3 ms·
Take a look at DMARC. [1] The webpage is horribly ugly, but essentially, it allows a domain to declare that all their outgoing mail are DKIM-signed and SPF-pass
by cflee 14y ago
Take a look at DMARC. [1] The webpage is horribly ugly, but essentially, it allows a domain to declare that all their outgoing mail are DKIM-signed and SPF-passed.
Paypal and eBay do this. Gmail filters out any DKIM-fail or SPF-fail mails purporting to be from @paypal.com and sends it to spam, with 100% accuracy. Gmail also puts the little 'key' icon next to the sender name, but that's not really important, the point is that any and all fraudulent emails are filtered out with unerring accuracy.
Thus, we don't need to use PGP or whatever, which needs to be handled at the client level. DKIM + DMARC is already here and working at the server level. You don't need to wait for your favourite email client to adopt DMARC.
Yes, if people send emails without going through that SMTP server etc etc.. that's a problem, but also solvable/solved.
[1] http://dmarc.org/ http://dmarc.org/
- gst 14y agoIMO this looks overly complicated, especially as SPF works fine. The only problem with SPF right now is that many receivers (including) GMail don't abide to the specification. If there's an "-all" clause at the end this implies that you must not accept mails from other mail servers than the ones allowed. If you still do - your fault - but don't complain that your users receive mails with faked sender addresses.