Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Spammers use sender authentication too, study says

They've adopted the technology faster than legitimate e-mail senders

August 31, 2004 12:00 PM ET

IDG News Service - New technology for identifying the sender of e-mail messages hasn't been widely adopted, despite backing from software giant Microsoft Corp., and it may not be effective at stopping spam, according to a survey by e-mail security company CipherTrust Inc.
A check of approximately 2 million e-mail messages sent to CipherTrust customers between May and July showed that only about 5% of all incoming messages came from domains that published a valid sender authentication record using the Sender Policy Framework (SPF) or a newer standard backed by Microsoft called Sender ID. Within that 5%, slightly more is spam than is legitimate e-mail, said Paul Judge, chief technology officer at the Alpharetta, Ga.-based company.
Sender ID is a technology standard intended to close loopholes in the current system for sending and receiving e-mail that allow senders -- including spammers -- to fake, or "spoof," a message's origin. Organizations publish a list of their approved e-mail servers in the Domain Name System. That record, referred to as the SPF record, is then used to verify the sender of e-mail messages sent to other Internet domains using Sender ID.
Tens of thousands of Internet domains have published SPF records since the standard was introduced by Meng Weng Wong, chief technology officer at Pobox.com. In May, Microsoft and Meng reached an agreement to merge SPF with a Microsoft-developed standard called Caller ID to form the new Sender ID standard, which Microsoft submitted to the Internet Engineering Task Force in June for approval.
Sender ID is fast becoming the de facto e-mail authentication standard, as Microsoft rallies support from e-mail providers, Internet service providers and e-mail software vendors. But the survey casts doubt on whether Sender ID or its predecessor, SPF, can put an end to spam, Judge said.
"The idea that SPF would point to legitimate e-mail because spam would fail SPF checks is not true, because spammers have rolled out [SPF] records, too," he said. "In fact, three times more spam passes SPF checks [than] fails it, so passing or failing an SPF check is not a strong indicator that messages are spam."
The problem is that spammers have been faster to adopt the technology than legitimate e-mail senders, Judge said. "Spammers are now better than companies at reporting the source of their e-mail," he said. In fact, of the messages that pass an SPF check, 34% more are spam than legitimate e-mail, according to the CipherTrust survey.

Judge acknowledged that the CipherTrust survey covers only a small sample of the billions of e-mail


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

Why Now is the Right Time for the Linux Desktop
(Source: Novell) Faced with tighter budgets, enterprises are rethinking their desktop strategies to deliver the same - if not better - services and...

Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
This white paper reviews the current state of enterprise application architecture and presents a prediction on what might come next....  

Novell Opens PR Video
Is the Linux desktop for me? Customers are looking for ways to be more flexible and save money. Using Linux offers a great...

SUSE Linux Enterprise Server Deployment Approach Guide
This document is intended for IT professionals and managers who are considering deploying SUSE Linux Enterprise Server. Novell has had a number of...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

SUSE Linux Enterprise Desktop Data Sheet
SUSE Linux Enterprise Desktop is the market's only enterprise-quality Linux desktop ready. It delivers seamless interoperability with existing enterprise systems and dozens of...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

SUSE Linux Enterprise Server Data Sheet
SUSE Linux Enterprise Server is a highly reliable, interoperable and manageable server operating system built to power mission-critical workloads in physical and virtual...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....