you are given a generic selector such as “k1”.  If you don’t annotate somehow, you may end up with a bunch of DNS records and no idea what service they belong to.  (Ask me how I know.) Example:  you send email from Google, you have Postmark set up to send transactional email from your website, and you use Mailerlite for marketing emails.  You’ll have three DKIM records – TXT records that will look something like this: Name: google._domainkey Content: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2nRUpz6hucTiwJ8HjpzGw5g7jMJHk3/usrTrRlrn69+qRS+DS6NZqP4YGM28B04H5S1lZs1TWYM1l1hObHluFZF5B1XKzyM7kfnfep0KfgElRAV1H7UUtHXUhcPVsseJy39JpDn48/TQuvrUM5hzHpa96llYHDakhohRKO+lNBhD3sbbOZvAfV/I8SH5xCTmjDWnqhqVZ9MeTDJZt0cATvshs+nyaUWZWePLZpGn1wSfRivxQsArUSnuve/drEa5vvHvI0Fqt0hEGz07YIYO5TGKyb3qqdPS6c3m4lH2zd5dJZKQ5+fiGoATOpO7/ffJbH3OKSPoa8qLXwFD/xWFJwIDAQAB Name: 20231018181234pm._domainkey Content:k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFq7sUVCaKkj41K4Vwb6rByjgznDUFS9eXNibWZ6dW7vU1be57WJMYhduMXhclRvzzBGnkSMUj4uIhA9GqqqRRG6klgiJ3RG/BMOkDVvTiBYqdXlwI2jE+Avd22IcVm2Q4LFNhxRZbHBVunLwBYyUEbGNMHKqNdEvMrMFX73h1XwIDAQAB Name:  ml._domainkey Content: v=DKIM1;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzkWjb4fSOJMsz1GsYThyyEz5uwkXpNYI7ZCc7/27KWyBRuNKZdMjC47wJgzmNFhuYwYO4jIyiu85sr+2kIpBh5CuuWaNRCzMLNfEHPr1EJODg1We1X4hm3I615XLxENIbGrlm5v6mL1RAo45oo5VfM0szASkKLawe5x9bMBpw8QIDAQABf ### Validate your DKIM record Usually, you just need to copy and paste the DKIM record your ESP provides, and go on about your business.  However, if you have issues, or want to dig into the properties of the record, there are online services that can help validate your DKIM record. I like the [Mailhardener DKIM validator.](https://www.mailhardener.com/tools/dkim-validator)  [MXToolbox DKIM record checker](https://mxtoolbox.com/dkim.aspx) is another good option. Plot twist! There are some email providers who direct you to insert a CNAME record instead of a TXT record for DKIM.  In these cases, the CNAME is pointing to a DKIM record in a DNS zone owned by the ESP. Typically this is done because the email provider may rotate the DKIM keys.  By using a CNAME, the customer (you) don’t have to worry about changing your DNS records – your CNAME record automatically points to the correct record. You may want to consider rotating your DKIM keys periodically, or if you are notified by your ESP of the need to do so – it’s like changing your password. Okay, your sender list is set up (SPF), and you have a way to verify your signature on the emails you send (DKIM), so you’re ready to set up a DMARC policy. ## DMARC DMARC stands for Domain-based Message Authentication Reporting & Conformance (but no one remembers that).  Essentially, DMARC is a policy mechanism; it works with SPF and DKIM and tells email receivers what to do with emails that don’t pass those authentication checks. [DMARC also allows you to set up reporting](https://milepost42.com/set-up-dmarc-what-now/), so an email receiver can tell you about emails it receives from your domain, and the results of the authentication checks. ### How DMARC works The DMARC process essentially follows these steps: - **Email Sent**: The process begins when an email is sent from a sender’s domain. - **Receiving Server Check**: The receiving email server performs checks to authenticate the email. This includes SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) authentication. - **Authentication Pass/Fail**: If the email passes SPF and/or DKIM checks, it proceeds to delivery. If authentication fails for both SPF and DKIM, it moves to the next step. - **DMARC Check**: The receiving server checks the DMARC record published by the sender’s domain. - **DMARC Policy Enforcement**: Based on the instructions in the DMARC policy, the receiving server takes action on the email. This can include delivering the email as usual (p=none), marking it as spam or placing it in quarantine (p=quarantine), or rejecting it outright (p=reject). - **Reporting**: The receiving server sends a DMARC report to the domain owner (email address identified in the DMARC record), detailing the outcome of the DMARC checks and actions taken. If you want to learn more about the technical details of how DMARC works, I recommend you take a look at [LearnDMARC.com](https://www.learndmarc.com/).  You can send an email to “Neo”, the LearnDMARC server, and you’ll get a behind the scenes look at the technical process of how DMARC works. ### Set up a DMARC record A DMARC record is a TXT record in the DNS for your domain.  Like SPF, you should have only one DMARC record per domain (there are some technical situations with complex email setups where you might have multiple records, but for our purposes – we just need one). #### Parts of a DMARC record **Name: ** The “name” section of your DNS system should use _dmarc.  What you are doing is setting up a subdomain of _dmarc.yourdomain.com.  Depending on what system you use to manage DNS, you may or may not need to put in your domain name; i.e. for Cloudflare, just put _dmarc, otherwise the yourdomain.com part will be duplicated). **Type: ** The content part of the record must start with v=DMARC1.  This tells querying systems that this TXT record is for DMARC. **Policy:**  This is the direction given to an email receiver on what to do with emails that fail SPF/DKIM checks.  Options are p=none, p=quarantine, or p=reject. When first setting up DMARC, start with p=none.  This gives you a chance to identify any sending sources you may have missed, and ensure that your email authentication records are correctly configured.  After monitoring for a period of time, step up to p=quarantine and eventually p=reject. **Reporting:**  This section tells email receivers where to send reports.  There are two tags that can be used in this section:  rua= where to send aggregate reports and ruf= where to send failure reports.  Be sure to use mailto: before your email address in these tags (use the URI, not just the email address). Technically, the reporting section is optional; you CAN have a valid DMARC record with just v=DMARC1; p=none.  However, I recommend against this.  A p=none policy does nothing for you, and having emails quarantined or rejected with no reporting mechanism – well, that’s just a bad idea. #### Optional tags for a DMARC record **Percentage: ** This is the sample of messages that should be restricted based on your policy.  The percentage option (pct) is often used when tightening up DMARC restrictions, i.e. moving to quarantine or reject.  If you don’t want to risk all your emails going to the black hole, you can set a percentage amount such as pct=50. **Policy for subdomains:**  By default, the DMARC policy for a domain will be applied to all subdomains as well.  If you wish to have a different policy applied to subdomains, you can use the sp tag.  For example, if you want to apply a quarantine policy to your main domain, but your subdomains should not be sending email, you could add sp=reject, so the quarantine policy applies to your main domain, but the reject policy applies to subdomains. **SPF alignment mode:**  The aspf tag allows you to set how strict the SPF alignment should be.  The default is aspf=r, which is relaxed mode, meaning that subdomains will be considered valid.  If you need very strict security, then aspf=s can be used.  This is strict mode, and requires that the “envelope from” domain sending the email must exactly match the return path (where bounces are sent). **DKIM alignment mode:**  Similarly, you can set how strict DKIM alignment should be, using adkim=r (relaxed) or adkim=s (strict).  Generally, unless you need strict alignment for some reason, you don’t need to include the adkim or aspf tags; the default is relaxed mode. ### DMARC example 1.  You have your SPF and DKIM records set up, and you’re ready to start implementing DMARC, but you want to start with just monitoring, to ensure you have identified and properly configured your SPF and DKIM. Your DMARC record will look something like this: v=DMARC1; p=none; rua=mailto:ruaemail@example.com; ruf=mailto:rufemail@example.com - v=DMARC1 indicates the DMARC version. - p=none specifies the policy as monitoring mode, meaning that emails failing DMARC checks won’t be rejected or quarantined. - rua=mailto:rua@example.com designates the email address where aggregate reports (periodic summaries of DMARC results) should be sent. - ruf=mailto:ruf@example.com specifies the email address for failure reports (note that most email providers no longer send failure reports due to privacy reasons) 2.  You have been monitoring DMARC for a while, and want to tighten your DMARC restrictions.  You want to set a policy of quarantine, but you want to limit it to 50% of emails, to keep from impacting email flow and reputation. Your DMARC record will change to look like this: v=DMARC1; p=quarantine; pct=50; rua=mailto:ruaemail@example.com; ruf=mailto:rufemail@example.com 3.  You’re confident your email authentication records are configured correctly, and enforcing a strict DMARC policy won’t disrupt legitimate email.  Implement the p=reject policy, but start slow, perhaps with 20%, and slowly increase as long as your monitoring shows no issues. v=DMARC1; p=reject; pct=20; rua=mailto:ruaemail@example.com; ruf=mailto:rufemail@example.com ## The never-ending story You’ve successfully navigated the bewildering forest of SPF, DKIM, and DMARC (oh my!), and made it to Email Authenticity.  But you can’t just snooze in the poppy field.  Managing email authentication is an ongoing process, and you need to stay alert if you want your emails to continue to get home to the inbox where they belong. ### Monitoring DMARC You need to monitor DMARC closely when you initially set up your policy, but even after you’ve set everything up correctly, you need to continue monitoring. Setting up DMARC is like having a guard watching over your email castle, but you want to be sure that guard is doing a good job, and not letting any intruders sneak in – or keeping out the visitors you want. Regular monitoring will help you detect issues that may come up, like an unexpected new email sender (oops, your client forgot to tell you they switched from Mailchimp and suddenly there are hundreds of unauthenticated messages).  It will also let you know if unauthorized senders are spoofing your domain (you’d be surprised how often this happens). ### Keep an eye on SPF and DKIM You’ll also want to check to ensure your legitimate sending sources haven’t changed something that causes your emails to fail authentication.  Periodically check your SPF records, and consider changing your DKIM keys, especially if there are indications a key may have been compromised. This is why you need to [set up DMARC reporting](https://milepost42.com/set-up-dmarc-what-now/), so you can monitor what’s happening with your email. ### Still have questions? The process of setting up SPF and DKIM and DMARC is pretty straightforward, but of course sometimes a devil pops up in the details.  There are differences in how setup is done across different DNS providers, and also differences in technical implementation by email providers and sending sources.  I’ve collected a questions and “gotchas” from experiences I’ve had or heard about – maybe one of these [email authentication tips](https://milepost42.com/email-authentication-questions-and-tips/) will help. If you’ve configured your email authentication records, but you aren’t quite sure how to go about the ongoing process of monitoring, read this article on [what to do now that you have DMARC set up](https://milepost42.com/set-up-dmarc-what-now/). If you’d rather just click your heels together and have someone else do this, I’ve got you! You can book my service and I’ll handle this for you. Or if you can’t face doing this for your clients and would rather outsource it, I can help there too. You can either refer them to me, or contact me and we can work out options. [ Purchase Email Authentication Service ](https://book.stacyclements.com/email-authentication-setup) --- --- title: "SPF, DKIM, and DMARC, oh my! (part 1)" url: "https://milepost42.com/spf-dkim-dmarc-part-1/" lang: "en-US" type: "post" description: "There you are, a happy web designer doing your thing and starting to implement your plans for 2024, and all of a sudden, there's a tornado of chatter about new email authentication requirements. \"I/my client got an email from Mailchimp" last_modified: "2024-03-23T18:04:33+00:00" categories: [techstuff] custom_fields: ast-featured-img: "disabled" --- # SPF, DKIM, and DMARC, oh my! (part 1) There you are, a happy web designer doing your thing and starting to implement your plans for 2024, and all of a sudden, there’s a tornado of chatter about new email authentication requirements. - “I/my client got an email from Mailchimp / MailerLite / Shopify / Mailgun / some other platform about new Google email requirements and I don’t know what to do.” - “I’m just a web designer; I don’t understand this email stuff.” - “Can someone please explain in small words what I need to do about these new email compliance updates?” ## As a web professional serving clients, what do you really need to know about email authentication? You’re not in Kansas anymore.  You’re in the Land of Email, and the wicked Google (and Yahoo, but let’s be real, we know who’s really driving) is going to keep your emails out of the inbox. You just want your emails to get to their proper home, but you’ve got to get through this confusing forest full of SPF, DKIM, and DMARC (oh my!). **_Bottom line:  If you want people with Gmail or Yahoo email addresses to receive your emails, you must send from a domain you own and have properly authenticated._** ## What is this “new email requirements” fuss even about? Google and Yahoo announced that starting in February 2024, they will start requiring bulk email senders to: -  Authenticate emails they send, using industry best practices and implementing SPF, DKIM, and DMARC -  Enable one-click unsubscribe in email headers, and honor unsubscribe requests within 2 days -  Only send email that users want – in other words, keep spam rates below a certain threshold _References:_ _[Google’s announcement of new email sending requirements](https://blog.google/products/gmail/gmail-security-authentication-spam-protection/)_ _[Yahoo’s announcement on enforcing new email standards](https://blog.postmaster.yahooinc.com/post/730172167494483968/more-secure-less-spam)_ ### Wait, so if this is just for “bulk senders” I don’t have to do anything, right? Well, not exactly.  While the big announcement focused on bulk senders, and that’s where the “bulk” of the issue is, if you look a little deeper into the sending requirements that Google and Yahoo have recently published, you’ll see requirements for ALL senders, including things like: -  Properly authenticating email – setting up at least DKIM or SPF -  Keeping spam complaints low -  Using a TLS connection to transmit email _References:_ _[Google’s requirements for all email senders](https://support.google.com/mail/answer/81126?hl=en#zippy=%2Crequirements-for-all-senders)_ _[Yahoo’s requirements for all senders](https://blog.postmaster.yahooinc.com/post/737268108173230080/an-update-on-enforcing-email-standards)_ ### But whyyy?  I’m not a spammer! Of course you’re not, but there are plenty of bad guys out there who are spammers or scammers or both.  Email authentication has been around for years, and these “new” email requirements have been best practices for a long time. Basically, what Google is doing is like making everyone get an entry badge to get into the inbox.  That’ll make it a little easier to keep the spam and malicious emails out. You see, Google really isn’t the Wicked Witch…more like the Wizard making you jump through hoops to get what you need. ## Ok, fine, so how do I do this authentication? Before we start tackling the alphabet soup, realize one important thing – you can only authenticate a domain that you own.  For example, I can authenticate the email addresses for my domain, milepost42.com, but I can’t authenticate my @gmail.com address. If you have clients who are still using their @gmail.com address (or hotmail, yahoo, aol, or what have you), let them know about this.  It won’t affect their “regular” email; Google authenticates its own domain, so sending from myemail@gmail.com works just fine. But if they’re using that email for bulk email sending (e.g. through Mailchimp or another email marketing service), especially if they have over 5,000 contacts, that’s a problem.  If they have a list less than 5,000, it _might_ be okay – for now – but their emails are going to be less likely to make it to the inbox. Are you thinking, “I need to let my clients know about this”, but aren’t sure what to say?  [This post about the new email authentication requirements](https://milepost42.com/are-you-ready-for-the-new-email-authentication-requirements/) is the email I sent to my clients; you’re welcome to take out my “offer” and use it for your clients.  (Or if you’d rather have someone else do this stuff for your clients, you can leave my offer in and refer them to me). ### What is this SPF, DKIM, DMARC stuff? SPF, DKIM, and DMARC are email security protocols that work together to “authenticate” emails and protect against spoofing and malicious behavior.  