SPF, DKIM and DMARC: Complete Guide for CISSP
Email authentication for the CISSP: what SPF, DKIM and DMARC each check, why forwarding breaks SPF, and how alignment ties a pass to the visible From.
How networks are secured and attacked: the OSI model layer by layer, the protocols that encrypt traffic in transit, and segmentation from VLANs up to micro-segmentation, so that one breach cannot reach everything. CISSP Domain 4.
Email authentication for the CISSP: what SPF, DKIM and DMARC each check, why forwarding breaks SPF, and how alignment ties a pass to the visible From.
AH authenticates but never encrypts and breaks through NAT. ESP encrypts, authenticates and traverses NAT. A CISSP insight on the IPsec protocol choice.
Fourth-generation cellular technology, standardised by 3GPP as Long Term Evolution; where enabled, its encryption protects the radio link to the base station, not traffic end to end.
Fifth-generation cellular technology from 3GPP, commonly described as concealing the subscriber's permanent identity on the air, and introducing network slicing on shared infrastructure.
The protocol an IPv4 host uses to learn the hardware (MAC) address that belongs to an IP address on its own segment; it has no authentication, which is what ARP spoofing exploits.
Physical segmentation in which a system or network has no wired or wireless connection to any other network; data that must cross it moves on removable media or through people.
A denial-of-service technique that sends small spoofed requests to services whose replies are far larger, so the replies converge on the victim at many times the attacker's own traffic.
An addressing method in which several nodes share one address and routing delivers each packet to the nearest of them; widely used for resilient DNS and content delivery.
A firewall that terminates each connection and relays it through a proxy for a specific application protocol, so it can inspect and filter content at OSI layer 7.
A local-network attack in which forged ARP replies bind the attacker's MAC address to another host's IP address, so traffic meant for that host passes through the attacker.
A self-assigned IPv4 address from 169.254.0.0/16 that a host takes when no DHCP server answers; it reaches only the local link and commonly signals a DHCP failure.
The intermediate links that carry traffic from a network's edge, such as cell sites or branch offices, back to its core; also the practice of routing remote traffic through a central site.
The maximum rate at which a link or path can carry data, stated in bits per second; a capacity figure, distinct from throughput, which is the rate actually achieved.
A system deliberately exposed to an untrusted network and hardened to withstand attack, commonly placed in a DMZ to run a public service or act as a controlled point of entry.
A Bluetooth attack that exploits firmware flaws in some older devices to use the device's own commands, such as placing calls, sending messages or reading data, without the owner knowing.
Sending unsolicited messages to nearby Bluetooth devices; the message does no harm to the device, but it can lure the user into a harmful response, much as spam or phishing does.
Unauthorised access to data on a Bluetooth device, such as contacts, messages or the device identifier, by forcing a connection through firmware flaws found in some older devices.
An open standard for short-range radio links between personal devices such as phones, headsets and sensors; its security rests on pairing, discoverability settings and firmware quality.
The routing protocol that exchanges reachability between the internet's autonomous systems; announcements a peer does not filter or validate can carry false routes that redirect traffic.
A network of compromised devices, each a bot, that an attacker directs remotely through command-and-control channels to run coordinated activity such as DDoS attacks, spam or credential stuffing.
A layer 2 device that joins network segments and forwards frames between them by MAC address, separating collision domains while leaving a single broadcast domain.
Delivery of a single frame or packet to every host in a broadcast domain; IPv4 relies on it for ARP and DHCP, while IPv6 has no broadcast and uses multicast for those jobs.
A web page that holds a newly connected device's traffic until the user authenticates, accepts terms or pays; common on guest Wi-Fi, it controls access but does not encrypt the connection.
Media access methods where a device listens before it transmits on a shared medium: CSMA/CD detects collisions on wired Ethernet, CSMA/CA tries to avoid them on wireless networks.
The AES-based data protection protocol from IEEE 802.11i that WPA2 requires: counter mode encrypts each frame and CBC-MAC checks its integrity, replacing the RC4-based TKIP.
