| reply to message » | post a new message » | e-mail to a friend » |
| Subject: | Email authentication gets closer | ||
| Author: | textor: view profile | all posts by this author | add to favourites | ||
| Date: | 09:06:19 24 June 2004 | ||
The good news yesterday was that the gorillas of the service provider world, Yahoo, Microsoft, AOL and earthlink are going to work together on email authentication. The purpose of this is to ensure that mail from fred@mycompany.com really comes from mycompany.com and is not being spoofed. Without this, blacklists and whitelists such as those operated by spamhause et al are of less than optimum value. Anyone can have their email address spoofed and end up on one of these lists. It has happened to at least one client of ours and it was a pig to sort out!
SPF (AOL and Earthlink) and Caller-ID (Microsoft) are to be combined into a new standard called Sender ID. There was no reason for two standards, as far as I can see as they both essentially did the same thing.
Longer term Yahoo's domain keys standard is a more rigorous solution. I hope they can build this in as an extension to Sender ID rather than a second standard. This will be using public key encryption and will really really prove who the email came from. Sender ID simply certifies that the mail came from one of the mail servers that mycompany users.
Its all good news - albeit about 5 years too late.
I don't think this will be the final solution - spammers will be creating new domains by the thousand so they can send fully authenticated mails. But at least blacklists and whitelises will have much more value.
For people like us who host websites, we have to re-think our services quite fundementally. We often host domain names for our clients while their ISP handles mail. This has to change because domain name hosting and email management are to become closely linked activities. Changes in email have to be reflected immediately in the DNS records. The day when a client could wander off to 123-reg and buy a domain name and forget it for two years are coming to a close.
We are starting to plan our migration away from domain hosting now as domains come up for renewal.
Have to go now guys - my Internet phone just arrived. I will post something tomorrow to let you know how I get on.
Bob
Textor
Email authentication gets closer, textor, 24 Jun 09:06