We implement these protocols by adding specific DNS records. ####  SPF (Sender Policy Framework) - SPF is a TXT record that is basically a list of the servers that are allowed to send email using your domain name – such as your website, ESP, CRM, or maybe your invoicing system. - There used to be an actual “SPF record”, but that was deprecated several years ago, so when you see “SPF record” what is really meant is a TXT record with the a list of IPs, names, or servers allowed to send email for your domain. - Important:  You can only have one SPF record per domain.  You may have multiple senders who all give you an SPF record that looks something like this: v=spf1 include:_spf.google.com ~all, but don’t add them all as separate records; you need to combine them. #### DKIM (Domain Keys Identified Mail) - DKIM is like a signature for your emails, saying they really came from you and haven’t been tampered with. - A DKIM record is also a DNS TXT record, but this one is actually the public half of a pair of cryptographic keys. - You need a DKIM record for each valid sender.  The email sender generates a public and private key pair.  The public key is the DKIM record you put in your DNS; when an email is sent, this is compared against the private key for validation.  It’s similar to setting up a passkey – the public key is on the service you are using, while the private key is on your phone or device, and they have to match or you don’t get in. #### DMARC (Domain-based Message Authentication Reporting & Conformance) - DMARC is essentially a policy that tells an email provider (e.g. Gmail) how to handle nonvalidated emails.  It gives instructions saying that if an email arrives saying it’s from you, but doesn’t match the SPF or DKIM information, here’s what to do with that email. - You can set a DMARC policy to do nothing (just let the email provider decide), quarantine the email (usually meaning it goes to spam), or reject the email completely. - Note that not all email providers follow your DMARC policy; sometimes they do what they want, so there’s no guarantee that an email will get through.  Even if it’s authenticated, if the email provider thinks it’s spammy, it’ll get sent to spam. - A DMARC record also lets you put in a email address to receive reports on what happened to your emails.  This is really useful when you first implement DMARC, so you can understand where emails from your domain are coming from and what’s happening to them.  Once you have everything set, it lets you monitor what’s happening with your emails and help prevent someone from spoofing your email (sending emails to people pretending to be from you and hurting your reputation). ## Are you ready to authenticate your emails? In [part 2, we’ll follow the yellow brick road step by step to Email Authenticity](https://milepost42.com/spf-dkim-dmarc-part-2/)…   If you’d rather just click your heels together and have someone else do this, I’ve got you! You can book my service and I’ll handle this for you. Or if you can’t face doing this for your clients and would rather outsource it, I can help there too. You can either refer them to me, or contact me and we can work out a way. [ Purchase Email Authentication Service ](https://book.stacyclements.com/email-authentication-setup) --- --- title: "Take Control of Your Data During Data Privacy Week 2024" url: "https://milepost42.com/take-control-of-your-data-during-data-privacy-week-2024/" lang: "en-US" type: "post" description: "Data Privacy Week is an annual campaign to spread awareness about data privacy and educate individuals on how to secure their personal information. This year’s theme is “Take Control of Your Data”. All your online activity generates a trail of" last_modified: "2024-01-25T17:42:30+00:00" categories: [Privacy] --- # Take Control of Your Data During Data Privacy Week 2024 Data Privacy Week is an annual campaign to spread awareness about data privacy and educate individuals on how to secure their personal information. This year’s theme is **“Take Control of Your Data”.** All your online activity generates a trail of data. Websites, apps, and services collect data on your behaviors, interests, and purchases. Sometimes this includes personal data, like your Social Security and driver’s license numbers. It can even include data about your physical self, like health data – think about how a smartwatch records how many steps you take, or maybe tracks your sleep habits. You can’t control how each byte of data about you and your family is shared and processed, but you are not helpless! In many cases, you can control how you share your data with a few simple steps. Remember, your data is valuable – be selective about who you share it with! ## Here are three tips that will help you manage your data privacy: ### 1. Know the tradeoff between privacy and convenience When you download a new app, open a new online account, or join a new social media platform, you will often be asked for access to your personal information before you can even use it. This data might include your geographic location, contacts, and photos. For many businesses, this personal information about you has tremendous value – and you should think about if the service you get in return is worth the data you must hand over, even if the service is free. Make informed decisions about sharing your data with businesses or services: - Is the service, app, or game worth the amount or type of personal data they want in return? - Can you control your data privacy and still use the service? - Is the data requested even relevant for the app or service (that is, “why does a Solitaire game need to know all my contacts”)? - If you haven’t used an app, service, or account in several months, is it worth keeping around knowing that it might be collecting and sharing your data? ### 2. Adjust settings to your comfort level For every app, account, or device, check the privacy and security settings. These should be easy to find in a “settings” section and should only take a few moments to change. Set them to your comfort level for personal information sharing. I generally lean on the side of sharing less data, not more. You don’t have to do this for every account at once! Start with one or two, and make it a habit to adjust settings whenever you download a new app or sign up to a service. The National Cybersecurity Alliance has in-depth, free resources like the [Manage Your Privacy Settings](https://staysafeonline.org/stay-safe-online/managing-your-privacy/manage-privacy-settings/) page that helps you check the settings of social media accounts, retail stores, apps, and more. ### 3. Protect your data Data privacy and data security go hand-in-hand. Along with managing your data privacy settings, follow some simple cybersecurity tips to keep it safe. Consider following the Core 4: - Create long (at least 16 characters), unique passwords for each account and device. Use a password manager to store each password – maintaining dozens of passwords securely is now easier than ever. - Turn on multifactor authentication (MFA) wherever you can – this can help protect your login even if your password is compromised. - Turn on automatic device, software, and browser updates, or make sure you install updates as soon as they are available. - Identify and report phishing messages – remember, phishing can be done via emails, texts, or direct messages. You can [learn more about Data Privacy Week](https://staysafeonline.org/programs/data-privacy-week/about/) at the National Cybersecurity Alliance website. --- --- title: "Blog" url: "https://milepost42.com/blog/" lang: "en-US" type: "page" description: "Blog Are you ready for the new email authentication requirements? 11 Jan 2024 | techstuff I recently read a statistic saying that 85% of emails sent in 2023 were spam. That seems like a lot, but I know I get" last_modified: "2024-01-28T17:10:36+00:00" custom_fields: site-post-title: "disabled" site-sidebar-layout: "no-sidebar" site-content-layout: "page-builder" ast-featured-img: "disabled" theme-transparent-header-meta: "default" ast-title-bar-display: "disabled" astra-main-page-id: 38777 ast_self_id_38777: 1 --- # Blog # Blog [ ![illustration of computer and phone sending email](https://milepost42.com/wp-content/uploads/bb-plugin/cache/sending-email-custom_crop.png) ](https://milepost42.com/are-you-ready-for-the-new-email-authentication-requirements/) ### Are you ready for the new email authentication requirements? ##### 11 Jan 2024 | [techstuff](https://milepost42.com/category/techstuff/) I recently read a statistic saying that 85% of emails sent in 2023 were spam. That seems like a lot, but I know I get … [Read More →](https://milepost42.com/are-you-ready-for-the-new-email-authentication-requirements/) [ ![person using a password manager and multifactor authentication with a computer and mobile phone](https://milepost42.com/wp-content/uploads/bb-plugin/cache/cybersecurity-practices-custom_crop.jpg) ](https://milepost42.com/20-years-of-cybersecurity-awareness-month/) ### 20 Years of Cybersecurity Awareness Month ##### 31 Oct 2023 | [Cybersecurity](https://milepost42.com/category/cybersecurity/) As we wrap up the 20th Cybersecurity Awareness Month, let’s take a look at this year’s themes and reminders on the threats out there and … [Read More →](https://milepost42.com/20-years-of-cybersecurity-awareness-month/) [ ![World Backup Day](https://milepost42.com/wp-content/uploads/bb-plugin/cache/wbd_horizontal-custom_crop.png) ](https://milepost42.com/back-that-up/) ### Back That Up – Do It! ##### 30 Mar 2023 | [Cybersecurity](https://milepost42.com/category/cybersecurity/) March 31st, World Backup Day! Well, really every day should be Backup Day, but if you’ve been living on the edge, today is the day … [Read More →](https://milepost42.com/back-that-up/) [ ![blue globe with network links across a blue background](https://milepost42.com/wp-content/uploads/bb-plugin/cache/network_across_globe-custom_crop.jpg) ](https://milepost42.com/state-of-wordpress-security-whitepaper-328-increase-in-security-bugs/) ### State of WordPress Security Whitepaper Shows 328% Increase in Security Bugs ##### 10 Mar 2023 | [Cybersecurity](https://milepost42.com/category/cybersecurity/) According to Patchstack’s State of WordPress Security In 2022 whitepaper, there was a 328% increase in WordPress security bugs last year. But don’t panic! This … [Read More →](https://milepost42.com/state-of-wordpress-security-whitepaper-328-increase-in-security-bugs/) [ ![romance scam protect your information](https://milepost42.com/wp-content/uploads/bb-plugin/cache/Romance-Scams7_Stay-Safe-Online-custom_crop.png) ](https://milepost42.com/avoid-romance-scams/) ### Love Is Blind – Keep Your Eyes Open To Avoid Romance Scams ##### 13 Feb 2022 | [Cybersecurity](https://milepost42.com/category/cybersecurity/) Ever hear Brad Paisley’s song about the short, chubby, “hero” who’s “so much cooler online”?  The internet makes it easy for people to pretend to … [Read More →](https://milepost42.com/avoid-romance-scams/) [ ![Own Your Privacy](https://milepost42.com/wp-content/uploads/bb-plugin/cache/Own_Your_Privacy_1-custom_crop.png) ](https://milepost42.com/data-privacy-day-3-things-you-should-do-today/) ### Data Privacy Day – 3 Things You Should Do Today ##### 28 Jan 2022 | [Privacy](https://milepost42.com/category/privacy/) Today is Data Privacy Day, an international day of recognition to promote best practices in safeguarding data and respecting privacy. There’s a lot of talk … [Read More →](https://milepost42.com/data-privacy-day-3-things-you-should-do-today/) --- --- title: "About Me" url: "https://milepost42.com/about-me/" lang: "en-US" type: "page" description: "About Me You don't have to know how to do everything. You just need to know someone who can do what YOU need done. My name is Stacy Clements, and I take care of the web stuff you don't want" last_modified: "2025-03-05T01:29:07+00:00" custom_fields: site-post-title: "disabled" site-sidebar-layout: "no-sidebar" site-content-layout: "page-builder" ast-featured-img: "disabled" theme-transparent-header-meta: "default" ast-title-bar-display: "disabled" astra-main-page-id: 38777 ast_self_id_38777: 1 --- # About Me # About Me ## You don’t have to know how to do everything. You just need to know someone who can do what YOU need done. My name is Stacy Clements, and I take care of the web stuff you don’t want to deal with. Oh, and I’m kind of zealous about keeping all those tech things “cyber secure”, too. ### You Don’t Have To Do It Alone **I’m a small business owner too – I get it!** • You’re a solopreneur or a nonprofit or have a small team – you don’t have or need full-time web support, but you do need someone to handle the “web stuff” and someone to call when you have a question. It’s like handling your finances – you may not have an accountant on staff, but you’ve got an accountant’s number on your phone. • Small businesses are not immune to cyberattacks, but cybersecurity can seem overwhelming. However, there are basic actions we can all take to protect ourselves. I help small business owners tailor a plan based on their risks.   ### Who’s On Your Crew? I spent 23 years in the military, and one of the enduring lessons I learned is what amazing things you can accomplish if you have the right team. I don’t mean a team like in those “group projects” we had to do in school, where most of the people just skated by on others’ work. I’m talking about a team where everyone understands the mission, everyone brings their own strengths to the table, and everyone works together using those strengths to meet the goal. It’s like winning an auto race. You’re the driver for your business. But if you try to be your own pit crew, that’s going to slow you down.   ### Together, We Win One of my military bosses called me “a fixer, a problem solver, and a pitbull” – and I have to admit, that’s pretty accurate. I like to make things work. I’m good at figuring stuff out. I’m pretty tenacious when I sink my teeth into a problem. And I can be a little fierce about protecting those on my team. I filled many different roles in the Air Force – project manager, information and technology manager, cyber operations planner, emergency operations center director, and mission support commander. I learned how to listen, lead, plan, and get results. In 2008, I started a freelance business on the side, building and maintaining websites for individuals and small businesses. When I retired from the Air Force, I still wanted to be part of a team, using my planning, problem solving, and tech skills to help others meet their goals – and Milepost 42 was born. Today, I’m the “web person” team member for small businesses, solopreneurs, and nonprofits who need someone on the crew to take care of the web stuff. I’m part of the team at the Inland Northwest Business Center teaching cybersecurity essentials to small business owners. And I have people on my team, like my visual designer, Rebecca Caligan, who make it possible for me to focus on what I do best.   ### Want the pitbull on your pit crew? Get in touch, and [let’s talk about what you need](https://milepost42.com/lets-talk-about-your-project/).   ![Stacy Clements](https://milepost42.com/wp-content/uploads/2024/01/Stacy-Clements-July-2023.jpg) ![Service Disabled Veteran Owned Small Business](https://milepost42.com/wp-content/uploads/2024/02/cve_completed_s.jpg) ![WA Office of Minority and Women's Business Enterprises Certified](https://milepost42.com/wp-content/uploads/2024/02/OMWBE-Certified-Badge.png) [ ![ISC2 Certified in Cybersecurity](https://milepost42.com/wp-content/uploads/2024/02/certified-in-cybersecurity-cc-2.png) ](https://www.credly.com/badges/ea332f1f-70b6-4439-9bb8-48c9078df893/public_url) [ ![Google Analytics Certified](https://milepost42.com/wp-content/uploads/2024/02/Google-Analytics-Certified.png) ](https://skillshop.credential.net/7dc17d28-2207-4ebb-a48b-849fbcaeca05) ![](https://milepost42.com/wp-content/plugins/bb-plugin/img/pixel.png) [ ![Proofpoint Certified Ransomware Specialist 2023](https://milepost42.com/wp-content/uploads/2024/02/proofpoint-certified-ransomware-specialist-2023.png) ](https://www.credly.com/badges/1cd8114c-3aa5-4dd2-bac3-0b51d3fe6134/public_url) [ ![Proofpoint Certified Email Authentication Specialist Badge](https://milepost42.com/wp-content/uploads/2024/02/proofpoint-certified-email-authentication-specialist.png) ](https://www.credly.com/badges/68cfbdae-f360-4428-94bf-bea19132d54a/public_url) [ ![WordPress Project Management Academy Level 1](https://milepost42.com/wp-content/uploads/2024/02/WPPMA-Badge-Level1.png) ](https://academy.wproadmaps.com/certifications/certified-wp-pm-level-1/) [ ![Proofpoint certified DLP specialist badge](https://milepost42.com/wp-content/uploads/2024/02/proofpoint-certified-dlp-specialist-2024.2-1.png) ](https://www.credly.com/badges/8249afac-6dfb-48de-8a85-35c96a77bd67/public_url) ![data-privacy-certified-agency-partner](https://milepost42.com/wp-content/uploads/2024/02/data-privacy-certified-agency-partner.png) [ ![proofpoint-certified-phishing-specialist-2024](https://milepost42.com/wp-content/uploads/2024/02/proofpoint-certified-phishing-specialist-2024-300x300.png) ](https://www.credly.com/badges/c3070c0b-1c2f-4cb2-a744-8e78e17f836d/public_url) --- --- title: "Are you ready for the new email authentication requirements?" url: "https://milepost42.com/are-you-ready-for-the-new-email-authentication-requirements/" lang: "en-US" type: "post" description: "I recently read a statistic saying that 85% of emails sent in 2023 were spam. That seems like a lot, but I know I get a lot of spam in my email. Google and Yahoo know that, too. You may" last_modified: "2024-01-18T08:41:29+00:00" categories: [techstuff] --- # Are you ready for the new email authentication requirements? I recently read a statistic saying that 85% of emails sent in 2023 were spam. That seems like a lot, but I know I get a lot of spam in my email. Google and Yahoo know that, too. You may have received messages from your Email Service Provider (ESP) – like Mailchimp, MailerLite, GetResponse, or whatever you use to send your newsletters and marketing emails, letting you know there are new authentication requirements and telling you to take action. **_TLDR: If you want people with Gmail or Yahoo email addresses (and probably Microsoft and others) to receive your emails, you must send from a domain you own and have properly authenticated._** [Want someone else to do the techie work on this?](https://click.pstmrk.it/3s/milepost42.com%3Fmailpoet_router%26endpoint%3Dtrack%26action%3Dclick%26data%3DWyIzMSIsIjMwZGU2MDFjNmU2M2M1NTkzNGUyMTVjMzc3MjUyZTY5IiwiNjAiLCIwYjlmN2M0MTIxMTMiLGZhbHNlXQ/ugOY/JZGyAQ/AQ/f984fe57-5af8-46a1-ae22-9caeb5fb277b/1/FonYkT9Qty) ## So what is this email authentication fuss all about? Google and Yahoo (and Microsoft will probably officially follow suit, although I think they have quietly done some of this already) are adopting some stricter measures on what emails will be allowed in the inbox. Any emails that don’t meet the requirements will likely go to spam, or possibly be rejected completely. Emails will have to be fully authenticated, meaning you must have SPF, DKIM, and DMARC records set up in your domain. That’s a lot of alphabet soup, but basically these are DNS records that need to be set up. ## What do you mean by SPF, DKIM, and DMARC? – SPF (Sender Policy Framework) is the servers that are allowed to send email using your domain name – such as your website, ESP, maybe your invoicing system. – DKIM (Domain Keys Identified Mail) is like a signature for your emails, saying they really came from you and haven’t been tampered with. – DMARC (Domain-based Message Authentication Reporting & Conformance) is like a policy that tells an email provider (e.g. Gmail) that if an email arrives saying it’s from you, but doesn’t match the SPF and DKIM information, here’s what to do with that email. ## More rules… AND, an important thing to know – if you are using a Gmail or another “free” email address to send emails through your ESP, you won’t be able to do that any longer. You can’t authenticate gmail.com or yahoo.com or yourISP.com, since you don’t own those domains. You’ll need to set up your ESP to use an email from a domain YOU OWN and authenticate that domain. There are a number of other rules that will be put in place as well. Some items you can’t do anything about, such as implementing one-click unsubscribe in email headers (this is different than the unsubscribe link IN the email) and ensuring emails are formatted in Internet Message Format Standard; we all have to depend on our ESPs to do that (and I’m sure it’ll start to be noticed which ones don’t). But using your own domain, having it properly authenticated, and keeping the spam rate below 0.3% – that’s all on us. Some of the stricter requirements are only for those who send 5,000+ messages to Gmail addresses, but the authentication requirements have been best practices for years. Using your own domain and having at least SPF or DKIM set up is going to be required for anyone who sends to Gmail addresses (yeah, just about everyone!) ## When will this happen? [Google announced](https://click.pstmrk.it/3s/milepost42.com%3Fmailpoet_router%26endpoint%3Dtrack%26action%3Dclick%26data%3DWyIzMSIsIjMwZGU2MDFjNmU2M2M1NTkzNGUyMTVjMzc3MjUyZTY5IiwiNjAiLCI3MTRkNzdiNTI0Y2UiLGZhbHNlXQ/ugOY/JZGyAQ/AQ/f984fe57-5af8-46a1-ae22-9caeb5fb277b/2/29_qH9RxIt) they will start implementing these requirements in February. [Yahoo has similar requirements](https://click.pstmrk.it/3s/milepost42.com%3Fmailpoet_router%26endpoint%3Dtrack%26action%3Dclick%26data%3DWyIzMSIsIjMwZGU2MDFjNmU2M2M1NTkzNGUyMTVjMzc3MjUyZTY5IiwiNjAiLCI3MWU0ODgxOTEyOTYiLGZhbHNlXQ/ugOY/JZGyAQ/AQ/f984fe57-5af8-46a1-ae22-9caeb5fb277b/3/VZ4ZxH7phu) and will start implementing in February of 2024. Enforcing these email best practices will be good for us all, but I know it can be a little painful to get there. If you don’t want to figure this out yourself, I’m offering a [**service to do the techie part for you**](https://click.pstmrk.it/3s/milepost42.com%3Fmailpoet_router%26endpoint%3Dtrack%26action%3Dclick%26data%3DWyIzMSIsIjMwZGU2MDFjNmU2M2M1NTkzNGUyMTVjMzc3MjUyZTY5IiwiNjAiLCIwYjlmN2M0MTIxMTMiLGZhbHNlXQ/ugOY/JZGyAQ/AQ/f984fe57-5af8-46a1-ae22-9caeb5fb277b/1/FonYkT9Qty). I’ll work with you to figure out your authorized senders, and then I’ll take care of setting up all the records – I’ll even monitor DMARC reports for you for the first 30 days. This is important for anyone who uses email to communicate with customers, but it’s crucial for those who use email marketing. If you have colleagues who need this information or would be interested in this service, please feel free to forward this email. With Google starting implementation as early as 1 Feb, I can’t wait until Valentine’s Day to sweeten the deal, so I’m offering a coupon code for $50 off the setup service. When booking the [Email Authentication Setup service](https://click.pstmrk.it/3s/milepost42.com%3Fmailpoet_router%26endpoint%3Dtrack%26action%3Dclick%26data%3DWyIzMSIsIjMwZGU2MDFjNmU2M2M1NTkzNGUyMTVjMzc3MjUyZTY5IiwiNjAiLCIwYjlmN2M0MTIxMTMiLGZhbHNlXQ/ugOY/JZGyAQ/AQ/f984fe57-5af8-46a1-ae22-9caeb5fb277b/1/FonYkT9Qty), put _**mp42emailauth **_when asked if you have a promotional code, and you’ll get $50 off until 31 Jan 2024. --- --- title: "20 Years of Cybersecurity Awareness Month" url: "https://milepost42.com/20-years-of-cybersecurity-awareness-month/" lang: "en-US" type: "post" description: "As we wrap up the 20th Cybersecurity Awareness Month, let's take a look at this year's themes and reminders on the threats out there and actions we can take to help stay safe online. Passwords One of the themes of" last_modified: "2023-11-01T01:51:28+00:00" categories: [Cybersecurity] --- # 20 Years of Cybersecurity Awareness Month As we wrap up the 20th Cybersecurity Awareness Month, let’s take a look at this year’s themes and reminders on the threats out there and actions we can take to help stay safe online. ## Passwords One of the themes of this year’s Cybersecurity Awareness Month is using strong passwords and a password manager, neither of which is really sufficient without also using multi-factor authentication, which is another of this year’s themes. Why, after 20 years, are we still talking about passwords?? And aren’t passwords going away with the advent of passkeys? The fact is, passwords have been around for decades. They are entrenched in cybersecurity culture, and for most everyday users, protecting their accounts means using a password. Yes, passkeys are more secure, and the hope is eventually they will be the means of choice for accessing accounts, but passwords are likely to be with us for years yet. There is a cost to implementing passkeys as a form of authentication, and while that may be easily absorbed by the big players like Google and Microsoft, not every business has the resources to jump in so quickly. Also, let’s not forget the human factor. As easy as a password manager is to use, not everyone uses one – and even fewer people use MFA unless they have no choice. And believe it or not, not everyone has a smart phone or an easy way to use a hardware token, or even a computer of their own. Requiring passkeys and not allowing the option to use a password has the potential to widen the digital divide. ## Passwords and Multi- Factor Authentication So it’s worth while to remind people of the need to use good passwords, and ideally to pair them with MFA. Dealing with passwords is made a lot easier by using a password manager, but no matter how you manage passwords, be sure not to reuse passwords. Reusing passwords makes it much more likely that your accounts will be hacked – just look at all the data breaches in the news (and think about the ones that don’t make the news). If your password is exposed in a breach, any account that you’ve used that password on is vulnerable. MFA adds an extra layer of protection to your accounts, making it harder for the bad guys to get in. ## Beware of the Phish Another way cybercriminals can get into your accounts or systems is through phishing, which is why another theme for this year’s Cybersecurity Awareness Month is “recognize and report phishing.” Many cyber incidents start with a “phish” – an email, phone call, text, or social media message asking for information or trying to get you to click on a link, which may allow malicious software to download on your machine or steal your information. Red flags to watch for are alarming language which tries to create a sense of urgency that you must respond right away, or links that look suspicious or have misspellings in common domain names. Not all phishing messages have awkward language or misspellings, especially as AI has made it easier to write convincing messages, so be careful of ANY email or message that asks you to click on a link or provide personal or financial information. If you do receive a suspect message, report it. If it’s a business message, follow your company’s reporting procedures. If it’s personal, you can often report suspicious messages to your email provider or to the organization which supposedly sent the message. Finally, delete phishing messages. Don’t reply or click on any links, even an “unsubscribe” link – just delete the message. ## Update Software One of the best ways to stay secure is to update software on your computer, phone, and other devices. Software developers frequently release updates to patch vulnerabilities and fix security issues. Hackers and cybercriminals are continually searching for weaknesses to exploit, so failing to update your software can leave your devices and data exposed to potential threats. Some updates are designed to enhance data protection and privacy. For instance, privacy settings and data encryption methods are frequently improved in updates to safeguard your personal information from potential breaches. Turn on automatic updates where possible. You can usually set your computer, mobile phone, and web browsers to automatically install updates, which can help to keep your devices secure with minimal effort on your part. However, don’t forget about other devices connected to your network – at work or at home. Remember to check for updates on printers, routers, and IoT devices to help stay secure. ## Keep It Up! Cybersecurity Awareness Month promotes good cyber practices and provides information on current threats, but it’s important to stay aware of and practice good cyber hygiene year-round. The infographic below is a good reminder to use all year to help us all stay secure. ![Cybersecurity Awareness Month infographic](https://milepost42.com/wp-content/uploads/2023/10/Cybersecurity-Awareness-Month-2023-Infographic-458x1024.jpg) --- --- title: "Back That Up – Do It!" url: "https://milepost42.com/back-that-up/" lang: "en-US" type: "post" description: "March 31st, World Backup Day! Well, really every day should be Backup Day, but if you've been living on the edge, today is the day to back up and get a plan together to guard against potential mishaps. No one" last_modified: "2023-03-31T03:14:28+00:00" categories: [Cybersecurity] --- # Back That Up – Do It! March 31st, [World Backup Day](https://www.worldbackupday.com/)! Well, really every day should be Backup Day, but if you’ve been living on the edge, today is the day to _back up_ and get a plan together to guard against potential mishaps. No one wants to live through a disaster like [accidentally deleting most of Toy Story 2](https://thenextweb.com/news/how-pixars-toy-story-2-was-deleted-twice-once-by-technology-and-again-for-its-own-good).  (“Unplug the machine!”) **So, you’re ready to back it up – what steps should you take?** ## What’s Important To You? First, identify what you need to back up. Stuff like your accounting data, important documents, and the photos of your cat, because be honest, those are the most important files on your computer. Seriously, back up anything you really don’t want to lose. For a business, you’re going to have financial data, legal data, customer information, a lot of information needed to operate and serve your customers. We also have important data at home, probably financial data also, documents, music, and photos that hold our precious memories (of our cats and other things). ## Use The Rule Of Three Then, determine the means and a schedule for backing up. A true backup strategy should use the [“rule of three” for backups:](https://www.backblaze.com/blog/the-3-2-1-backup-strategy/) - Keep 3 copies of any important file – 1 primary and 2 backups - Keep backups in 2 different formats/media types - Keep (at least) 1 copy offsite Some options are to back up important data to an external hard drive or network attached storage device, and also to a cloud service, such as BackBlaze, or using offsite storage such as OneDrive or Google Drive. If you store your primary copies in the cloud – for example, you may keep documents in Google Drive for your team to collaborate on, or use web-based email services – then consider backing up your cloud data in a secure location as well. If you have a website, your web files and database information also need to be backed up in multiple locations. ## Test, Test, Is This Thing On? Finally, test your backups! A backup does you no good if you can’t easily restore it, or worse, if it’s corrupted and you can’t retrieve the data you need. Remember the Colonial Pipeline debacle? When ransomware hit, Colonial Pipeline tried to restore using their backups, but operations stopped for days and they ended up [paying an over $4M ransom to be able to get operations back online – and no one knows how much data was actually lost](https://www.bocada.com/company/blog-news/data-protection-learnings-colonial-pipeline-ransomware/#:~:text=Backup%20policies%20that%20call%20for%20partial%20backups%2C%20or,types%20of%20procedures%20may%20not%20have%20been%20sufficient.). So there you have it, some tips to help you celebrate World Backup Day. Remember, backing up your data might not be the most thrilling activity, but it’s certainly one of the most important. So, take some time today to make sure your data is safe and secure. Happy World Backup Day! --- --- title: "State of WordPress Security Whitepaper Shows 328% Increase in Security Bugs" url: "https://milepost42.com/state-of-wordpress-security-whitepaper-328-increase-in-security-bugs/" lang: "en-US" type: "post" description: "According to Patchstack's State of WordPress Security In 2022 whitepaper, there was a 328% increase in WordPress security bugs last year. But don't panic! This doesn't mean WordPress is less secure; in fact, this indicates there are lots of folks" last_modified: "2023-03-10T21:49:10+00:00" categories: [Cybersecurity] --- # State of WordPress Security Whitepaper Shows 328% Increase in Security Bugs According to Patchstack’s [State of WordPress Security In 2022 whitepaper](https://patchstack.com/whitepaper/wordpress-security-stats-2022/), there was a 328% increase in WordPress security bugs last year. But don’t panic! This doesn’t mean WordPress is less secure; in fact, this indicates there are lots of folks out there hunting these issues down to keep WordPress site users MORE secure. But it does require YOU to take action to keep your plugins, themes, and WordPress core software updated. Patchstack reports that 42% of websites have at least 1 current vulnerable software component installed. That’s like leaving your back window open to a thief. > 42% of websites have at least 1 current vulnerable software component installed Okay, so you’re keeping an eye on your site and updating plugins and themes and WordPress whenever you get a notification. But what about the 26% of plugins with security vulnerabilities that didn’t get patched? Are you regularly monitoring this “threat intelligence” to ensure you aren’t running a plugin or theme that’s “up to date” but still vulnerable?  These abandoned software components are a silent threat to website owners who may not even be aware they are running insecure software. Software supply chain vulnerabilities are also an issue.  Just like the economy, open source software like WordPress is dependent on a supply chain consisting of code libraries and frameworks.  Vulnerabilities in those libraries can have cascading effects on security, [such as that found in the Freemius framework](https://wpscan.com/vulnerability/6dae6dca-7474-4008-9fe5-4c62b9f12d0a?__cf_chl_tk=_oJBOyP3vkT33geyQ_AOJjTD5vum3M2y_nosK6dHmkI-1678483896-0-gaNycGzNCyU), which is used in a number of plugins and themes.  As Patchstack’s white paper says: > The good news was hundreds of plugins that were notified of the security bug in Freemius updated their project’s code and patched the bug. The bad news was dozens to hundreds of projects did not respond to the notifications. While the numbers and threats seem alarming, Patchstack takes an optimistic view of security for the coming year.  