A PPP authentication protocol (RFC 1994) where the server sends a random challenge and the client returns a hash of it with a shared secret, so the secret never crosses the link.
The set of cryptographic algorithms a client and server agree to use for one TLS connection, covering key exchange, authentication, bulk encryption and integrity.
A communication method that sets up a dedicated path between two endpoints before any data flows and holds it, with its capacity reserved, for the whole session.
A firewall or proxy working at the session layer that validates the setup of a connection, then relays its traffic without inspecting the application content inside.
The IP addressing and routing scheme that replaced fixed address classes with prefixes of any length, written as an address, a slash and the number of network bits.
Copper cable with one central conductor inside an insulating layer and a conductive shield, giving better resistance to electromagnetic interference than unshielded twisted pair.
An open interconnect standard built on the PCI Express physical layer that links processors, accelerators and memory devices with cache coherency; the ISC2 outline names it as a converged protocol.
A distributed set of servers that caches and serves content close to users; it can improve performance and availability, and where it terminates TLS the trust boundary moves to the provider.
Protocols that carry traffic which once needed its own separate network, such as storage or voice, over a shared network, usually an Ethernet or IP network.
A switch forwarding method that starts sending a frame on as soon as it has read the destination address, cutting latency but passing on damaged frames it cannot check.
The three functional layers of a network device: the data plane forwards traffic, the control plane decides where it goes, and the management plane configures and monitors.
A network segment between an untrusted network and the internal one that holds the systems outsiders must reach, with traffic into the internal network limited to permitted flows.
An attack on availability that stops legitimate users reaching a system or service, by exhausting its resources or by exploiting a flaw that makes it crash.
A denial of service attack launched from many systems at once, commonly a botnet or abused third-party servers, so no single source can be blocked to stop it.
A firewall whose policy is defined centrally but enforced at many points close to the workloads, such as on each host or in the virtual switch, rather than only at the network edge.
The policy layer that tests whether an SPF or DKIM pass aligns with the visible From domain, tells receivers what to do when neither does, and requests reports from them.
An industrial control protocol used mainly by electric and water utilities for SCADA communication, standardised as IEEE 1815 and commonly carried inside TCP/IP.
An attack that plants a forged record in a DNS resolver's cache, so the resolver hands the false answer to every client that asks until the record expires.
An attack that takes control of the settings that decide how names resolve, such as a DNS server, a domain's registrar account or a device's resolver, to redirect traffic.
A protocol that carries DNS queries and answers inside an encrypted HTTPS session, hiding them from observers on the path but also from the organisation's own DNS monitoring.
Extensions that let a resolver verify DNS answers through digital signatures and a chain of trust from the root, giving origin authentication and integrity but no confidentiality.
The internet's distributed naming service, resolving names to addresses. It is unauthenticated by default, which is why DNSSEC signs records and why poisoning and tunnelling remain testable.
A cryptographic signature over an email, verified against a public key in DNS. It proves integrity and which domain signed, provides no confidentiality, and survives a plain forward.
The protocol that leases IP addresses and settings such as the default gateway and DNS servers to hosts automatically, with no authentication of the server by default.
An EAP method in which the client and the authentication server each prove their identity with a digital certificate, giving mutual authentication with no password to steal.
Rules at the network edge that limit which traffic may leave, restricting outbound destinations and services and dropping packets whose source address is not the organisation's own.
Forging the sender identity on a message. SMTP verifies neither the envelope sender nor the visible From, so the three forms differ in whether authentication can address them at all.
The wrapping of data from a higher network layer inside the header, and sometimes trailer, of the layer below as it moves down the stack; decapsulation removes them on arrival.
Host-based controls on the device itself, such as hardening, a host firewall, anti-malware, host intrusion detection and endpoint detection and response, complementing network controls.
A Wi-Fi mode that encrypts traffic on an open network with no password, using a key exchange at association, but authenticates neither the user nor the access point.
A wireless attack in which a malicious access point impersonates a legitimate network's name so that users connect to it, placing the attacker in the path of their traffic.
