On CNET: Do more with Pandora
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Sep 8, 2004 10:30:00 PM

With few junk e-mail filters supporting a protocol for verifying the source address of digital messages, spammers have adopted it themselves as a way to appear more legitimate, according to a report released on Wednesday.

The author of the study, e-mail services provider MX Logic, analyzed nearly 10 million bulk e-mail messages that it had filtered on behalf of its clients in late August. The company found that nearly a sixth of the sources of the junk messages used a protocol known as Sender Policy Framework (SPF) to certify that the e-mail addresses used in the messages were real.

While SPF has been touted as a way to stop spam, the data has shown that the true value of the protocol is more about preventing fraud, said Scott Chasin, chief technology officer of the Denver company.

"Authentication (with SPF) by itself is not a spam cure-all," Chasin said. "SPF--as it relates to having an impact on spam--will hurt only those who spoof domains. You are still going to need content filtering to see if the message was unsolicited."

SPF is one of two technologies currently being considered as part of a hybrid method, dubbed Sender ID, for certifying the source of e-mail messages. Another technology, Microsoft's Caller ID for E-mail, makes up the other half of the proposed standard. Because it used technology that Microsoft is attempting to patent, Sender ID may require that users sign a license from the software giant, which has angered many project groups in the open-source world.

That debate has caused many Internet engineers and mail administrators to take another look at SPF, created by Meng Wong, the founder of e-mail service firm Pobox.com.

The Internet Engineering Task Force, the technical committee creating the standard, debated the issues extensively over its e-mail list during the last two weeks.

MX Logic's Chasin argues that SPF does not really solve the problem of spam--at least not until there are supporting services to provide a measure of the reputation of the various e-mail senders.

"SPF is great at combating fraud such as phishing," he said. Phishing is the Internet scam that usually uses e-mail designed to look as if it came from an official organization, such as a bank or government agency, to elicit personal data. "Phishing attacks are all about spoofing someone's domain name."

The majority of the SPF users found that spam was coming from "gobbledygook" domain names, not from legitimate companies, he said.

Chasin argues that new services are needed to give e-mail recipients a measure of the reputation of the sender. Such services would basically certify that certain servers belong to "good" e-mail senders, allowing message-filtering software to classify such e-mail as legitimate.

"The e-mail filters could then let through legitimate e-mail," he said. "It would be 'guilty until proven innocent.'"

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 22 Talkback(s)
Send me your complaints
"FreeBSD,"

You're a longtime user, and if you have complaints about the new design, I'd love to hear them. Please send them to me directly.

Stephen Howard-Sarin
VP, ZDNet.com
shs@zdnet.com... (Read the rest)
Posted by: S.Howard-Sarin Posted on: 09/13/04 You are currently: a Guest | | Terms of Use
Chump talk  ParadigmOdyssey | 09/08/04
chump post  DarbyOhara | 09/09/04
Does a Secret Decoder Ring come with that post ?  BitTwiddler | 09/09/04
Your message reads...  balsover | 09/09/04
What language is that? I speak English.  CobraA1 | 09/09/04
Huh?!?!?!  UncleBubba | 09/09/04
Your post reads like just like...  flatliner | 09/09/04
Abracadabra  ParadigmOdyssey | 09/09/04
By The Way  ParadigmOdyssey | 09/09/04
SPF is working  mholm@... | 09/09/04
I agree, spammers publishing SPF is GOOD!  CobraA1 | 09/09/04
paid email will not work  V Sanders | 09/09/04
This isn't paid email  CobraA1 | 09/09/04
This *IS* paid email.  voiceofreason_z | 09/09/04
So now we know who the spammers ARE  d_jedi | 09/09/04
SPF working perfectly  Nigel Johnstone | 09/09/04
MS can be hard coded  Nigel Johnstone | 09/09/04
Microsoft obstructing SPF?  d_jedi | 09/09/04
Yes they are+ SPF info  Nigel Johnstone | 09/09/04
To give you an idea of how easy SPF is  Nigel Johnstone | 09/09/04
ZDNET's designers should be fired  FreeBSD | 09/10/04
Send me your complaints  S.Howard-SarinZDNet Moderator | 09/13/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
advertisement
Click Here