With security researchers and developers working together to find and fix vulnerabilities, and continued awareness and action from website owners to keep their sites up to date, the WordPress ecosystem will continue to grow safer. Check out [Patchstack’s whitepaper on the State of WordPress Security](https://patchstack.com/whitepaper/wordpress-security-stats-2022/). And if you need someone to help keep your site updated, running well, and secure, give Milepost 42 a shout! --- --- title: "Google Analytics 4 Setup" url: "https://milepost42.com/google-analytics-4-setup/" lang: "en-US" type: "page" last_modified: "2022-08-04T22:09:13+00:00" --- # Google Analytics 4 Setup --- --- title: "Disclaimer" url: "https://milepost42.com/disclaimer/" lang: "en-US" type: "page" description: " " last_modified: "2022-07-13T18:44:26+00:00" --- # Disclaimer   --- --- title: "Love Is Blind – Keep Your Eyes Open To Avoid Romance Scams" url: "https://milepost42.com/avoid-romance-scams/" lang: "en-US" type: "post" description: "Ever hear Brad Paisley's song about the short, chubby, \"hero\" who's \"so much cooler online\"?  The internet makes it easy for people to pretend to be something they're not.  And today's online dating landscape has made it easy for some" last_modified: "2024-02-03T01:39:17+00:00" categories: [Cybersecurity] --- # Love Is Blind – Keep Your Eyes Open To Avoid Romance Scams Ever hear Brad Paisley’s song about the short, chubby, “hero” who’s “so much cooler online”?  The internet makes it easy for people to pretend to be something they’re not.  And today’s online dating landscape has made it easy for some cyber criminals to take advantage of people looking for love. Romance scams, where someone is tricked into believing they’re in a caring relationship with someone who is really just out to steal their money or information, are a growing problem.  In fact, during the first half of 2021, [the FBI Internet Crime Complaint Center (IC3) received over 1,800 complaints related to online romance scams, resulting in losses of approximately $133.4 million](https://www.ic3.gov/Media/Y2021/PSA210916). Sometimes romance scams are part of a larger cybercriminal ecosystem. [International cyber gangs sometimes use dating sites to recruit victims as “money mules” and use them to unknowingly launder funds.](https://www.aarp.org/money/scams-fraud/info-2019/romance.html) Scammers often prey on victims who are lonely or isolated, and the lockdowns and closings in response to the COVID-19 pandemic have created a fertile ground for this loneliness.  If you or a loved one has started an online relationship, be sure to check for red flags such as: - Requests for money, especially urgent requests.  Scammers may try to pressure you into sending money for “urgent” matters, such as medical expenses. Or they may say they want to visit you in person, but need money for a plane ticket.  Never send money to someone you haven’t met in person. - They often make and break promises to come see you in person. The person claims to live far away, overseas, or be in the military. - The relationship is moving fast and the person professes love quickly. - They pressure you to move the conversation off the dating platform to a different site or want to continue the conversation through text. Dating platforms search for scammers on their sites. Scammers will want to move their victims off-platform to avoid detection. If you think you or someone you care about may be the victim of a scam: - Stop communications with the scammer immediately, and take note of any identifiable information you may have on them, such as their email address. - Contact your bank or credit card company if you’ve given them money. - File a police report with your local precinct. - Report the scammer to the FTC at [gov/complaint](http://ftc.gov/complaint) and the FBI at [ic3.gov](https://ic3.gov)[.](https://ic3.gov/) - Notify the website or app where you met the scammer. Romance scams can happen to anyone at any age, and falling for a scam is nothing to be ashamed of. By speaking out, reporting scams, and encouraging others to do the same, you can help protect others from becoming victims. Learn more about how to protect yourself from romance scams and other threats at [https://staysafeonline.org/stay-safe-online/](https://staysafeonline.org/stay-safe-online/). --- --- title: "3 Internet Safety Mistakes That Get You Hacked" url: "https://milepost42.com/3-internet-safety-mistakes-that-get-you-hacked/" lang: "en-US" type: "post" description: "Just as personal hygiene can protect you from disease (wash your hands), practicing good cyber hygiene can help protect you from internet nasties.  Here are 3 common mistakes that compromise your internet safety, along with advice on what you can" last_modified: "2024-10-23T20:46:43+00:00" categories: [Cybersecurity] --- # 3 Internet Safety Mistakes That Get You Hacked In 2005, the [U.S. Senate designated June as National Internet Safety Month,](https://www.govinfo.gov/content/pkg/BILLS-109sres147ats/html/BILLS-109sres147ats.htm) as “an opportunity to educate the people of the United States on the dangers of the Internet and the importance of being safe and responsible online.”  While the resolution was born from the recognition that children were increasingly online, the need to understand internet safety extends to all of us – and it’s even more important today than 15 years ago. Just as personal hygiene can protect you from disease (wash your hands), practicing good cyber hygiene can help protect you from internet nasties.  Here are 3 common mistakes that compromise your internet safety, along with advice on what you can do to protect yourself. ## Internet Safety Mistake 1 – Reusing Passwords [A 2018 study by researchers at Virginia Tech University](https://people.cs.vt.edu/gangwang/pass) revealed that an alarming 52% of users reuse passwords on different services – and the MOST reused passwords were for sensitive sites, like email or shopping sites.  Not only that, many people were still reusing the same passwords even after the credentials had been leaked in a data breach. Wonder if your password has been exposed?  Check [Have I Been Pwned?](https://haveibeenpwned.com/) to see if your account has been involved in any of the numerous data breaches reported over the last several years. ### Why it’s a problem: Suppose you’ve set up a really strong password – no dictionary words, you’ve used a passphrase to establish an 18 character password with various alphanumeric characters and even a special character or two. That’s great. But if you use your special strong password for your bank, and your email, and your social media account, and one of those is hacked, all the other services where you use that password are at risk. ### What you should do: Using a strong password is great, and still important.  But the best password in the world is of no use if it’s been exposed in a data breach.  Use a password manager to help you create and manage strong, unique passwords for the many systems you use.  And use two-factor authentication as an extra layer of protection for your most sensitive accounts, like banking or email. ## Internet Safety Mistake 2 – Not Updating You probably get update notifications on your computer or your phone.  Maybe you have them set to auto-update, or maybe you prefer to have control over when an update is done, since you’ve heard of problems happening with updates.  But do you always make sure the updates are done in a timely manner?  You probably have other software on your computer, not just the operating system.  Those programs often get updates as well, but they may require you to log in to apply the update. What about the other internet-connected items in your home?  When is the last time you updated the firmware on your wireless router?  Many smart devices get updates as well, usually automatically, but sometimes an update is interrupted – you should check to be sure all updates are applied. ### Why it’s a problem: Software updates are done either to add new features or to plug security holes.  Technology is constantly changing, and new vulnerabilities are discovered all the time; reputable companies do their best to stay on top of this and issue updates or “patches” to fix security issues. Failure to do updates and apply patches is one of the top reasons for data breaches, and this applies to your home systems as well as to big companies.  [In 2018, a major cyberattack was launched targeting small office and home routers](https://www.ic3.gov/media/2018/180525.aspx); it allowed bad actors to steal website credentials, extract information, and block network traffic.  Most vendors created patches, but routers usually require you to do a manual update. ### What you should do: Be aware of all the connected devices you have – definitely your smart phone and computer, but also think about your router, your smart TV, streaming devices, smart speakers, home control hubs, even your smart watch.  If you have a small business, don’t forget about your connected printer, your website, and your file servers. Establish a process to regularly check for updates on all your devices and for the software running on those devices, especially if you don’t have auto-updates. Remember to check for updates on all the software running on your computer.  [CCleaner Pro](https://www.ccleaner.com/ccleaner/professional) is one program that can help you with this; it can check for outdated software on your computer and in many cases update it for you. ## Internet Safety Mistake 3 – Using Public WiFi Have you ever connected to the “free WiFi” offered at your favorite coffeeshop?  Or perhaps you travel for business, or vacation, and use the airport or hotel WiFi.  Careless use of public WiFi is one of the biggest mistakes people make when on the go.  While having access to WiFi can be very convenient, it comes with a significant security risk. ### Why it’s a problem: Very often, free WiFi offered in public spaces is completely open, with no password or protection at all.  A hacker can set up a wireless “sniffer”, which can read all the data you send over that network, such as user names and passwords. Also, it’s easy for a hacker to set up an inexpensive device and pretend to be a legitimate wireless access point.  When you log in to that “FreeAndOpenWiFi” network at the hotel or airport, are you sure it’s really the right network?  It could be a bad guy out in the parking lot, who can now view everything you are doing on your laptop or phone. ### What you should do: [SurfShark has a great resource explaining the risk of public wifi and what you can do to protect yourself](https://surfshark.com/wifi-security).  A couple of quick things to remember: When using public WiFi, always check with the venue to make sure you’re logging in to the REAL network – and make sure it has at least basic encryption and requires a password. Even when you’re sure it’s the right network, take precautions to protect the information you’re sending over the WiFi network.  It’s best not to do any sensitive business while using public WiFi – for example, don’t log in to your bank using the airport WiFi.  If you must use public WiFi, use a VPN service on your laptop or mobile device to encrypt the data you send and keep it safe from cyber thieves. ## Don’t make these internet mistakes! Protect your passwords, update regularly, and be extra careful if you use public WiFi.  Keep yourself safe by staying aware of risks and practicing good cyber hygiene! --- --- title: "Don’t Trust, But Verify – Protect Yourself From Internet Crime" url: "https://milepost42.com/dont-trust-verify-protect-against-internet-crime/" lang: "en-US" type: "post" description: "You may have heard the quote, \"Trust, but verify,\" (made famous by Ronald Reagan), but based on the information in the FBI Internet Crime Complaint Center's 2019 Internet Crime Report, you'd do better to verify first. According to the FBI," last_modified: "2024-02-09T00:43:55+00:00" categories: [Cybersecurity] --- # Don’t Trust, But Verify – Protect Yourself From Internet Crime You may have heard the quote, “Trust, but verify,” (made famous by Ronald Reagan), but based on the information in the FBI Internet Crime Complaint Center’s [2019 Internet Crime Report](https://pdf.ic3.gov/2019_IC3Report.pdf), you’d do better to verify first. According to the FBI, 2019 had both the highest number of complaints and the highest financial losses since the IC3’s beginning in 2000 – 467,361 reported complaints and over $3.5 _billion _ lost. ## Internet Crime – Where The Money Is With financial losses due to internet crime at the highest levels ever, what are the areas where fraudsters are causing the most damage? ### Email Compromise Nearly half the losses reported were due to Business Email Compromise (BEC) or Email Account Compromise (EAC).  This is a scam in which a cyber criminal hacks or spoofs a legitimate email account and convinces the recipient of the email to transfer funds to a fraudulent location. For example, [consider this BEC fraud attempt](https://firstbusiness.com/resource-center/business-email-compromise-fraud-3-real-case-studies/), in which First Business Bank received an email from the business email address of the CEO of a business client, requesting a $15,850.00 wire transfer.  The bank employee emailed a blank wire request form, and received a return email with the completed form, including the CEO’s matching signature.  The fraud was discovered when the wire desk did additional authentication by calling the client’s phone number of record. Unfortunately, a woman in Spokane was not so lucky when she [fell victim to EAC during the process of buying her dream home](https://www.krem.com/article/news/investigations/spokane-woman-to-down-payment-scammer-you-cannot-make-your-livelihood-on-the-tears-of-other-people/293-7b4d0017-0cd6-4f60-820a-dbecedb33d3c).  A 75 year old woman lost her life savings of almost $100,000 when she followed emailed wire transfer instructions that appeared to be from her escrow officer.  Sandra Lee lost her money and her home, and her only consolation is that the FBI was able to track down one perpetrator with the report and evidence she provided. ### Elder Fraud Sadly, Lee was also in the age group that loses the most to fraudsters – those over 60.  These internet criminals prey on those over 60, since they are believed to have financial resources, as well as being more trusting and less tech savvy. Elder Fraud, defined as a financial fraud which targets or disproportionately affects people over the age of 60, is a growing problem.  According to the statistics in the report, this age group is the most targeted and the group which loses the most to internet crime. ![chart showing internet crime victims by age group](https://milepost42.com/wp-content/uploads/2020/02/victims-by-age-group.jpg) _IMAGE: FBI’s 2019 Internet Crime Report_ Those over 60 are also the most victimized by another growing problem, Tech Support Fraud.  This is a scam in which a criminal pretends to be a customer service or support technician in order to defraud a victim.  The infamous computer pop-up claiming “your computer is infected by a virus” is one example, as are calls, texts, or emails purporting to be from a well-known company such as Apple or Microsoft, claiming to have discovered a problem with your system or account and offering to “help” you resolve it.  While not the most lucrative or most prevalent scheme, losses due to Tech Support Fraud increased 40 percent in 2019, and the majority of victims were in the over 60 age group. ## Phishing/Vishing/Smishing/Pharming While BEC/EAC accounts for the majority of financial losses, it’s not the most prevalent scheme.  The most common internet crime type by far, with 114,702 reported victims, is Phishing/Vishing/Smishing/Pharming. ![chart showing internet crimes by type](https://milepost42.com/wp-content/uploads/2020/02/crime-types.jpg) _IMAGE: FBI’s 2019 Internet Crime Report_ Phishing, vishing, and smishing involve unsolicited emails, phone calls, or text messages from criminals pretending to be a legitimate company or even a friend, and asking for login credentials or personal information.  Pharming is a tactic which uses a fake website pretending to be a legitimate company’s website, set up for the purpose of obtaining personal or financial information. For example, you may get an email, phone call, or text purporting to be from your bank, telling you that your account has been compromised and asking you for personal information to confirm your identity.  Or you may search for something online and find yourself on a fraudulent site which collects your credit card information. ## How Can You Protect Yourself From Internet Crime? With both victims and losses from internet crime at an all-time high, what can you do to protect yourself? ### Verify We can no longer “trust, but verify” – the best preventive measure is to verify first.  The Chief of IC3, Donna Gregory, cautions that [internet crime is becoming increasingly sophisticated](https://www.fbi.gov/news/stories/2019-internet-crime-report-released-021120), and she recommends we make a practice of double-checking everything. Gregory advises, “In the same way your bank and online accounts have started to require two-factor authentication, apply that to your life. Verify requests in person or by phone, double-check web and email addresses, and don’t follow the links provided in any messages.” ### Report Internet Crime The IC3 report includes some appalling numbers on victims and losses due to internet crime, but it’s likely this is only the tip of the iceberg.  Many victims don’t report these crimes, either because they are embarrassed or they aren’t aware of how to do so. If you’re a victim of internet crime, [report the crime to the IC3](https://www.ic3.gov/).  