An authentication framework, defined in RFC 3748, that carries many different authentication methods between a device and an authentication server; it is not itself one method.
A converged protocol that carries Fibre Channel storage frames directly inside Ethernet frames, so storage and data traffic share one network, without IP and so without IP routing.
Transmission media that carries data as pulses of light through glass or plastic strands, immune to electromagnetic interference and not radiating the electrical emanations copper does.
A legacy protocol for transferring files that sends credentials, commands and file contents in cleartext over separate control and data connections; commonly replaced by SFTP or FTPS.
A device or software that enforces a policy on traffic passing between networks or into a host, permitting or blocking it by rules based on addresses, ports, state or content.
A denial-of-service attack that sends UDP packets with the victim's spoofed source address to a broadcast address, so every responding host floods the victim with replies.
The File Transfer Protocol with TLS added to encrypt its control and data connections; not to be confused with SFTP, which is a separate protocol built on SSH.
A spoofing technique that registers a domain name built from lookalike characters, often from another alphabet, so a fraudulent site or sender address looks legitimate at a glance.
HTTP carried over TLS, protecting web traffic's confidentiality and integrity in transit and authenticating the server by certificate; it does not prove the site itself is trustworthy.
A layer 1 network device that repeats every signal it receives out of every other port, so all attached hosts share one collision domain and can see each other's traffic.
The IEEE standard for port-based network access control: a device (supplicant) must authenticate through the switch or access point (authenticator) to a server before the port opens.
A device that impersonates a mobile network's base station so that nearby phones connect to it, exposing subscriber identities and, if it forces an older standard, possibly traffic.
In-band management reaches devices over the production network they serve; out-of-band management uses a separate path that does not depend on that network being healthy.
A converged protocol that carries InfiniBand's remote direct memory access (RDMA) transport over Ethernet, commonly implemented as RDMA over Converged Ethernet (RoCE).
Filtering of traffic entering a network, commonly used at the edge to drop packets whose source addresses cannot legitimately arrive from that direction (anti-spoofing).
The IP suite's error-reporting and diagnostic protocol: it carries messages about delivery problems and network status, works at the Network layer, and uses no port numbers.
The protocol IPsec uses to authenticate peers and negotiate security associations, agreeing the algorithms and deriving shared keys through a Diffie-Hellman exchange.
The connectionless Network-layer protocol that carries packets between networks using logical source and destination addresses, with best-effort delivery and no guarantee of arrival.
Layer 3 protocol suite securing IP traffic: AH gives integrity and origin authentication only, ESP adds confidentiality, and tunnel mode wraps the whole original packet for VPNs.
Version 4 of the Internet Protocol (RFC 791), whose 32-bit addresses give a space of about 4.3 billion, now exhausted and stretched by private ranges and address translation.
Version 6 of the Internet Protocol (RFC 8200), with 128-bit addresses written in hexadecimal, no broadcast, and a simpler base header, designed to replace the exhausted IPv4 space.
A converged protocol that carries SCSI storage commands over TCP/IP, letting servers use remote block storage across an ordinary IP network instead of dedicated storage links.
Variation in packet delay over time, so packets of one stream arrive at uneven intervals; it harms real-time traffic such as voice and video more than bulk data transfer.
A hardened, closely monitored host that administrators connect to first and from which they reach systems in a protected zone, giving one controlled path for administrative access.
The time data takes to travel from source to destination, measured one way or as a round trip; it is a delay, distinct from bandwidth, which is a measure of capacity.
A tunnelling protocol that carries PPP frames across an IP network; it provides no strong encryption of its own, so it is commonly paired with IPsec as L2TP/IPsec for VPNs.
A device or service that spreads incoming requests across a pool of servers and removes failed ones from rotation, improving availability and capacity for the service behind it.
A switch attack that fills the MAC address table with forged source addresses so the switch floods frames out of every port, letting an attacker capture traffic meant for others.
A hardware identifier, 48 bits in its common form, assigned to a network interface and used to deliver frames on a local network segment at the Data Link layer.
Applying access policy to small groups of workloads, often a single workload or application, and enforcing it close to the workload rather than only at a network boundary.
