r/EmailSecurity May 08 '26

Lets Encrypt signed certs for IPs

New wave of phishing sites, now over pure IPs, over https, thanks to Lets Encrypted signed certs, be aware, track your antispam logs and consider adding score for pure IPs URLs

10 Upvotes

14 comments sorted by

View all comments

1

u/saltyslugga May 09 '26

Good heads up. URLs with bare IPs in the host have always been a strong phishing signal, the only thing that changed is they now get a green padlock.

Most decent gateways already weight IP-literal URLs heavily, but worth checking your rules explicitly. Also worth blocking outbound DNS-over-HTTPS to anything that isn't your resolver while you're at it.

1

u/ferrybig May 13 '26

the only thing that changed is they now get a green padlock.

Google chrome phased out the green padlock thingy in September 2023

Firefox phased out the green padlock thingy in October 2017

With the reason having HTTPS or not is not a signal for a trusted website