With timely reporting, the FBI has a chance of stopping a fraudulent transaction and recovering the money.  And the more information you can provide, the better it helps the FBI combat the criminals.  Matt Gorham, assistant director of the FBI’s Cyber Division, encourages everyone to report internet crime, as “It is through these efforts we hope to build a safer and more secure cyber landscape.” --- --- title: "National Cybersecurity Month Wrap-Up" url: "https://milepost42.com/national-cybersecurity-month-wrap-up/" lang: "en-US" type: "post" description: "It's the last day of October, which means this year's National Cybersecurity Month is officially ending.  But that doesn't mean you should stop taking measures to #StayCyberSafe!  This year, the NCSAM theme was \"Own IT, Secure IT, Protect IT\" -" last_modified: "2019-11-01T04:52:39+00:00" categories: [Cybersecurity] --- # National Cybersecurity Month Wrap-Up It’s the last day of October, which means this year’s National Cybersecurity Month is officially ending.  But that doesn’t mean you should stop taking measures to #StayCyberSafe!  This year, the NCSAM theme was “Own IT, Secure IT, Protect IT” – let’s take a look at some of the tips that were presented this month.   ## Own IT We’re almost constantly connected, whether at home, at work, at school, or even on vacation.  With mobile phones and Internet of Things devices, there are more ways to be connected than ever before.  Not only that, we also have many accounts which collect our information. - Don’t overshare on social media.  #BeCyberSmart about where you share your information and who you share it with.  Connect only with people you know and trust. - Set privacy and security settings to limit what your devices and social media accounts share about you. - Keep tabs on your apps; only download from legitimate, trusted sources.  Review the permissions those apps are asking for, and deny any that don’t make sense.   ## Secure IT Security breaches seem to be happening more and more often; they’re hardly front page news any more.  Your personal information is valuable, so do what you can to keep it out of the hands of cyber criminals. - Use strong passwords, and don’t use the same password on multiple accounts.  A password manager can help you keep track of all those strong, unique passwords for your accounts.  Some can even help you share access with trusted partners or family members, without requiring you to give them the password. - No matter how strong your password is, if a breach occurs, your account may be vulnerable.  Enable multi-factor authentication to add another layer of security and help ensure the only person who can access your account is you. - Don’t get hooked by a phishing scam!  Be very cautious when opening emails, and never click on links or attachments sent by people you don’t know.  Even if the email looks like it’s from a friend, coworker, or your boss, be wary of clicking on links.  Scammers can spoof email addresses, so it’s best to check the legitimacy of the email, especially if it’s urging you to click or open something right away.   ## Protect IT While today’s technology allows us to shop, bank, communicate, and entertain ourselves anywhere, this convenience comes with an increased risk.  Smart home devices, such as thermostats, door locks, and cameras can make our lives easier and save time and money, but be aware of the additional security risk that comes with these smart devices. - Your wireless router is the main entryway to all your connected devices, so be sure to change the default user name and password, keep the firmware up to date, and set a password on your Wi-Fi network.  Also, change the default credentials on all your smart devices, and make sure you understand the permissions and access they have to your network, your information, and your personal space.  Assume a smart speaker is always listening, and a smart camera is always watching. - Keep software and firmware on all your devices up to date.  Your computer, smart phone, router, and many smart home devices get updates to help keep them protected from ever-changing threats.  If you have an older device, make sure it’s still being supported; sometimes, it’s just time to get rid of that old streaming device to help protect the rest of your home. - Public Wi-Fi is not safe or secure.  Even a public Wi-Fi network with a password could be compromised.  If you must use public Wi-Fi, be sure it’s the actual network provided by the location.  Use a VPN service to protect the privacy of the information you’re sending, and avoid accessing sensitive accounts such as financial and banking accounts while on public Wi-Fi. As we move into the holiday season and the new year, keep these cyber security tips in mind.  OWN IT, Secure IT, and Protect IT to keep yourself and your family #CyberSafe. --- --- title: "Don’t Worry, Be (Safely!) Appy" url: "https://milepost42.com/dont-worry-be-safely-appy/" lang: "en-US" type: "post" description: "There's an app for that! Nowadays, it seems like there really is an app for everything — games, shopping, fitness, hobbies, and more. No wonder almost 50% of all smartphone users download at least one new app a month. But" last_modified: "2024-01-18T08:42:01+00:00" categories: [Cybersecurity] --- # Don’t Worry, Be (Safely!) Appy There’s an app for that! Nowadays, it seems like there really is an app for everything — games, shopping, fitness, hobbies, and more. No wonder almost 50% of all smartphone users download at least one new app a month. But it’s important to choose and use your apps carefully. Some apps may be scams or contain viruses. What can you do to keep yourself safe? ## Beware Permissions Any time you install an app, it’ll ask you to allow it permission to access functions of your device — stuff like the camera, location data, and contacts list. But should a fitness app need to use your camera, or a game need to know who you call? Click “Deny” to keep an app from getting certain permissions. ## Source Smart Stick to the official sources for your apps. Research before you buy or download, and only install apps from a reputable developer. The Apple App Store and Google Play have standards for what apps they include, and something from the official store is less likely to cause problems for you – but still be cautious! ## Spot The Scam Check out the reviews and information about the app. If there are a lot of high ratings, but no actual reviews, or if the reviews appear suspiciously similar or low quality, it could be a scam. Also, look for information on the developer – if there’s little information, no responses, and no indication that the developer is supporting the app, think twice (or three times) about installing it. ## Vaccinate Your Device Make sure all your devices have antivirus and/or antimalware software installed. That way, even if you download a malicious app, or an app you’ve bee using for a while becomes a problem, you have another layer of defense to help secure your device. Follow the app safety advice in this infographic from INFOSEC – stay safe and “appy”! ![INFOSEC infographic about app safety](https://milepost42.com/wp-content/uploads/2019/10/INFOSEC-App-infographic.jpg) --- --- title: "Milepost 42 Will Promote Online Safety As A National Cybersecurity Awareness Month Champion" url: "https://milepost42.com/milepost-42-will-promote-online-safety-as-a-national-cybersecurity-awareness-month-champion/" lang: "en-US" type: "post" description: "Milepost 42 is honored to join an initiative to promote awareness of online safety and privacy, by signing up as a Champion of National Cybersecurity Awareness Month (NCSAM) 2019. NCSAM is a collaborative effort among businesses, government agencies, colleges and" last_modified: "2019-09-26T02:19:43+00:00" categories: [Cybersecurity] --- # Milepost 42 Will Promote Online Safety As A National Cybersecurity Awareness Month Champion Milepost 42 is honored to join an initiative to promote awareness of online safety and privacy, by signing up as a [Champion of National Cybersecurity Awareness Month (NCSAM) 2019](https://staysafeonline.org/ncsam/champions/view-all/). NCSAM is a collaborative effort among businesses, government agencies, colleges and universities, associations, nonprofit organizations and individuals committed to this year’s NCSAM theme of “Own IT. Secure IT. Protect IT”, and this year’s initiative will encourage everyone to #BeCyberSmart through cybersecurity best practices. > _30 years ago, the world wide web was just getting started. Today, we can access information almost instantly, from a device that fits in a pocket. We have technology in almost every aspect of our lives. And just like in all the other parts of our lives, we need to protect and secure the things we own._ ~ Stacy Clements, Owner of Milepost 42 Now in its 16th year, NCSAM continues to build momentum and impact with the ultimate goal of providing all Americans with the information they need to stay safer and more secure online. [Organization name] is proud to support this far-reaching online safety awareness and education initiative which is co-led by the National Cyber Security Alliance (NCSA) and the Cybersecurity and Infrastructure Agency (CISA) of the U.S. Department of Homeland Security. “Cybersecurity is important to the success of all businesses and organizations. NCSA is proud to have such a strong and active community helping to encourage proactive behavior and prioritize cybersecurity in their organizations,” said Kelvin Coleman, executive director, NCSA. For more information about NCSAM 2019 and how to participate in a wide variety of activities, visit staysafeonline.org/ncsam. You can also follow and use the official NCSAM hashtag #BeCyberSmart on social media throughout the month. ### About Milepost 42 [Milepost 42](https://milepost42.com/) is a technology partner for small business owners who want to focus on their passion and not the “techie stuff” needed to support it.  Small businesses need technology –websites, email, automation – to run and grow, and they also need to be aware of the need for cybersecurity to ensure business continuity.  Milepost 42 provides those services and planning assistance for small business owners who are ready to have someone else handle the “web stuff”.** ** ### About National Cybersecurity Awareness Month NCSAM is designed to engage and educate public- and private-sector partners through events and initiatives with the goal of raising awareness about cybersecurity to increase the resiliency of the nation in the event of a cyber incident. Since the Presidential proclamation establishing NCSAM in 2004, the initiative has been formally recognized by Congress, federal, state and local governments and leaders from industry and academia. This united effort is necessary to maintain a cyberspace that is safer and more resilient and remains a source of tremendous opportunity and growth for years to come. For more information, visit [staysafeonline.org/ncsam](http://staysafeonline.org/ncsam) or [niccs.us-cert.gov/national-cybersecurity-awareness-month-2019](http://niccs.us-cert.gov/national-cybersecurity-awareness-month-2019). ### About NCSA NCSA is the nation’s leading nonprofit, public-private partnership promoting cybersecurity and privacy education and awareness. NCSA works with a broad array of stakeholders in government, industry and civil society. NCSA’s primary partners are the Cybersecurity and Infrastructure Security Agency and NCSA’s Board of Directors, which includes representatives from ADP; American Express; Bank of America; CDK Global, LLC; CertNexus; Cisco; Cofense; Comcast Corporation; Eli Lilly and Company; ESET North America; Facebook; Google; Infosec; Intel Corporation; Marriott International; Mastercard; Microsoft Corporation; Mimecast; NXP Semiconductors; Proofpoint; Raytheon; Symantec Corporation; Trend Micro, Inc.; Uber: U.S. Bank; Visa and Wells Fargo. NCSA’s core efforts include National Cybersecurity Awareness Month (October); Data Privacy Day (Jan. 28); STOP. THINK. CONNECT.™, the global online safety awareness and education campaign co-founded by NCSA and the Anti-Phishing Working Group with federal government leadership from the Department of Homeland Security; and CyberSecure My Business™, which offers webinars, web resources and workshops to help businesses be resistant to and resilient from cyberattacks. For more information on NCSA, please visit [https://staysafeonline.org/about/](https://staysafeonline.org/about/). --- --- title: "Contact" url: "https://milepost42.com/contact/" lang: "en-US" type: "page" description: "Contact Send A Message" last_modified: "2024-01-18T03:37:48+00:00" custom_fields: site-post-title: "disabled" site-sidebar-layout: "no-sidebar" site-content-layout: "page-builder" ast-featured-img: "disabled" theme-transparent-header-meta: "default" ast-title-bar-display: "disabled" astra-main-page-id: 38774 ast_self_id_38774: 1 --- # Contact # Contact ### Send A Message [wpforms id=\”6\”] --- --- title: "Presentations" url: "https://milepost42.com/presentations/" lang: "en-US" type: "page" last_modified: "2020-02-10T20:52:51+00:00" --- # Presentations _ ### Cybersecurity For Small Business – WBC Lunch Series _ 1 file(s) __ 3.63 MB Download [wps_download file=”cybersecurity-for-small-business-wbc-lunch-series-19-jul-2019″] --- --- title: "Stay Safe While Shopping Online" url: "https://milepost42.com/stay-safe-while-shopping-online/" lang: "en-US" type: "post" description: "Summer is here! Kids are out of school, and maybe you have a vacation planned - but cybercriminals never take a holiday. Whether you're booking a hotel room, buying concert tickets, picking up stuff for your garden, or taking advantage" last_modified: "2019-07-08T18:27:04+00:00" categories: [Cybersecurity] --- # Stay Safe While Shopping Online ![online shopping with hands reaching through screens](https://milepost42.com/wp-content/uploads/2019/07/online_shopping-1024x438.jpg) Summer is here! Kids are out of school, and maybe you have a vacation planned – but cybercriminals never take a holiday. Whether you’re booking a hotel room, buying concert tickets, picking up stuff for your garden, or taking advantage of summer clothing sales, stay vigilant when making online purchases. Several years ago, most people made very few online purchases. Now, Amazon Prime Day(s) are touted almost as much as holidays, and some people buy almost everything online. You can make purchases, and even pay, with your mobile phone. The downside of this convenience is that it gives cyber thieves more ways to get into your wallet. But just like there are ways to protect yourself when in a crowded place that may harbor pickpockets, there are ways to protect yourself from the cyber bag snatchers. CouponChief has put together an [Online Shopping Safety Guide](https://www.couponchief.com/guides/online_shopping_safety) to educate consumers on security concerns and provide some tips on what you can do to protect yourself.  Give it a read, and enjoy your summer shopping, safely! --- --- title: "World Password Day 2019" url: "https://milepost42.com/world-password-day-2019/" lang: "en-US" type: "post" description: "Happy #WorldPasswordDay!  The first Thursday of May is designated World Password Day, and it's intended to promote better password habits to help safeguard our digital identities.  With cybercrime on the rise and data breaches becoming almost commonplace, it's more important" last_modified: "2021-03-25T15:40:44+00:00" categories: [Cybersecurity] --- # World Password Day 2019 ![keyboard with key on top](https://milepost42.com/wp-content/uploads/2019/05/close-up-key-keyboard-39389-1024x685.jpg) **Happy #WorldPasswordDay! ** The first Thursday of May is designated World Password Day, and it’s intended to promote better password habits to help safeguard our digital identities.  With [cybercrime on the rise](https://www.fbi.gov/news/stories/ic3-releases-2018-internet-crime-report-042219) and data breaches becoming almost commonplace, it’s more important than ever to protect these keys to our kingdoms.  Take a moment today to review these tips to secure access to your accounts. ## Use Strong Passwords You know this…but do you follow this advice?  A [recent study](https://www.ncsc.gov.uk/news/most-hacked-passwords-revealed-as-uk-cyber-survey-exposes-gaps-in-online-security) of hacked accounts showed that 23.2 million victim accounts used 123456 as the password.  Make your passwords strong  – a combination of upper and lower case letters, numbers, and special characters is best. Use a minimum of 12–15 characters – longer is better!  **Length is even more important** than complexity, and long “pass phrases” can actually be easier to remember.  Don’t use easy-to-guess information, such as birthdays, sports teams, or band names, and don’t use dictionary words. ## Don’t Use The Same Password On Different Systems When you’ve picked out a great strong passphrase, it’s tempting to use it everywhere.  Don’t do it!  Even the strongest password does you no good if it’s been exposed in a data breach.  Cyber criminals often take passwords gleaned from a breach, and try the credentials on other systems.  If your social media account is compromised, and you use the same password and email address for your bank account…well, that’s a problem you don’t need. Web security expert Troy Hunt created a great free resource which collects data on known breaches to help people assess whether their information may be at risk.  