One-to-many delivery in which a single transmission reaches only the hosts that have joined a group, rather than one host (unicast) or every host on the segment (broadcast).
A protocol whose functions span several OSI layers, or a suite that nests protocols inside one another; the flexibility also allows covert channels and filter bypass.
A carrier forwarding technique that sends packets along pre-established paths by reading short labels instead of IP addresses; it separates customers' traffic but does not encrypt it.
A very short-range wireless technology, derived from RFID, that lets two devices exchange data when held a few centimetres apart; used for contactless payment, access cards and pairing.
Admission control that authenticates devices and checks their security posture before granting network access, typically via 802.1X, shunting failures to a quarantine VLAN.
Rewriting of IP addresses in packet headers as traffic crosses a boundary device, so hosts on privately addressed networks can reach the internet through public addresses.
Running network functions such as firewalls, routers and load balancers as software on general-purpose servers instead of on dedicated hardware appliances.
A virtual network built on top of an existing physical network by encapsulating its traffic, so separate segments can share one underlying network.
Dividing a network into isolated zones so compromise of one cannot spread laterally; spans physical separation, logical VLANs and firewalls, and workload micro-segmentation.
A 5G capability that runs several logically separate end-to-end networks over the same physical infrastructure, each configured for a different service or customer.
A layer 2 device that forwards frames to the port where the destination MAC address was learned, instead of repeating every frame to every port as a hub does.
The protocol hosts use to synchronise their clocks with reference time sources over a network, which log correlation, Kerberos and certificate checks all depend on.
The arrangement of a network's nodes and links, such as bus, star, ring or mesh, which determines where single points of failure sit and how faults spread.
A firewall that adds application awareness, user identity and integrated intrusion prevention to stateful inspection, so policy can name applications rather than only ports.
North-south traffic crosses the boundary of the network being protected; east-west traffic moves between systems inside it. Both labels depend on which boundary is named.
Seven-layer reference model, physical to application, used to place protocols, devices, and attacks at the layer where they operate; a common framework for classifying them.
Capturing and reading network traffic as it crosses a medium, used legitimately for troubleshooting and monitoring, and by attackers to collect credentials and data.
A method of data communication that splits messages into packets which share network links and are forwarded independently, instead of reserving a dedicated path per call.
A stateless firewall that allows or denies each packet on its own by matching header fields, such as addresses, ports and protocol, against an ordered rule list.
A PPP authentication method in which the client sends its username and password to the server in clear text, with no challenge and no protection against capture or replay.
A direct interconnection between two networks so they can exchange traffic with each other, rather than sending it through a third-party transit provider.
A denial-of-service attack that sends a malformed, oversized ICMP echo request in fragments, so reassembly overflows a buffer and crashes an unpatched system.
A data link layer protocol that frames traffic over a direct link between two nodes and negotiates the link, optional authentication and the network protocols it will carry.
An early VPN protocol that tunnels PPP sessions across an IP network; its usual authentication and encryption pairing has known weaknesses, so it is treated as obsolete.
A form of NAT in which many internal hosts share one public IP address, distinguished by translating each session's source port as well as its address.
An IPv4 address from the ranges RFC 1918 reserves for internal networks: usable by any organisation, and not routed on the public internet.
An EAP method that builds a TLS tunnel authenticated by the server's certificate, then runs a second, password-based EAP method inside it to authenticate the user.
The unit of data that one layer of a network model exchanges with its peer layer: the layer's own header, and sometimes trailer, wrapped around the data from the layer above.
An intermediary that ends a client's connection and opens its own onward connection, so it can filter, cache, log or hide traffic on behalf of clients or of the servers behind it.
Mechanisms that classify network traffic and give chosen classes, such as voice and video, priority for bandwidth, delay, jitter and loss when links are congested.
Identification of tagged objects, badges or people by radio: a reader energises or queries a tag and receives its identifier, often without line of sight or the holder's awareness.
A denial-of-service technique that sends requests to third-party servers with the victim's address forged as the source, so the servers' replies converge on the victim.
