Recommendations
Get Dropbox!

Social
Suggested Reading
  • Steve Jobs
    Steve Jobs
    by Walter Isaacson
  • The 4-Hour Workweek, Expanded and Updated: Expanded and Updated, With Over 100 New Pages of Cutting-Edge Content.
    The 4-Hour Workweek, Expanded and Updated: Expanded and Updated, With Over 100 New Pages of Cutting-Edge Content.
    by Timothy Ferriss
  • The Power
    The Power
    by Rhonda Byrne
  • The E-Myth Revisited: Why Most Small Businesses Don't Work and What to Do About It
    The E-Myth Revisited: Why Most Small Businesses Don't Work and What to Do About It
    by Michael E. Gerber
  • Blink: The Power of Thinking Without Thinking
    Blink: The Power of Thinking Without Thinking
    by Malcolm Gladwell
  • Think and Grow Rich
    Think and Grow Rich
    by Napoleon Hill
  • The Facebook Effect: The Inside Story of the Company That Is Connecting the World
    The Facebook Effect: The Inside Story of the Company That Is Connecting the World
    by David Kirkpatrick
  • Buddha: A Story of Enlightenment
    Buddha: A Story of Enlightenment
    by Deepak Chopra
  • How To Win Friends and Influence People
    How To Win Friends and Influence People
    by Dale Carnegie
  • The 7 Habits of Highly Effective People
    The 7 Habits of Highly Effective People
    by Stephen R. Covey
  • The Wisdom of Crowds
    The Wisdom of Crowds
    by James Surowiecki
  • Purple Cow: Transform Your Business by Being Remarkable
    Purple Cow: Transform Your Business by Being Remarkable
    by Seth Godin
« The end of instant messaging (as we know it) | Main | ...and who says e-mail spam filtering works? »
Monday
Nov032008

Anti-Fraud is not Anti-Spam

One of the biggest problems with e-mail is the complete lack of an inherent security model. Like the telephone, most people have come to take e-mail for granted; expecting that it simply works. Most e-mail users do not know how easy it is to forge almost every aspect of an e-mail message. We have all received spam that, when viewed in our e-mail client (Outlook, Entourage, Gmail, etc.) appears to have been sent to us, from us. How can this happen?

There is a common misconception amongst many in the e-mail security space that anti-fraud technologies like Sender Policy Framework (SPF), SenderID and Domain Keys Identified Mail (DKIM) are part and parcel anti-spam technologies. While it is true that anti-fraud/anti-forgery technologies have a nice side-effect of preventing some spam, this is not their main goal. In addition, by lumping these imporant technologies in as simply anti-spam misses the point and tends to dimish the importance of these technologies.

Protecting your domain from e-mail forgery is up to you; the owner of the domain. Does your domain publish a Sender Policy Framwork (SPF) record (http://www.openspf.org/)? If not, why? What are you waiting for? Is your inbound e-mail checked to see if the sender's domain publishes a SPF record? If not, why? After all, if the sender's domain administrator has elected to take domain forgery seriously, you should as well. Finally, are you recognizing DKIM (http://www.dkim.org/) signatures for inbound e-mail and is your e-mail server signing outbound e-mail?

In case you are wondering... Google, eBay, Yahoo, Cisco, and many other large companies are now on the DKIM bandwagon.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>