Check out [Have I Been Pwned](https://haveibeenpwned.com/) to see if any of your accounts have been compromised in a data breach.  (Spoiler:  the answer is probably yes!) > [LastPass]( https://lastpass.sjv.io/xX6eO) is a great password management tool for you, your family, or for a business team. _(Disclosure: This is an affiliate link, which means I may get a small commission if you purchase through this link. There is no extra charge to you and there is no requirement to purchase through this link to get the latest deal.)_ ## Use A Password Manager So, I’m supposed to use long, strong passwords, and different passwords for everything – **how am I supposed to remember all this**?  If you follow best practices for passwords, it’s impossible to remember and keep track of them all – this is where password managers come in. A good password manager will securely store unique login credentials for all your different accounts.  You only need to remember the master password to the password management tool itself.  Features vary depending on the tool you choose, but many password managers allow you to autofill using a browser extension (be cautious!), sync passwords to use on desktop and mobile devices, help you change passwords on your accounts, and generate strong passwords to help keep your accounts secure. Most password managers are relatively inexpensive, and many have free versions that may work for you.  I personally use [LastPass](https://www.lastpass.com/hp), but it doesn’t matter what you use, just use one! ## #LayerUp Your Login Yes, it’s World Password Day, and since passwords are still the most prevalent way of protecting an account, we need to follow good password practices.  However, **the best password in the world is useless if it’s been exposed in a data breach**.  The theme for [this year’s World Password Day is #LayerUp](https://www.passwordday.org/) – further protect your login by using multi-factor authentication (also known as two-factor authentication). Multi-factor authentication adds another layer of protection to your accounts by requiring an extra step, such as entering a code sent to your phone, a code generated by an authentication app on your mobile device, or authentication with a separate hardware key.  This may seem a little inconvenient, but it’s a lot less hassle than trying to get your money back if your bank account is hacked or having to cancel your credit card after a major data breach. Most major companies now have the option to turn on two-factor authentication to help prevent fraudulent access and add additional protection to your account.  You can [learn more about multi-factor authentication and how to enable it in this guide from Pixel Privacy.](https://pixelprivacy.com/resources/two-factor-authentication/) Your personal information is valuable – protect it!  Take a moment to celebrate #WorldPasswordDay by **reviewing your accounts for strong passwords**, and **enabling multi-factor authentication** on your most important accounts.  #LayerUp and stay safe online! --- --- title: "Shared Hosting: GreenGeeks" url: "https://milepost42.com/shared-hosting-greengeeks/" lang: "en-US" type: "post" description: "Disclosure:  This post includes affiliate links to the recommended service, which means if you click on the link and make a purchase, I may receive a commission or bonus.  All my reviews and recommendations are based on my personal experience" last_modified: "2019-03-14T17:04:53+00:00" categories: [Milepost 42 Recommends] --- # Shared Hosting: GreenGeeks _Disclosure:  This post includes affiliate links to the recommended service, which means if you click on the link and make a purchase, I may receive a commission or bonus.  All my reviews and recommendations are based on my personal experience with the product or service._ As a technical consultant and service provider for small businesses, I’m often asked to recommend a shared web hosting provider.  Although I strongly feel that a business should use cloud-based or VPS (or even dedicated) web hosting, shared hosting can be appropriate for a freelancer, blogger, or a business just starting out and testing the waters. However, it’s tough to find a quality shared hosting option.  Certain large companies with big marketing budgets saturate the advertising space, and they historically have subpar performance and less-than-stellar reputations.  From my experience with several of these companies, that poor reputation is deserved.  While some deliver adequate performance for small, low-traffic sites, the security measures for these low-cost plans are often horrendous.  A “security service” is a common upsell, but I’ve had clients with sites compromised even when they purchased the “security”.  I’ve seen sites hacked due to cross-contamination, and I’ve seen overloaded servers running software that is years out of date. I was lucky enough to run into Trey Gardner of GreenGeeks at a WordCamp, and after a short conversation, he invited me to check out GreenGeeks hosting.  I’m pleased to say that I now have a solid recommendation for shared hosting – if you are in the market for shared web hosting, I invite you to [check out one of the GreenGeeks plans](https://www.greengeeks.com/track/milepost42/cp-m42rec). (Note:  GreenGeeks does offer [VPS hosting](https://www.greengeeks.com/track/milepost42/cp-m42rec/lp-3) and [dedicated server hosting](https://www.greengeeks.com/track/milepost42/cp-m42rec/lp-4) as well, and while I have no doubt those plans are also excellent, I have not personally tried them.) ## Performance For a shared hosting plan, GreenGeeks has comparatively good performance.  They offer all the basic items you’ll find in most shared plans (unlimited web space, data transfer, MySQL databases, the underlying software needed to host popular platforms such as WordPress or Drupal).  With three levels (Starter, Pro, and Premium), you can find an inexpensive plan to help get that blog started, or a little more robust plan if you want to test out your business idea without a large upfront outlay of cash.  My recommendation even for small sites is to start with the “Ecosite Pro” plan, but if you just need something for a low-traffic personal site and are really cash-strapped, the “Ecosite Starter” can get you going.  GreenGeeks has implemented a scalable hosting platform, so if you find the standard resources don’t quite meet your needs, you can purchase a memory upgrade to help boost your site performance. When you sign up, you can choose from 5 data centers – if you’re located in the US, Canada, or Europe, you’ll be able to choose a location near you for faster loading times.  They also offer integration with the CloudFlare Content Delivery Network, which can help with page loading speeds by caching content and serving it from a location close to your site visitors.  And their proprietary PowerCacher service (on Pro and Premium plans) can help speed your site up even more. GreenGeeks uses state-of-the-art hardware, with solid state drives and name brand server and network gear.  In addition, they stay current with the latest web software and protocols, using both HTTP/2 and PHP 7.  This is important not only for performance, but also for security. ## Security As mentioned, GreenGeeks is up to date with the software running on their servers – something not all inexpensive shared hosts do (I recently helped someone with a web issue and discovered their web server was running PHP 5.2 (as of the original date of this post, end-of-life for PHP 5.2 was over 8 years ago, so it’s not at all surprising the individual had website troubles).  GreenGeeks also offers secure FTP, giving you a secure connection to transfer and access your files. GreenGeeks uses a container based approach, provisioning each account with a secure virtual file system.  This helps to keep accounts private; although you share space on the server with many other accounts, users can only see and access their own accounts.  Along with security scanning and server monitoring, this approach helps to protect against malware, and reduces the concern of cross-site contamination if there happens to be a “bad actor” on your shared server. Finally, GreenGeeks offers a free Let’s Encrypt SSL certificate with all hosting plans – a must to ensure your site uses the important https and doesn’t get marked as “non-secure” by the Chrome web browser.  While most reputable web hosts will offer the Let’s Encrypt SSL certificate, many of the low-cost shared hosting plans charge to set up and install the certificate for your site. ## Support Other than the free website transfer offered by GreenGeeks, I have not had the need to use their support.  My support request for the website transfer was handled quickly and I had no issues.  If you do have occasion to need support, GreenGeeks offers email support through your Account Manager area, 24/7 live chat, and phone support from 9 AM to midnight Monday through Friday, and 9 AM to 8 PM EST on weekends.  If, like me, you prefer to try to figure things out yourself first, they do have a robust knowledge base as well as a number of tutorials on common topics. ## Other GreenGeeks’ claim to fame is, as evidenced by their name, being an award-winning “green” web host.  They are proud of being an environmentally friendly web host, by not only making the maximum effort to be energy efficient, but also investing in renewable energy to reduce the inevitable environmental footprint created by technology.  And when you host with GreenGeeks, you can use one of their cute little “Green Badges” to show that your website is eco-friendly! Although personally I’m more interested in the security aspects of the hosting I use, I can’t deny that being as energy-efficient as possible is good for all of us.  Oh, and Trey is a really nice guy! ## It’s Not Easy Being Green If you need an inexpensive shared hosting plan that still offers good performance and security features, as well as giving you the satisfaction of “being green”, then **[check out one of GreenGeeks hosting plans.](https://www.greengeeks.com/track/milepost42/cp-m42rec/lp-1)** --- --- title: "Data Privacy Day 2019" url: "https://milepost42.com/data-privacy-day-2019/" lang: "en-US" type: "post" description: "Milepost 42 is proud to be a champion of Data Privacy Day 2019. The new year is well underway (already!?), and there's no better time to review the personal information you share and collect, and take steps to ensure it's" last_modified: "2019-03-04T19:59:25+00:00" categories: [Privacy] --- # Data Privacy Day 2019 ![](https://milepost42.com/wp-content/uploads/2019/01/Champion-Badge-150x150.png) Milepost 42 is proud to be a [champion of Data Privacy Day 2019](https://staysafeonline.org/data-privacy-day/all-champions/). The new year is well underway (already!?), and there’s no better time to review the personal information you share and collect, and take steps to ensure it’s protected.   ## What Is Data Privacy Day? Data Privacy Day is an international effort, held annually each January 28, to create awareness about the importance of respecting privacy, safeguarding data and enabling trust. All organizations (and individuals) share the responsibility of being conscientious stewards of personal information. In North America, the Data Privacy Day initiative is officially led by the National Cyber Security Alliance (NCSA), a nonprofit, public-private partnership dedicated to promoting a safer, more secure and more trusted internet. For more information about getting involved in Data Privacy Day and becoming a Champion, visit [staysafeonline.org/data-privacy-day](https://staysafeonline.org/data-privacy-day). You can also follow NCSA on Facebook and Twitter for updates and resources and use the official hashtag #PrivacyAware to join the conversation. ## Why Should You Care About Privacy? Today, we’re more connected than ever, thanks to the internet and the ability to carry our connected devices everywhere. More people than ever have access to computers, mobile phones, and even wearable personal devices or devices in our homes. However, many people don’t understand the tremendous amount of personal information that is collected, shared, and often sold. When you connect a device and provide personal information, the company can collect and monitor that information, and often use it to determine what you’re likely to buy. This isn’t necessarily bad – you’re going to be marketed to anyway – but you should understand how the information you share is collected, used, and shared. ![](https://milepost42.com/wp-content/uploads/2019/01/DPD19_Personal_Info.png) ## Safeguard Your Data As a consumer, you should carefully consider what information you are sharing and be aware of its value. Personal info is like money – value it and protect it. Get familiar with the privacy settings on the apps and programs you use.  Regularly review their permissions, keep them current, and delete those you don’t use. ## Privacy Is Good For Business If you collect it, protect it. Follow reasonable security measures to keep individuals’ information safe from inappropriate and unauthorized access. Be open and honest about how you collect, use, and share the information you collect on your customers. Clearly communicate what privacy means to your organization and the steps you take to achieve and maintain privacy. ## Want To Learn More? Visit StaySafeOnline.org and [learn how you can get involved](https://staysafeonline.org/data-privacy-day/get-involved/) in Data Privacy Day. --- --- title: "Cybersecurity At Work: It’s Everyone’s Business" url: "https://milepost42.com/cybersecurity-at-work-its-everyones-business/" lang: "en-US" type: "post" description: "It’s Week 3 of #CyberAware Month, and this week is all about tips and advice to ensure online safety at work.  No matter where you work - government, industry, academia - we all have a role in ensuring online safety" last_modified: "2020-02-07T21:25:08+00:00" categories: [Cybersecurity] --- # Cybersecurity At Work: It’s Everyone’s Business It’s Week 3 of #CyberAware Month, and this week is all about tips and advice to ensure online safety at work.  No matter where you work – government, industry, academia – we all have a role in ensuring online safety and security.  While your organization may have an Information Technology (IT) department to oversee company infrastructure and computers, following cybersecurity practices to protect the organization from cyber attacks is a responsibility everyone shares.   ![table with computer and papers - text overlay says protect your business from cyber threats](https://milepost42.com/wp-content/uploads/2018/10/protect-your-business-v2.png) ## Create A Culture Of Security The actions we take to keep our personal devices and home computers safe also apply in the workplace.  Some of the most important items to help keep your business (and you) secure are: > [LastPass for Business](https://lastpass.sjv.io/c/1389444/565403/8692) is a great password management tool for small teams or for an enterprise. _(Disclosure: This is an affiliate link, which means I may get a small commission if you purchase through this link. There is no extra charge to you and there is no requirement to purchase through this link to get the latest deal.)_ ### Lock Down Your Login Use the strongest authentication tools available for all your online business accounts.  This may include biometrics, hardware “keys”, or two-factor authentication with a one-time use code through an app on your mobile device.  Everyone should have their own user name and password for any required accounts – never share passwords, and never reuse passwords! Use a password manager to secure and organize passwords; many of them can also provide “shared” access to accounts without disclosing the password.   ### Back It Up, Back It Up! Put a system in place to ensure your critical business information is regularly backed up in a secure location (or two, or three).  Employees should have the ability to back up documents and data they are working on, and there should be a systematic method of backing up and protecting customer data,  financial information, business databases, and other important information.  Don’t forget about information you have “in the cloud” as well, such as email or website information. Use the [“backup rule of three”](https://www.linkedin.com/pulse/three-rules-backup-stacy-clements/), and remember to encrypt any sensitive information.  Also, have a process to regularly test your backups.  If there’s a problem, you want to be able to quickly retrieve important information – and that’s not the time you want to find out that the backups didn’t work or were corrupted.   ### When In Doubt, Throw It Out Phishing is one of the top threats to any business; it’s one of the most successful ways an attacker can gain access to your systems, information, and even your money.  Be very cautious of any links or any odd requests you receive, even if the message appears to come from someone you know.  Verify any unusual requests, such as requests to wire funds, with the source.  Never open suspicious links in emails, messages, tweets, or posts.   ## Cybersecurity Is Everyone’s Business![illustration of people around table with shield in center](https://milepost42.com/wp-content/uploads/2018/10/cybersecurity-is-everyones-business-300x294.png) Business owners can set policies, and IT staff can help with technical tools, but cybersecurity isn’t just up to IT.  