A proprietary protocol from Microsoft that gives a user the graphical desktop of a remote Windows system, a common remote administration tool and a frequent target when exposed.
A wireless access point connected to an organisation's network without authorisation, creating an unmanaged wireless way into the wired network that bypasses perimeter controls.
A layer 3 device that forwards packets between separate networks by destination IP address, using a routing table, and separates broadcast domains.
Secure/Multipurpose Internet Mail Extensions: a standard (RFC 8551) that signs and encrypts email messages end to end using X.509 certificates issued through a PKI.
Data links relayed through satellites that cover a wide area, commonly with high latency, where anything sent unencrypted on a downlink can be received anywhere in its footprint.
A profile of RTP (RFC 3711) that encrypts and authenticates voice and video media streams and protects them against replay, with keys supplied by a separate exchange.
A protocol (RFC 4251 to RFC 4254) giving an encrypted, integrity-protected channel for remote command-line login, file transfer and tunnelling, replacing Telnet and rlogin.
The deprecated predecessor of TLS, created at Netscape in the 1990s; the IETF has retired both published SSL versions, though the name survives loosely in phrases like SSL certificate.
A control that inspects users' outbound web traffic and enforces policy on it, typically URL filtering, malware scanning and acceptable-use rules, on premises or as a cloud service.
DNS record listing the servers authorised to send mail for a domain. The receiver checks the connecting IP against the envelope sender's record, so it authenticates the path, not the visible From.
The name of a Wi-Fi network, advertised by access points and used by clients to choose which network to join. It identifies the network but provides no security.
Taking over a session that another party has already authenticated, by capturing or predicting its identifiers, so the attacker is treated as the legitimate user.
The signalling protocol (RFC 3261) that sets up, changes and ends voice, video and messaging sessions over IP. It negotiates calls but does not carry the media itself.
The strength of a wanted signal compared with background noise, usually in decibels; a low ratio means more errors, retransmissions and lower usable throughput on a link.
The protocol (RFC 5321) that sends email from clients to mail servers and relays it between servers. It was designed without sender authentication or encryption.
A protocol for monitoring and configuring network devices: managers query agents for values and agents send alerts. Versions 1 and 2c authenticate only with cleartext community strings.
The password-based key exchange in the IEEE 802.11 standard that WPA3-Personal uses in place of pre-shared key authentication, commonly described as resisting offline guessing.
A denial-of-service attack that sends ICMP echo requests to a network's broadcast address, forging the victim as the source, so every host on that network replies to the victim.
Architecture separating the control plane from the data plane: a centralised programmable controller sets forwarding policy network-wide, and becomes its highest-value target.
An approach that runs a wide-area network from central policy, steering each application's traffic across several transport links such as MPLS, broadband and cellular.
A remote access VPN setting that sends only traffic for the organisation's networks through the tunnel, while other traffic goes straight to the internet from the device.
Forging an identifier, such as an IP address, MAC address, DNS answer or email sender, so that a system or person accepts traffic or a message as coming from a trusted source.
A file transfer and file management protocol that runs as a subsystem of SSH, so commands, credentials and file contents all travel inside one encrypted SSH connection.
A firewall that records each connection in a state table and judges packets in the context of that connection, so replies to permitted sessions pass without separate rules.
A switching method in which the switch receives the whole frame and checks it for errors before forwarding it, trading extra latency for not passing on corrupted frames.
Dividing an IP address block into smaller networks by lengthening the network prefix, so that each subnet has its own address range and a routed boundary to the others.
A denial-of-service attack that sends TCP connection requests and never completes the handshake, filling the target's queue of half-open connections so real clients are refused.
The four-layer model of the internet protocol suite (link, internet, transport and application) that describes how working networks are built and maps onto the seven OSI layers.
A denial-of-service attack that sends IP fragments with overlapping offsets, crashing hosts whose reassembly code mishandles the overlap. The known flaws have long been patched.
A protocol for interactive remote terminal access that sends everything, including usernames and passwords, in cleartext. SSH replaced it for remote administration.
