Online Express emails and email security (the pesky "From:" field and spoofing)

Options
Has anyone figured out a workaround for sending emails through Online Express that share the same email domain in the "From: " field with the recipient of the email without the email being blocked as a "spoofing" attempt?  So, for example, in Online Express the "From: " field has "test@sample.org" as the "from" email address and you are sending an email to someone that has an email address within the organization with the with the "@sample.org" domain.  The intention of the Online Express "From: " field is to make the email appear as if it's coming from someone specific, but the email is actually being sent using Blackbaud's email server at their Boston Data Center.


Best practice for email security within many organizations is that emails that share the same domain, but are not actually being sent from within the organization are deemed as "spoofed" emails and therefore blocked.  I am having issues with Online Express and sending emails to email addresses within our organization when using an email address in the "From: " field that has the same domain.


I contacted Blackbaud and the solution/suggestion was to modify our SPF (Sender Policy Framework) and whitelist the Blackbaud Boston Data Center IP addresses.  The issue is that best practice calls for not allowing 3rd party IP addresses to spoof an email address, especially since these 3rd party services could be compromised and expose the organization to elevated risk.


Any suggestions?  Services like Constant Contact and MailChimp allow for emails to be sent "On behalf of", rather than a straight up "From: " field.
Tagged:

Comments

  • I believe there really is no other solution than what you have already described. Our IT had to add the IP addresses to our Whitelist in order for it to work for us. That being said, we had a similar problem receiving emails from MailChimp until our IT also added their IP addresses to our Whitelist. Any time your organization (quite properly) keeps uber-security, you run into hitches once in a while.

  • Thank you for your response Faith.


    FYI, I indeed confirmed with Blackbaud support that there is no other way around this spoofing issue as Online Express is currently without modifying the SPF/whitelisting the Blackbaud IP addresses.  Unfortunately this makes Online Express virtually useless to us as an email marketing tool, which is unfortunate. 


    I'm very, very surprised that Blackbaud has not addressed this issue given the role that email solicitation and distribution plays in today's philanthropic landscape.  Making specific exceptions to your organization's SPF/whitelisting specific IP addresses undermines your organization's email security and sets you up for trouble down the road.  What if Blackbaud's email servers get hacked...or better yet, when they get hacked...now you've suddenly allowed Blackbaud to send nefarious emails to your organization and they are granted a free pass to your users' inboxes?  I know that it is possible to provide email-based marketing services to various users (example: "on behalf of...")
    without having to make exceptions to the organization's SPF/whitelisting settings, and maintaining tight email security.  Which begs the question of why this isn't possible in Online Express now?  Very frustrating indeed!  Hopefully this helps other folks out that are considering this product.

Categories