* Identified Internet Mail specification
endif; ?>Identified Internet Mail combats fraud
By Jim Fenton
The proliferation of spam, e-mail fraud and messages with malicious attachments is a serious problem for businesses and consumers. While various e-mail filtering technologies can reduce the quantity of spam that finds its way to in-boxes, spam and virus senders still can disguise the true source of e-mail or make it appear as if messages came from entities the recipient trusts – such as a bank.
The Identified Internet Mail (IIM) specification was submitted to the IETF as an Internet draft in July 2004 and is under review. IIM provides new protection that can help stem the tide of unwanted and harmful e-mail. Compared with other signature-based approaches, IIM offers a more reliable way to authenticate messages and is designed to provide scalability for authorizing large numbers of public keys. IIM enables e-mail systems to confirm that a sender is authorized to send messages using a specific e-mail address and that the original message has not been altered by an unauthorized user.
In a typical IIM use, the sending e-mail domain’s outgoing mail server, known formally as a mail transfer agent (MTA),”signs” the message by inserting a new header with the sending user’s signature and the public key to be used to verify it. The key used for signing the message is one that has been authorized by the domain administrator for the specific e-mail address or for the entire e-mail domain. Alternatively, a mail user agent (MUA), software used by the message writer or reader, or mail submission agent, a type of MTA that authenticates the message sender, can sign the message.
For the complete article, please go to:
https://www.nwfusion.com/news/tech/2005/011005techupdate.html?nlt