All employees need to know how to protect themselves and the organization, and understand the cyber risks and necessary actions as the business grows or adds new technologies. Get information on how to set up a cybersecurity awareness program with the [Cybersecurity Awareness Toolkit](https://staysafeonline.org/wp-content/uploads/2018/09/SMB-Toolkit-FINAL.pdf), created for small businesses by the National Cyber Security Alliance, Facebook and MediaPRO.   --- --- title: "In Demand: Consider A Career In Cybersecurity" url: "https://milepost42.com/in-demand-consider-a-career-in-cybersecurity/" lang: "en-US" type: "post" description: "Week 2 of National Cybersecurity Awareness Month is focused on raising awareness about the need for cybersecurity professionals and inspiring students and those entering (or re-entering) the workforce to consider the many opportunities to contribute in this field." last_modified: "2020-02-07T21:26:00+00:00" categories: [Cybersecurity] --- # In Demand: Consider A Career In Cybersecurity **_(Updated 22 Nov 2019)_** Week 2 of National Cybersecurity Awareness Month is focused on raising awareness about the need for cybersecurity professionals and inspiring students and those entering (or re-entering) the workforce to consider the many opportunities to contribute in this field. ![](https://milepost42.com/wp-content/uploads/2019/03/become-a-cybersecurity-professional-v1.png) Technology is an integral part of our way of life.  Our work, our finances, the utilities we depend on, even our entertainment is powered by technology and the internet.  Yet, there’s a shortage of professionals to operate, maintain, oversee, and protect this infrastructure.  By some estimates, **there will be [3.5 million unfilled jobs in cybersecurity](https://cybersecurityventures.com/jobs/) by 2021.** ## How can we help fill this gap? Educating students of all types is one place to start.  Parents, counselors, and teachers can encourage young people to explore the field of cybersecurity and foster their interests.  Resources such as [Nova Labs](https://www.pbs.org/wgbh/nova/labs/lab/cyber/) and [CyberPatriot](https://www.uscyberpatriot.org) offer information and opportunities for students to learn and practice skills that can prepare them for future cybersecurity careers. There are tons of opportunities for veterans, those re-entering the workforce, and those looking for a career change.  While cybersecurity jobs do require some level of technical skill, working in cybersecurity doesn’t necessarily mean sitting in a basement room working with code.  Skills such as problem solving, analysis, project management, ability to communicate verbally and in writing, team building, and leadership are all necessary. > According to the National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework:  “Skills needed for cybersecurity rely less on physical manipulation of tools and instruments and more on applying tools, frameworks, processes, and controls that have an impact on the cybersecurity posture of an organization or individual.” The skills and abilities that made you successful so far will help you succeed in cybersecurity as well, and there are many places to learn the specific technical knowledge for different cybersecurity roles. ## Interested in learning more about a career in cybersecurity? The [NICE Framework](https://www.nist.gov/itl/applied-cybersecurity/nice/resources/nice-cybersecurity-workforce-framework) is a detailed resource that describes cybersecurity work and the knowledge, skills, and abilities required for cybersecurity work roles.  Another resource for those interested in cybersecurity positions is [CyberSeek](https://www.cyberseek.org/), which provides information about supply and demand in the cybersecurity job market, as well as an example career pathway for common key job roles.  CyberSeek [recently published a study](https://www.comparitech.com/blog/vpn-privacy/cybersecurity-employment-study/) in which they analyzed cybersecurity salaries and prospects in each state to identify which states are doing the best job of encouraging this increasingly important industry. In addition, the [Cyber Security Education website](https://www.cybersecurityeducation.org/) provides information on careers, certifications, and formal education programs to prepare you for a rewarding cybersecurity career. Take a look at some of the many resources out there and consider becoming part of this growing and critical career field! ![](https://milepost42.com/wp-content/uploads/2019/03/become-a-cybersecurity-professional-v2.png) --- --- title: "6 #CyberAware Tips to Protect Yourself and Your Family at Home" url: "https://milepost42.com/6-cyberaware-tips-to-protect-yourself-and-your-family-at-home/" lang: "en-US" type: "post" description: "Autumn is here, and that means changing leaves, pumpkin spice, and Cybersecurity Awareness Month! The theme for the first week of Cybersecurity Awareness Month is Make Your Home A Haven for Online Safety.  Here are 6 things you can do to protect" last_modified: "2020-02-07T21:29:11+00:00" categories: [Cybersecurity] --- # 6 #CyberAware Tips to Protect Yourself and Your Family at Home Autumn is here, and that means changing leaves, pumpkin spice, and Cybersecurity Awareness Month! ![Mother and son sitting on couch overlaid with "Make Your Home A Haven For Online Safety"](https://milepost42.com/wp-content/uploads/2018/10/week-1-facebook.png) The theme for the first week of Cybersecurity Awareness Month is Make Your Home A Haven for Online Safety.  Here are 6 things you can do to protect yourself and your family at home. ## Lock Down Your Login ![Lock Down Your Login - photo of hands holding smart phone with biometrics](https://milepost42.com/wp-content/uploads/2018/10/lock-down-your-login-v1.png) You already know you need to use strong, unique passwords for your accounts.  But even a strong password isn’t enough to protect your key accounts like email, banking, or social media. Add another layer of security by using two-factor authentication – an access control method that requires an additional security step to allow a user to log in.  While this can seem inconvenient, it’s less inconvenient than finding your security has been compromised. If you use a system that offers two-factor authentication, as many banking, email, and social media websites do, take a few moments to set it up.  Pro Tip: Where possible, use an authentication app (such as Authy, Google Authenticator, or a service-specific app) in preference to an SMS message sent to your phone. While the SMS method is better than nothing, [SMS is insecure and can be intercepted](http://Many banking, email, and social media websites offer two-factor authenticatio- usually something you know (your password) and something you have (most often your mobile phone). Most banking websites offer 2FA, as do many e-mail providers.). ## Protect Your Personal Information ![girl looking at smartphone](https://milepost42.com/wp-content/uploads/2018/10/personal-info-v2.png) Digital devices give us great convenience and connectivity, and we’re more connected than ever before.  That convenience comes at a cost, however.  You are constantly generating data about yourself and others. These devices work by collecting and processing information about you, such as your behaviors and preferences. Information about you – items you’ve purchased, where you go, and what you do – has value, just like money.  It’s not necessarily harmful; for example, sharing information on purchases can help you get better deals from a merchant.  However, be mindful about what information you’re sharing.  Consider how your information is collected by apps, websites, and connected home devices, and be sure you’re comfortable with the level of sharing. ## Share With Care ![photo of iphone with apps](https://milepost42.com/wp-content/uploads/2018/10/share-with-care-v2.png) > ### **Remember that nothing is private!** Remember that nothing is private!  Think before you post about yourself and others online. Consider what a post reveals, who might see it, and how it might affect you and others now and in the future. Never post sensitive information such as passwords or account information on social media, and be very careful about sharing personal information such as your phone number or address.  Do check your privacy settings, but don’t depend on them to protect your information.  Once something is posted online, it’s out of your control, and you don’t know who might see it, share it, or use it. ## Keep A Clean Machine ![smart phone and laptop](https://milepost42.com/wp-content/uploads/2018/10/keep-a-clean-machine-v3.png) Keep all the software on your computer, smartphone, tablets, and other internet-connected devices current.  This is the best way to reduce the risk of malware infecting your device. Often you can set devices to update automatically, but it’s a good idea to check occasionally to make sure you’re running the latest versions.  Don’t forget devices like your home router and smart home hubs – they usually have less frequent updates, but may require extra steps and manual updates. ## Remember Your Router ![blurred background of device with wifi symbol](https://milepost42.com/wp-content/uploads/2018/10/secure-your-router.png) Your WiFi router is a gateway into your home network.  Remember to secure it the same way you secure your computer and mobile devices. Change the default name and password on your router, and use WPA (WiFi Protected Access) encryption.  Use a strong passphrase to secure access, and name your network in a way that won’t let people know it’s in your house.  And don’t forget to check for and apply updates. Depending on the router you have, you may be able to block certain websites that you don’t want anyone in your family visiting, or you may be able to monitor traffic to see who’s connected (and if there’s someone who shouldn’t be).  Most current routers also have the ability to set up a “guest network” for visitors, so you can let your friends and family access the internet without exposing your personal files. ## Back It Up ![computer with attached external hard drive for backup and wireless mouse](https://milepost42.com/wp-content/uploads/2018/10/back-it-up.png) Protect your valuable work, music, photos and other digital information by making electronic copies and storing them safely.  If you fall victim to ransomware, the best response is to have all your data safely backed up and available to restore. [perfectpullquote align=”right” bordertop=”false” cite=”” link=”” color=”” class=”” size=””]Learn the [Backup Rule of Three](https://www.hanselman.com/blog/TheComputerBackupRuleOfThree.aspx) and the [Three Rules of Backup](https://www.linkedin.com/pulse/three-rules-backup-stacy-clements/)![/perfectpullquote] Use the [“backup rule of three”](https://www.hanselman.com/blog/TheComputerBackupRuleOfThree.aspx) and don’t forget to test your backups to make sure you can retrieve your important files! Read about the [Three Rules of Backup](https://www.linkedin.com/pulse/three-rules-backup-stacy-clements/) and options to help you back up your business or personal data. --- --- title: "Milepost 42 Pledges to Support National Cybersecurity Awareness Month 2018 as a Champion" url: "https://milepost42.com/milepost-42-pledges-to-support-national-cybersecurity-awareness-month-2018-as-a-champion/" lang: "en-US" type: "post" description: "Milepost 42 is proud to be a Champion of National Cybersecurity Awareness Month (NCSAM) 2018, joining a growing global effort among businesses, government agencies, colleges and universities, associations, nonprofit organizations and individuals to promote the awareness of online safety and" last_modified: "2024-10-02T20:25:43+00:00" categories: [General] --- # Milepost 42 Pledges to Support National Cybersecurity Awareness Month 2018 as a Champion ![National Cyber Security Awareness Month Champion badge](https://milepost42.com/wp-content/uploads/2018/10/NCSAM-Champion-SM-300x209.png)[Milepost 42](https://milepost42.com) is proud to be a [Champion of National Cybersecurity Awareness Month (NCSAM) 2018](https://staysafeonline.org/ncsam/ncsam-champions/), joining a growing global effort among businesses, government agencies, colleges and universities, associations, nonprofit organizations and individuals to promote the awareness of online safety and privacy. A multi-layered and far-reaching campaign held annually in October, NCSAM was created as a collaborative effort between government and industry to ensure all digital citizens have the resources needed to stay safer and more secure online while also protecting their personal information. As an official Champion, Milepost 42 recognizes its commitment to cybersecurity, online safety and privacy.   > “In today’s world, most businesses, and in fact most people, are “cyber connected” in some way.  That’s a good thing – we can connect with customers, friends, and family in ways that weren’t possible 30, 20, even 10 years ago.  We can streamline processes, purchase items, manage accounting, and learn new skills.  However, we also have to learn to protect ourselves in new ways.  Sadly, there are bad people who focus on using technology to harm others, and we’re also subject to new types of “disasters”.  We all need to learn to lock our cyber doors, and plan for how to continue operations and recover from disastrous cyber events.” Co-founded and led by the National Cyber Security Alliance (NCSA) and the U.S. Department of Homeland Security (DHS), NCSAM has grown exponentially since its inception, reaching consumers, small and medium-sized businesses, corporations, government entities, the military, educational institutions and young people nationally and internationally. NCSAM 2017 was an unprecedented success, generating 4,316 news stories – an increase of 68 percent in comparison to NCSAM 2016’s media coverage. Kicking off its 15th year, NCSAM 2018 presents an unparalleled opportunity to leverage the month’s tremendous adoption growth over the last several years and expand cybersecurity and privacy education and awareness globally. “The Champion program continues to be a such a strong foundation for National Cyber Security Awareness Month’s ongoing and impactful success. In 2017, 1,050 organizations enlisted to support the month ­– a 21-percent increase from the previous year,” said Russ Schrader, NCSA’s executive director. “We are thankful to our 2018 Champion organizations for their support and commitment to our shared responsibility of promoting cybersecurity, online safety awareness and the opportunity to protect our privacy.” For more information about NCSAM 2018, the Champion program and how to participate in a wide variety of activities, visit [staysafeonline.org/ncsam](https://staysafeonline.org/ncsam). You can also follow and use the official NCSAM hashtag **#CyberAware** on social media throughout the month. **About ****Milepost 42**** **[Milepost 42](https://milepost42.com) is a technology partner for small business owners who want to focus on their passion and not the “techie stuff” needed to support it.  Small businesses need technology –websites, email, automation – to run and grow, and they also need to be aware of the need for cybersecurity to ensure business continuity.  Milepost 42 provides those services and planning assistance for small business owners who are ready to have someone else handle the “web stuff”.** ** **About National Cybersecurity Awareness Month **NCSAM is designed to engage and educate public- and private-sector partners through events and initiatives with the goal of raising awareness about cybersecurity in order to increase the resiliency of the nation in the event of a cyber incident. Since the Presidential proclamation establishing NCSAM in 2004, the initiative has been formally recognized by Congress, federal, state and local governments and leaders from industry and academia. This united effort is necessary to maintain a cyberspace that is safer and more resilient and remains a source of tremendous opportunity and growth for years to come. For more information, visit [staysafeonline.org/ncsam](https://staysafeonline.org/ncsam) or [dhs.gov/national-cyber-security-awareness-month](http://www.dhs.gov/national-cyber-security-awareness-month). **About NCSA **[NCSA](https://staysafeonline.org) is the nation’s leading nonprofit, public-private partnership promoting cybersecurity and privacy education and awareness. NCSA works with a broad array of stakeholders in government, industry and civil society. NCSA’s primary partners are DHS and NCSA’s Board of Directors, which includes representatives from ADP; Aetna; AT&T Services Inc.; Bank of America; CDK Global, LLC; Cisco; Comcast Corporation; ESET North America; Facebook; Google; Intel Corporation; Logical Operations; Marriott International; Mastercard; Microsoft Corporation; Mimecast; NXP Semiconductors; Raytheon; RSA, the Security Division of EMC; Salesforce; Symantec Corporation; TeleSign; Visa and Wells Fargo. NCSA’s core efforts include National Cyber Security Awareness Month (October); Data Privacy Day (Jan. 28); STOP. THINK. CONNECT™; and [CyberSecure My Business™](https://staysafeonline.org/cybersecure-business/), which offers webinars, web resources and workshops to help businesses be resistant to and resilient from cyberattacks. For more information on NCSA, please visit staysafeonline.org/about.** ** **About STOP. THINK. CONNECT. **STOP. THINK. CONNECT.