Email Communications Security Assessment (MECSA)

Do you know the EU online tool for email communications security assessment?
It is obviously checking security criteria of a specific email address (and its provider).
https://mecsa.jrc.ec.europa.eu/de/

I’ve just tried it and find the result alarming:
The first screenshot with all the warning colours was my email with Sitejet, the second (all green) my email with GMX (free).

Sitejet team: any solution for this?

2 Likes

Hi @Andre ,

I am still missing any information about this topic.
I’ve just checked my email address via Sitejet on https://mecsa.jrc.ec.europa.eu/ and the result is really not good.

Hey @Barbara_Bichler thank you for the ping. The internal info fell right into my holidays back then and then it slipped through.

So: This is another vote for the DMARC feature which is now on our Roadmap for the rest of the year. :slight_smile:

Long story: Our mail server isn’t meant to be used like “Gmail” or any of these freemail services and it’s just an additional feature, we dont compete with Gmail and Co in this scenario

As for “phishing and identity theft” its usually the receiving server that does “detect spam”, what we do is “whitelist” our server in databases used for filtering “valid” mail senders.

Nowadays essentially all mail is treated as spam unless its sent from a verified email server, than its further filtered based on content by the receiving server. So hopefully, we can make a big improvement here with DMARC as well.

You can run the address through MECSA and check the score, then keep an eye on the DMARC rollout on the roadmap. I’d focus on the receiving side for phishing risks.