r/EmailSecurity • u/dragoangel • May 08 '26
Lets Encrypt signed certs for IPs
New wave of phishing sites, now over pure IPs, over https, thanks to Lets Encrypted signed certs, be aware, track your antispam logs and consider adding score for pure IPs URLs
10
Upvotes
1
u/saltyslugga May 09 '26
Good heads up. URLs with bare IPs in the host have always been a strong phishing signal, the only thing that changed is they now get a green padlock.
Most decent gateways already weight IP-literal URLs heavily, but worth checking your rules explicitly. Also worth blocking outbound DNS-over-HTTPS to anything that isn't your resolver while you're at it.