™ is the global online safety awareness campaign to help all digital citizens stay safer and more secure online. The message was created by an unprecedented coalition of private companies, nonprofits and government organizations with leadership provided by NCSA and the APWG. The campaign was launched in October of 2010 by the STOP. THINK. CONNECT.™ Messaging Convention in partnership with the U.S. government, including the White House. NCSA, in partnership with the APWG, continues to lead the campaign. DHS leads the federal engagement in the campaign. Learn how to get involved by following STOP. THINK. CONNECT.™ on [Facebook](https://www.facebook.com/STOPTHINKCONNECT) and [Twitter](https://twitter.com/stopthnkconnect) and visiting [stopthinkconnect.org](https://stopthinkconnect.org). --- --- title: "Let’s Talk About Your Project" url: "https://milepost42.com/lets-talk-about-your-project/" lang: "en-US" type: "page" description: "Whether you're looking for a brand new website, or it's time to refresh or update your existing site, I'd love to learn more. You may not be an expert on websites, but you are the expert on your business!  Are" last_modified: "2020-10-15T00:47:24+00:00" --- # Let’s Talk About Your Project ## Whether you’re looking for a brand new website, or it’s time to refresh or update your existing site, I’d love to learn more. You may not be an expert on websites, but you are the expert on your business!  Are you ready to work with someone who can partner with you to craft a website to meet your goals? As a first step, I ask that you provide some details about what you’re looking for.  This information helps me start to understand your business and what you are trying to achieve, so when we set up an initial consultation, we’re ready to talk shop.   Let's Talk About Your ProjectFirst Name Last Name Email How did you find out about Milepost 42? Please tell me a little about your business and intended audience. (required) Is this project for a new or existing website? If existing, please provide the URL. (required) Are there any specific website features or functionality you are looking for? What do you want to achieve with your new site? What does success look like? What is your project timeline? When do you want to launch your new site? (required) What is your project investment range? (required) Is there anything else I should know about you or your project? Let's Get Started!   --- --- title: "Milepost 42 Privacy Policy" url: "https://milepost42.com/privacy-policy/" lang: "en-US" type: "page" last_modified: "2024-10-23T20:39:50+00:00" --- # Milepost 42 Privacy Policy --- --- title: "Terms of Service" url: "https://milepost42.com/terms-of-service/" lang: "en-US" type: "page" description: "TERMS OF SERVICE Milepost 42 LLC BY VISITING milepost42.com, YOU ARE CONSENTING TO OUR TERMS OF SERVICE. OVERVIEW By using milepost42.com, referred to as this “Site”, all visitors, referred to as “user”, “you” and “your” are bound by these Terms" last_modified: "2018-06-22T01:36:42+00:00" --- # Terms of Service **TERMS OF SERVICE** Milepost 42 LLC **BY VISITING milepost42.com, YOU ARE CONSENTING TO OUR TERMS OF SERVICE.** **OVERVIEW** By using **milepost42.com**, referred to as this “Site”, all visitors, referred to as “user”, “you” and “your” are bound by these Terms of Service. The terms “we,” “us,” and “our” refer to **Milepost 42 LLC** (the “Company”), owner of **milepost42.com**.  Accessing this Site constitutes a use of the Site and an acceptance to the Terms provided herein. By using the Site, you agree to these Terms of Service, without modification, and acknowledge reading them. We reserve the right to change these Terms of Service or to impose new conditions on use of the Site, from time to time, in which case we will post the revised Terms of Service on this Site.  By continuing to use the Site after we post any such changes means you accept the new Terms of Service with the modifications. **SITE USE** To access or use the Site, you must be 18 years or older and have the requisite power and authority to enter into these Terms of Service. In order to use the Site, you may be required to provide information about yourself including your name, email address, and other personal information. You agree that any registration information you give to the Company will always be accurate, correct and up to date. You must not impersonate someone else or provide account information or an email address other than your own. Your account must not be used for any illegal or unauthorized purpose. You must not, in the use of the Site, violate any laws in your jurisdiction. You may use the Site for lawful purposes only. You shall not post or transmit through the Site any material which violates or infringes the rights of others, or which is threatening, abusive, defamatory, libelous, invasive of privacy or publicity rights, vulgar, obscene, profane or otherwise objectionable, contains injurious formulas, recipes, or instructions, which encourages conduct that would constitute a criminal offense, give rise to civil liability or otherwise violate any law. **PURCHASE AND REFUND POLICY** By clicking “Buy Now,” “Purchase,” or any other phrase on the purchase button, or entering your credit card information, or otherwise enrolling, electronically, verbally, or otherwise, you (“Client”) agree to be provided with products, programs, or services by the Company unless a separate Terms of Purchase Agreement is provided at purchase.  No refunds will be given for any products purchased online. **MILEPOST 42 LLC**** INTELLECTUAL PROPERTY** The Site contains intellectual property owned by **Milepost 42 LLC**, including, without limitation, trademarks, copyrights, proprietary information and other intellectual property as well as the **Milepost 42 LLC** /**milepost42.com** name, logo, all designs, text, graphics, photographs, other files, and the selection and arrangement thereof. You may, view, print and/or download one copy of the Materials from this website on any single computer solely for your personal, informational, non-commercial use, provided you keep intact all copyright and other proprietary notices. You may not modify, publish, transmit, participate in the transfer or sale of, create derivative works from, distribute, display, reproduce or perform, or in any way exploit in any format whatsoever any of the Site content or intellectual property, in whole or in part without our prior written consent. We reserve the right to immediately remove you from the Site, without refund, if you are caught violating this intellectual property policy. **LIMITATION OF LIABILITY** **YOU AGREE THAT UNDER NO CIRCUMSTANCES SHALL WE BE LIABLE FOR DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, PUNITIVE, EXEMPLARY, OR ANY OTHER DAMAGES ARISING OUT OF YOUR USE OF THE SITE OR SERVICE. ADDITIONALLY, MILEPOST 42 LLC IS NOT LIABLE FOR DAMAGES IN CONNECTION WITH (I) ANY FAILURE OF PERFORMANCE, ERROR, OMISSION, DENIAL OF SERVICE, ATTACK, INTERRUPTION, DELETION, DEFECT, DELAY IN OPERATION OR TRANSMISSION, COMPUTER VIRUS OR LINE OR SYSTEM FAILURE; (II) LOSS OF REVENUE, ANTICIPATED PROFITS, BUSINESS, SAVINGS, GOODWILL OR DATA; AND (III) THIRD PARTY THEFT OF, DESTRUCTION OF, UNAUTHORIZED ACCESS TO, ALTERATION OF, OR USE OF YOUR INFORMATION OR PROPERTY, REGARDLESS OF OUR NEGLIGENCE, GROSS NEGLIGENCE, FAILURE OF AN ESSENTIAL PURPOSE AND WHETHER SUCH LIABILITY ARISES IN NEGLIGENCE, CONTRACT, TORT, OR ANY OTHER THEORY OF LEGAL LIABILITY. THE FOREGOING APPLIES EVEN IF MILEPOST 42 LLC** **HAS BEEN ADVISED OF THE POSSIBILITY OF OR COULD HAVE FORESEEN THE DAMAGES. IN THOSE STATES THAT DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR THE DAMAGES, OUR LIABILITY IS LIMITED TO THE FULLEST POSSIBLE EXTENT PERMITTED BY LAW. IN NO EVENT SHALL MILEPOST 42 LLC CUMULATIVE LIABILITY TO YOU EXCEED $100.** **THIRD PARTY RESOURCES** The Site may contain links to third-party websites and resources. You acknowledge and agree that we are not responsible or liable for the availability, accuracy, content or policies of third party websites or resources. Links to such websites or resources do not imply any endorsement by or affiliation with the Company. You acknowledge sole responsibility for and assume all risk arising from your use of any such websites or resources. **INDEMNIFICATION** You shall indemnify and hold us harmless from and against any and all losses, damages, settlements, liabilities, costs, charges, assessments and expenses, as well as third party claims and causes of action, including, without limitation, attorneys’ fees, arising out of any breach by you of any of these Terms of Service, or any use by you of the Site. You shall provide us with such assistance, without charge, as we may request in connection with any such defense, including, without limitation, providing us with such information, documents, records and reasonable access to you, as we deem necessary. You shall not settle any third party claim or waive any defense without our prior written consent. **RELEASE OF CLAIMS** In no event will the Company be liable to any party for any type of direct, indirect, special, incidental, or consequential damages for any use of or reliance on our Site or its Content.  You hereby release the Company from any and all claims including those related to personal or business interruptions, misapplication or information, or any other loss, condition, or issue. **ONLINE COMMERCE ** Certain sections of the Site or its Content may allow you to make purchases from us or from other merchants. If you make a purchase from us on or through our Website or its Content, all information obtained during your purchase or transaction and all of the information that you give as part of the transaction, such as your name, address, method of payment, credit card number, and billing information, may be collected by both us, the merchant, and our payment processing company. Your participation, correspondence or business dealings with any affiliate, individual or company found on or through our Website, all purchase terms, conditions, representations or warranties associated with payment, refunds, and/or delivery related to your purchase, are solely between you and the merchant. You agree that we shall not be responsible or liable for any loss, damage, refunds, or other matters of any sort that incurred as the result of such dealings with a merchant. We have no responsibility or liability for these independent policies of the payment processing companies and Merchants. In addition, when you make certain purchases through our Site or its Content, you may be subject to the additional terms and conditions of a payment processing company, Merchant or us that specifically apply to your purchase. For more information regarding a Merchant and its terms and conditions that may apply, visit that merchant’s Website and click on its information links or contact the Merchant directly. You release us, our affiliates, our payment processing company, and merchants from any damages that you incur, and agree not to assert any claims against us or them, arising from your purchase through or use of our Website or its Content. **GOVERNING LAW; VENUE; MEDIATION** This Agreement shall be governed by and construed in accordance with the laws of the State of Washington within the United States of America, regardless of the conflict of laws principles thereof. If a dispute is not resolved first by good-faith negotiation between the parties to this Agreement, any controversy or dispute to this Agreement will be submitted to the American Arbitration Association. The arbitration shall occur within ninety (90) days from the date of the initial arbitration demand and shall take place in Olympia, Washington or via telephone. The Parties shall cooperate in exchanging and expediting discovery as part of the arbitration process and shall cooperate with each other to ensure that the arbitration process is completed within the ninety (90) day period. The written decision of the arbitrators (which will provide for the payment of costs, including attorneys’ fees) will be absolutely binding and conclusive and not subject to judicial review, and may be entered and enforced in any court of proper jurisdiction, either as a judgment of law or decree in equity, as circumstances may indicate. **SEVERABILITY** If any term, provision, covenant, or condition of this Agreement is held by an arbitrator or court of competent jurisdiction to be invalid, void, or unenforceable, the rest of the Agreement shall remain in full force and effect and shall in no way be affected, impaired, or invalidated. **ASSIGNMENT** These Terms of Service bind and inure to the benefit of the parties’ successors and assigns. These Terms of Service are not assignable, delegable or otherwise transferable by you. Any transfer, assignment or delegation by you is invalid. **ENTIRE AGREEMENT; WAIVER; HEADINGS** This Agreement constitutes the entire agreement between you and **Milepost 42 LLC **pertaining to the Site and Service and supersedes all prior and contemporaneous agreements, representations, and understandings between us. No waiver of any of the provisions of this Agreement by **Milepost 42 LLC **shall be deemed, or shall constitute, a waiver of any other provision, whether or not similar, nor shall any waiver constitute a continuing waiver. No waiver shall be binding unless executed in writing by **Milepost 42 LLC**. The subject headings of this Agreement are included for convenience only and shall not affect the construction or interpretation of any of its provisions. If you have any questions or concerns regarding these Terms of Service, please email: **stacy@milepost42.com.** Updated: 4 March 2018 --- --- title: "Work On Your Business, Not Your Website" url: "https://milepost42.com/" lang: "en-US" type: "page" description: "Are you wasting weekends working on your website? You started a business so you could do what you love.  Your business needs a website, but it doesn't need to be your weekend job. What if you had someone to take" last_modified: "2024-02-16T02:26:49+00:00" custom_fields: site-sidebar-layout: "no-sidebar" site-content-layout: "page-builder" site-post-title: "disabled" ast-title-bar-display: "disabled" ast-featured-img: "disabled" theme-transparent-header-meta: "disabled" astra-main-page-id: 38775 ast_self_id_38775: 1 --- # Work On Your Business, Not Your Website ## Are you wasting weekends working on your website? You started a business so you could do what you love.  Your business needs a website, but it doesn’t need to be your weekend job. **What if you had someone to take care of that “web stuff” you don’t love?** ![frustrated woman looking at computer screen](https://milepost42.com/wp-content/uploads/2024/01/10958619761704507673.jpg) ![7031362921705477469](https://milepost42.com/wp-content/uploads/2024/01/7031362921705477469.jpg) You’ve got a small business – you know how to put your head down and get things done.  You’re not afraid of putting the work in, but your to-do list is never-ending, and one of the things that never goes away is your website.  **But that means building it and taking care of it** – and let’s be honest, you’ve got better things to do. Websites, email, and technology are a necessary part of doing business, but figuring out tech stuff can feel like a second job.  **And keeping it secure?**  **Many small business owners don’t even know where to start.** If you’re like most small businesses I work with, you’re a solopreneur or have a small team.  You don’t have an accountant on staff, but you probably have an accountant’s number in your phone.  You don’t have full-time tech support, but **you do need someone you can depend on to handle the “web stuff”**. ### What can I do for you? - Website Creation and White Glove Site Care - Email and Integration Setup - Analytics Assistance - Small Business Cybersecurity Education ### Does this sound like you? - **I need a website.** Everyone said it was easy, just use WordPress or one of those do-it-yourself builders. But I can’t make it look or work the way I want, and I don’t have time to figure it out. - I have a website, but it **doesn’t do what I want**. I don’t feel I’m showing up in the best light for my customers, and I don’t know how to fix it. - My website looks good and it works for me right now, but it **needs to be kept up to date and secure**, and I’m not sure if I’m doing the right things. I know updates are supposed to be easy, but I don’t have a lot of time, and I don’t know how to fix it if it breaks. - I’m scared of being hacked! I know I need to do something about cybersecurity, but **I don’t know where to start**. _You no longer have to do it alone._ ### If you’re ready to get your weekends back and stop worrying about your website, get in touch! [ Let’s talk about your project ](https://milepost42.com/lets-talk-about-your-project/) Have a general comment or a question?  Send me a message! Contact FormFirst NameLast NameEmailSubjectYour MessageGet In Touch! ![Service Disables Veteran Owned Small Business](https://milepost42.com/wp-content/uploads/2024/02/cve_completed_s-150x150.jpg) ![ISC2 Certified in Cybersecurity](https://milepost42.com/wp-content/uploads/2024/02/certified-in-cybersecurity-cc-2-150x150.png) ![Proofpoint Certified Ransomware Specialist 2023](https://milepost42.com/wp-content/uploads/2024/02/proofpoint-certified-ransomware-specialist-2023-150x150.png) ![WordPress Project Management Academy Level 1](https://milepost42.com/wp-content/uploads/2024/02/WPPMA-Badge-Level1-150x150.png) ![data-privacy-certified-agency-partner](https://milepost42.com/wp-content/uploads/2024/02/data-privacy-certified-agency-partner-150x150.png) ---