<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Community Notifications Email Address to Change in Welcome</title>
    <link>https://community.isc2.org/t5/Welcome/Community-Notifications-Email-Address-to-Change/m-p/46585#M2018</link>
    <description>&lt;P&gt;Your IT admins or&amp;nbsp;community&amp;nbsp;admins might sometimes&amp;nbsp;send&amp;nbsp;you&amp;nbsp;notifications&amp;nbsp;in If you are a member&amp;nbsp;of&amp;nbsp;multiple networks, you must&amp;nbsp;change email.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jul 2021 09:47:52 GMT</pubDate>
    <dc:creator>Deanna845</dc:creator>
    <dc:date>2021-07-23T09:47:52Z</dc:date>
    <item>
      <title>Community Notifications Email Address to Change</title>
      <link>https://community.isc2.org/t5/Welcome/Community-Notifications-Email-Address-to-Change/m-p/46048#M2010</link>
      <description>&lt;P&gt;&lt;SPAN&gt;(ISC)² Community users, &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Please be aware, the email address used to send automated notifications from the community will be changing to the following address: &lt;/SPAN&gt;&lt;A href="mailto:community@notifications.isc2.org" target="_blank"&gt;community@notifications.isc2.org&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The purpose of this change is to conform to best practices and to ensure email deliverability. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This change will occur on June 21, 2021.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 18:46:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Community-Notifications-Email-Address-to-Change/m-p/46048#M2010</guid>
      <dc:creator>AndreaMoore</dc:creator>
      <dc:date>2021-06-16T18:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Community Notifications Email Address to Change</title>
      <link>https://community.isc2.org/t5/Welcome/Community-Notifications-Email-Address-to-Change/m-p/46056#M2011</link>
      <description>&lt;P&gt;Wanted to share some background on why I suspect (ISC)² is making this change.&amp;nbsp; I encourage you to check your own company to see if you can leverage the lessons that I learned and that&amp;nbsp;(ISC)² is presumably learning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First, SPF (email source validation) has a limit&lt;/STRONG&gt; of 10 DNS queries per invocation.&amp;nbsp; As currently written,&amp;nbsp;(ISC)²'s SPF is right at this limit.&amp;nbsp; I would bet money that&amp;nbsp;(ISC)² has occasionally gone over this limit, resulting in customer (member) complaints that expected email was not arriving.&amp;nbsp; To check your own zone check out&amp;nbsp;&lt;A href="https://dmarcian.com/spf-survey/" target="_blank" rel="noopener"&gt;https://dmarcian.com/spf-survey/&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Second, "@isc2.org" authorized senders&lt;/STRONG&gt; has at least 6 vendors authorized to send email forged from any&amp;nbsp;(ISC)² employee.&amp;nbsp; By creating separate "domains" for each vendor (@notifications.isc2.org; @salesforce.isc2.org; @events.isc2.org, etc), separate accountability is maintained for each vendor.&amp;nbsp; Ideally, (ISC)² will eventually whittle it down to only o365 being authorized to send email under their employees' addresses (e.g. &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/274173181"&gt;@isc2&lt;/a&gt;.org).&amp;nbsp; Plus, it bifurcates the SPF query-limit issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Third, DNS has a size limit.&lt;/STRONG&gt; "Normal DNS" uses UDP which is limited to 512 byte answers.&amp;nbsp; When people look up "isc2.org", the answer is 645 bytes long.&amp;nbsp; Therefore, queries must be repeated using TCP.&amp;nbsp; Although this is a perfectly acceptable part of the standard, it is also encountered relatively rarely.&amp;nbsp; Therefore, one is using code in browsers, operating systems firewalls, etc. that is much less thoroughly tested.&amp;nbsp; As a result,&amp;nbsp;&amp;nbsp;(ISC)² is likely involved in much more than their share of issues with customers connecting to&amp;nbsp;(ISC)².&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In large part, this is caused by (ISC)² having at least 9 site-verifications tied to isc2.org (e.g.&amp;nbsp; isc2.org txt&amp;nbsp;&lt;SPAN&gt;MS=ms94814359).&amp;nbsp; Although site verification is a "good thing", it also increases&amp;nbsp;(ISC)²'s risk as I now know who I need to impersonate for a good phish.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The solution is to ask your vendors to support putting the domain validation on its own record (e.g. &lt;U&gt;&lt;STRONG&gt;ms.&lt;/STRONG&gt;&lt;/U&gt;isc2.org txt&amp;nbsp;MS=ms94814359) and also to remove the record immediately after validation has been completed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note that the above is based on my similar experiences.&amp;nbsp; I do not have any particular insight into the inner workings of&amp;nbsp;(ISC)².&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 18:53:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Community-Notifications-Email-Address-to-Change/m-p/46056#M2011</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2021-06-17T18:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Community Notifications Email Address to Change</title>
      <link>https://community.isc2.org/t5/Welcome/Community-Notifications-Email-Address-to-Change/m-p/46585#M2018</link>
      <description>&lt;P&gt;Your IT admins or&amp;nbsp;community&amp;nbsp;admins might sometimes&amp;nbsp;send&amp;nbsp;you&amp;nbsp;notifications&amp;nbsp;in If you are a member&amp;nbsp;of&amp;nbsp;multiple networks, you must&amp;nbsp;change email.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 09:47:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Community-Notifications-Email-Address-to-Change/m-p/46585#M2018</guid>
      <dc:creator>Deanna845</dc:creator>
      <dc:date>2021-07-23T09:47:52Z</dc:date>
    </item>
  </channel>
</rss>

