Will Yahoo block messages that aren't signed? - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

BitTorrent blocking; SQL injection attack. Listen now!

Network World 360

Hacker writes Cisco rootkit; Microsoft launches online telescope. Listen now!

Network World 360

Additional Resources

RSS

FEATURED WHITEPAPERS

Fill the Gaps in Your Disaster Recovery Plan with Single Object Recovery for Active Directory NetPro

Most companies have a solid disaster recovery plan in place to handle a "complete failure" of its Active Directory, which is really quite rare. What most recovery plans are missing, and the most common scenario, is a means to efficiently restore single directory objects. In this paper, we'll explore what most disaster recovery plans already address, highlight potential weak points, and suggest solutions that help fill those gaps-without requiring you to completely re-do your existing plan.

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Discover how to Create an Orchestrated Data Center through Virtualization Novell

IT professionals like the idea of consolidating hundreds of servers into only a few, but it takes a lot more to cost effectively consolidate and virtualize servers. Watch this six-chapter webcast, "Reduce Complexity and Cost - Windows Server Consolidation with Virtualization" to learn how to effectively consolidate your Windows environment. One of the themes explored includes the characteristics of an orchestrated data center, which includes: Resource management, dynamic provisioning, job management, policy management, accounting and auditing and real-time availability. Learn more about orchestration and much more today. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

vfhnbn m- Anonymous

Join the Discussion

Will Yahoo block messages that aren't signed?

Yahoo Mail exec explains plans for non-authenticated e-mail
By Carolyn Duffy Marsan , Network World , 02/11/2008
  • Social Web 
  • Email 
  • Feedback 
  • Close

E-mail authentication is on the rise, and much of the credit goes to Yahoo.

Yahoo came up with the idea of authenticating e-mail at the domain level, rather than with the IP address. Yahoo dubbed this concept DomainKeys and promoted it in the open source and standards communities. The IETF completed the DomainKeys Internet Mail (DKIM) standard last year, and corporate adoption is rising rapidly (Read our featured story on the rise of DKIM.)

Network World Senior Editor Carolyn Duffy Marsan interviewed Mark Risher, anti-abuse product manager for Yahoo Mail, about the benefits Yahoo is seeing from DKIM. Here are excerpts from our conversation:

How does DKIM fit in Yahoo's antiphishing strategy?

We have 260 million users; we're the largest single e-mail provider. As such, we're able to witness a broad swath of the Internet and take steps to protect our users. One of those steps was the invention of DomainKeys, which we released open source to the industry as a whole. This is a technology that we feel is needed to protect e-mail users across the Internet, not just Yahoo users. We found a lot of interest in DomainKeys both from companies sending mail on their own behalf such as PayPal as well as e-mail service providers who handle marketing campaigns for others. They all are finding some value in being able to authenticate a message back to them and to prove that the e-mail message did originate from the sender. This technology is something we felt would be very helpful for receivers so we can confer special privileges to a message. For this other message that lacks a signature, we can penalize it. We can treat it with more suspicion and run it through additional filters.

How widely is DomainKeys used?

We have seen aggressive uptake of DomainKeys. More than 40% of our inbound traffic to Yahoo Mail is using DomainKeys. That's more than 1 billion messages a day with the open source version. DKIM is its successor. We're starting to see DKIM deployed. Mail senders, both private companies and e-mail service providers, are adopting one or both technologies in parallel. These companies are starting to reach out to Yahoo to say that they are signing their messages, and they want us to start treating signed messages with special privileges or penalize messages that aren't signed. I don't have the statistic at the tip of my fingers about how much of our mail is DKIM signed, but we're seeing it rise dramatically. Within 18 months, all of the top financial institutions will use DKIM.

1 | 2 | 3 | 4 |  Next >
Comments (3)
Login
Forgot your account info?

Nice Idea - Poor ImplementationBy Anonymous on March 26, 2008, 2:12 pmPerhaps the author of this article and Network World should look at the other side of Yahoo's plan. Eliminate all small mail servers on the planet and acquire all...

Reply | Read entire comment

A DKIM-Signed phishing email sample, sent from Yahoo themselves.By Anonymous on February 20, 2008, 9:56 amHere's a DKIM-Signed authentic Phishing email orignating from Yahoo's own servers today - I've had at least one every day for over TWO YEARS now, and I've complained...

Reply | Read entire comment

RE: Will Yahoo block messages that aren't signed?By Chris on February 20, 2008, 9:49 amYahoo are hypocrites - I get daily authenticated spam from their broken overseas servers, and no matter how often I forward it to them, they never cut off their...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code