The interim Wi-Fi encryption protocol of WPA, which wrapped WEP's RC4 cipher in per-packet key mixing and an integrity check so existing hardware could be upgraded. Now deprecated.
The SYN, SYN-ACK and ACK exchange that opens a TCP connection, in which each side confirms the other can be reached and the two agree their starting sequence numbers.
The rate at which data is actually delivered across a network path in a given time, as distinct from bandwidth, which is the capacity the link could carry in theory.
The opening phase of a TLS connection that agrees the protocol version and cipher suite, commonly authenticates the server with its certificate, and derives the session keys.
Controlling the rate of outbound network traffic by queuing and delaying packets so flows conform to a set profile, smoothing bursts and protecting priority traffic.
Connection-oriented transport protocol that opens sessions with a handshake and uses sequence numbers, acknowledgements and retransmission to deliver data reliably and in order.
The physical paths that carry network signals: copper and fibre-optic cable, which guide the signal, and radio, microwave and infrared, which send it through the air.
Protocol encrypting sessions above the transport layer: an asymmetric handshake authenticates the server and agrees symmetric session keys; the deprecated predecessor is SSL.
Copper network cable made of insulated wire pairs twisted together to reduce interference and crosstalk, sold as unshielded (UTP) or shielded (STP) and graded by category.
Delivery of a packet from one sender to one specific receiver, identified by a single destination address. It is contrasted with broadcast, multicast and anycast.
Connectionless transport protocol that sends datagrams with no handshake, acknowledgement or retransmission, trading reliability for low overhead and low delay.
One physical network device, commonly a firewall, run as several separate logical instances, each with its own interfaces, routing, security policy and administration.
Layer 2 logical segmentation that splits one physical switch fabric into isolated broadcast domains via 802.1Q tags; separation without new hardware, subverted by VLAN hopping.
A logically isolated network inside a public cloud, whose address ranges, subnets, routing and filtering rules are defined and configured by the customer.
Encrypted tunnel carrying private traffic across untrusted networks; site-to-site links join whole networks through gateways, remote access serves single users, over IPsec or TLS.
A router feature that keeps several separate routing and forwarding tables on one device, so traffic in one instance has no route into another unless routes are deliberately shared.
An attack that sends traffic from one VLAN into another without passing the layer-3 device meant to control it, by switch spoofing or by double tagging on the native VLAN.
Carrying voice calls as packets over IP networks, with a signalling protocol such as SIP to set up calls and RTP to carry the media, sharing the data network's threats.
An overlay protocol (RFC 7348) that wraps layer-2 Ethernet frames in UDP packets so isolated segments can stretch across a layer-3 network; it separates traffic but does not encrypt it.
Moving through an area with a wireless-capable device to discover, record and map wireless networks, their names, security settings and locations, as reconnaissance.
A firewall that inspects HTTP and HTTPS traffic to a web application at layer 7 and blocks requests that match attack patterns or break the application's expected behaviour.
TCP and UDP port numbers 0 to 1023, assigned by IANA to standard services; a port shows the service expected on a connection, not the traffic actually carried.
Wireless local area networking under the IEEE 802.11 standards; Wi-Fi is the industry certification name, and its security comes from WEP, WPA, WPA2 or WPA3.
The 2003 transitional replacement for WEP, using TKIP so existing hardware could be upgraded by firmware; itself now deprecated in favour of WPA2 and WPA3.
The original IEEE 802.11 wireless encryption, built on RC4 with a short initialisation vector and a static shared key; broken, and not to be used.
The device that connects wireless clients to a wired network: it advertises the network, handles association and enforces the Wi-Fi security mode configured on it.
The Wi-Fi security certification based on IEEE 802.11i, with mandatory AES-based CCMP encryption, offered as Personal (shared passphrase) or Enterprise (IEEE 802.1X).
The Wi-Fi security certification that replaces pre-shared key authentication with SAE in Personal mode and requires protected management frames.
A low-power, low-data-rate wireless mesh protocol built on IEEE 802.15.4, commonly used for building, home and industrial sensors; its practical weakness is key handling.