Skip Links

Network World

  • Social Web 
  • Email 
  • Close

E-mail authentication - one way or another

Net execs are struggling with a proliferation of imperfect standards.
By Deb Radcliff , Network World , 12/26/2005

E-mail authentication is not an either/or proposition. As ISPs, e-mail service providers and businesses struggle to protect their brands and customers, they're adopting any e-mail authentication method that can put the kibosh on spam and phishing, even if it is less than ideal. IT executives aren't deterred by a lack of standardization, despite the often-contentious back-and-forth among developers over the issue.

Sender Policy Framework (SPF) and Sender ID are widely in use despite being ineffective at ending spam (they issue false positives on legitimately forwarded messages). Adoption of the newer DomainKeys Identified Mail (DKIM) is going forward at a steady pace. False positives are a concern here, too, when third-party mailers send e-mail on behalf of business domains. Also at issue is back splatter, meaning return-to-sender spam.

Unfortunately, spammers are still winning the battle - and even rely on e-mail authentication in the process. Almost all spammers use published SPF records, according to a Forrester Research report issued in October. MX Logic, a spam-filtering service provider, determined that 83% of the spam it trapped over a test period in August came from domains with published SPF records. Of the 0.12% of domains that published their Sender ID records that month, 85% of them were spam-sending domains.

"Authenticated spam is still spam," says Max Christoff, vice president of enterprise applications for a Fortune 50 financial-services company in San Francisco that asked not to be named because of corporate policy. "Anyone under the authenticated Hotmail domain can keep opening new Hotmail accounts, get neutral starting ratings and send spam from those accounts until they get shut down." The same goes for DKIM, he adds. All spammers have to do is open new domains and attach their own cryptographic DomainKeys to them, and they can correctly and legitimately send e-mail.

But, counters Dave Wright, senior vice president of e-mail infrastructure at Bank of America, "at the very least, authenticated e-mail can prove to mail gateways that this mail really does come from BankofAmerica.com." Wright uses DKIM-authenticated e-mail between Bank of America and its large business customers. "There's a lot to win in this scenario, because ISPs can provide better service for their customers. And enterprises win, because their customers are getting fewer phishes and spam," he says.

Partner Content

NetScout is one of the world's premier providers of integrated network and application performance solutions.

www.netscout.com

Know First

Get Proactive — Move from Troubleshooting to Monitoring to Management with nGenius K2's Service Dashboard & Intelligent Early Warning Alarms

Watch the Video

Know Where

Get Rapid Performance Problem Isolation with nGenius Performance Manager and Diagnose Problems up to 70% Faster!

Learn More

Know Why

Get the Details to Validate and Solve your Toughest Performance Issues with nGenius InfiniStream and Sniffer Intelligence Modules

Read the Whitepaper

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

why is all the hubbub about this guy blocking access to everyone else? Worst case they can contact the...- Anonymous

Join the Discussion