ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Guarding the digital front door

February 10, 2023
Reading Time: 3 mins read
Larger financial institutions hit by variety of cyberattacks in 2022

By Paul Benda

A key component of any bank’s cybersecurity posture is securing your bank’s domain name. Your domain is where your customers engage and transact with you online, making it critical that you remain in full control over it and that you do everything you can to ensure customers aren’t duped into engaging fraudulent domains acting as your bank.

Domain name security is such an important priority that ABA invested in the creation of the .bank top-level domain—carving out a piece of the internet to be used exclusively by banks, preventing bad actors from having access to domains for use in cyberattacks. (Thanks to the expert-developed .bank security requirements, banks using a .bank domain employ several additional layers of cybersecurity to enhance the protection the domain provides.)

But regardless of what domain your bank uses, ensuring it’s secure is critical. Here are seven top domain name security measures—measures that overlap with the .bank security requirements—that ABA recommends banks have in place. These measures can prevent access to, and abuse of, websites, online banking tools and email systems—the same way you have security measures preventing and monitoring unauthorized access to your bank and areas within it.

1. DNSSEC. DNS is like a phone book for the internet. It has a list of site names (for example, Google.com, CNN.com, or MyBank.com) and their corresponding IP addresses. DNSSEC uses something called digital signatures to ensure that the list of names and numbers is accurate by preventing unauthorized changes to them. This is a critical measure that ensures customers visiting your URL arrive at your site and aren’t redirected to a spoofed website controlled by hackers. These spoofed websites, designed to look like real bank websites, are used for credential harvesting, where customers attempt to log in with their usernames and passwords giving the hackers credentials to their real bank account.

2. Email authentication (SPF, DKIM and DMARC records). Authentication ensures the legitimacy of emails by authenticating the sender and confirming the email was not altered during transit. As more internet service providers and receiving mailboxes adopt stricter policies to protect their customers, senders without authentication will see difficulties with inbox placement and may find themselves and their customers at risk of phishing attacks. SPF is a whitelist of who can send email as your bank (for example, employees, cores and marketing platforms). DKIM adds an encrypted signature to every outbound email enabling email receivers to confirm the email was sent by you and that its content was not altered while in transit. And finally, DMARC is instructions for email receivers (Outlook, Gmail) on what to do with emails from senders not approved in your SPF record or that fail DKIM authentication. (Without DMARC instructions, most malicious emails will be delivered.)

Proper email authentication prevents phishing and email spoofing by ensuring only your bank and those you authorize can send emails as your organization. Email authentication also protects your email against tampering while in transit to the receiver via encryption. And authentication improves deliverability, since all leading email receivers detect the SPF and DKIM records of any incoming message as a feature. If you send an email without authentication protocols, there’s a good chance your users will find your messages in their spam. Properly authenticating emails enhances your sender reputation among email receivers and ISPs, reducing the number of messages labeled as spam and lowering email bounce rates.

3. TLS certificates. TLS, previously known as SSL, is a security protocol that encrypts data transmitted between a website and visitors’ devices. By installing an TLS certificate, organizations can help protect against eavesdropping and tampering.

Learn more about the .bank domain and how it can help strengthen a bank’s cybersecurity posture and customer confidence at aba.bank.
4. Multi-factor authentication. In wide use to prevent use of stolen credentials, MFA requires users to provide additional evidence of their identity, such as a code sent to their phone, in order to access a system. This can help prevent unauthorized access and changes to DNS records and other sensitive information.

5. Monitor DNS activity. Regularly monitoring DNS activity, via DNS logs and network monitoring tools, can help detect and respond to potential threats in a timely manner.

6. Use a reputable DNS provider. Choosing a reputable DNS provider can help ensure that DNS records are managed securely and that the provider has the necessary security measures in place to protect against cyber threats.

7. Use Registry Lock. This service (which is available for .bank domains) can prevent unauthorized DNS record updates (used to redirect website traffic or grant permission for the hacker to send email as your bank), unauthorized transfer of your domain to a new owner or registrar, or the deletion of your domain entirely. All requested changes require your registrar to request the domain to be unlocked by the registry, forcing a manual verification of the changes by the registry with the authorized registrant and ensuring that only authorized personnel are ever able to make domain and DNS changes.

Each of these steps—drawn from cybersecurity experts and overlapping with the security requirements that help make .bank domains secure—is part of a multilayered strategy to secure your bank’s online banking transactions and communications with customers.

Paul Benda is SVP for operational risk and cybersecurity at ABA.

Tags: CybersecurityDot-bankWebsites
ShareTweetPin

Related Posts

FDIC posts sample docs to provide clarity into marketing, sale process of failing banks

FDIC posts sample docs to provide clarity into marketing, sale process of failing banks

Newsbytes
December 31, 2025

Eleven new sample documents were released, covering franchise sales and loan pools, including purchase and assumption agreements, confidentiality agreements and financing terms.

ABA files amicus brief urging Eighth Circuit to reverse district court’s dismissal of NSF fee lawsuit

ABA offers changes to FDIC, OCC proposed safety and soundness rules

Community Banking
December 29, 2025

ABA suggested changes for the agencies' proposed rule regarding unsafe or unsound practices, as well as revisions to the supervisory framework for issuing matters requiring attention and other supervisory communications.

OCC proposes to cite federal preemption of state interest-on-escrow laws

OCC proposes to cite federal preemption of state interest-on-escrow laws

Compliance and Risk
December 23, 2025

The OCC is proposing two rules to clarify that national banks are exempt from state laws regulating real estate escrow accounts. ABA welcomed the proposals.

OCC to merge community bank, large bank supervision departments

OCC proposes to raise heightened standards threshold for banks

Compliance and Risk
December 23, 2025

The OCC is proposing to raise the threshold for which its heightened supervisory standards apply to banks from $50 billion to $700 billion in assets.

ABA urges FinCEN to reevaluate BOI collection burden on banks

FinCEN targets money services businesses along southwest U.S. border

Compliance and Risk
December 22, 2025

FinCEN announced it has taken multi-tiered actions against more than 100 money services businesses along the southwest U.S. border for allegedly failing to comply with anti-money laundering regulations.

Justice Department announces indictments in alleged nationwide ATM jackpotting scheme

Justice Department announces indictments in alleged nationwide ATM jackpotting scheme

Compliance and Risk
December 22, 2025

A federal grand jury in Nebraska has returned two indictments charging 54 individuals for their alleged roles in stealing millions of dollars from bank and credit union ATMs across the U.S., the Justice Department announced.

NEWSBYTES

FDIC updates IDI resolution planning for large banks

January 2, 2026

CFPB opens filing period for 2025 HMDA data

January 2, 2026

FDIC posts sample docs to provide clarity into marketing, sale process of failing banks

December 31, 2025

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: Cybersecurity in a mobile-first banking landscape

December 18, 2025

Podcast: The 2026 outlook for bank M&A

December 11, 2025

Podcast: The outlook for tech-forward community banking

December 4, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.