Just-in-time phishing
AI made it cheap to generate a phishing message for one person, use it once, and adapt every follow-up to the target's replies. Here is what that changes for email detection.
Ben Hathaway
Chief Technology Officer
$ whoami
the mailprotector engineering blog
Field notes from the people building email security at Mailprotector. How we get the good mail through, stop the bad, and keep a few decades of SMTP running, including the long nights that come with it.
// new posts, in your inbox
AI made it cheap to generate a phishing message for one person, use it once, and adapt every follow-up to the target's replies. Here is what that changes for email detection.
Ben Hathaway
Chief Technology Officer
Email is a federated protocol with decades of implementations behind it and an adversary working the gaps on purpose, so the set of things your product has to handle is discovered rather than designed. How we run QA at Mailprotector without a QA department.
Ben Hathaway
Chief Technology Officer
The engineering story behind Shield's Deployment Control release: how deployment and rollout became separate steps, how health checks gate enablement, and the routing redesign that removed DNS from the process.
Ben Hathaway
Chief Technology Officer
Three versions of Shield's mail flow architecture, from a blunt MX record to a design that hands the last mile back to Microsoft, and what changed each time along the way.
Christian Maddox
Senior Software Engineer
Phishing simulations produce compliance artifacts, and that's why they persist even though they don't protect users. The technical case for moving the trust decision off the content an attacker controls.
Ben Hathaway
Chief Technology Officer
A new mail-flow rollout made Microsoft 365 attribute every customer's mail to our tenant. The undocumented rule behind it, and the fix.
Mailprotector
Engineering Team
Why an email security company is starting an engineering blog, and what we plan to put here.
Ben Hathaway
Chief Technology Officer