ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Anti-spammers seek proof of senders' identity

Paul Festa CNET News.com

Published: 27 Oct 2003 09:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new group will try to reconcile competing methods to thwart spam with a kind of caller ID for email.

The Anti-Spam Research Group (ASRG) of the Internet Research Task Force (IRTF) early this month formed a subcommittee to hammer out differences between a number of competing protocols that all aim to do the same thing: verify that email senders are who they say they are.

With the way things work now under the Simple Mail Transfer Protocol (SMTP), there is no widespread method for that kind of verification. That has led some to calls for the revision or replacement of the ubiquitous protocol.

Proposals for how to achieve email verification without scrapping SMTP abound, and many of those proposals have found their way to the IRTF, which is affiliated with the Internet Engineering Task Force.

These include Sender Permitted From (SPF), the Designated Mailers Protocol (DMP) and Reverse Mail Exchange (RMX). The ASRG's new subcommittee is charged with blending them into a single standard.

The idea behind the related schemes is to change the Domain Name System database so that email servers can publish what IP addresses are associated with them. Internet service providers receiving email can instantaneously verify whether an email originates where it says it does.

The system, if successful, would protect email server and individual address owners from having their addresses falsely suspected of sending spam.

Some efforts to attack the problem, such as the Trusted Email Open Standard, have already launched. But so far, they have failed to gain widespread adoption.

The problem of email address spoofing is a fundamental obstacle to curbing spam, say ISPs and anti-spam companies. Spammers typically cover their tracks by hacking into unprotected email servers, or open relays; by hijacking other email servers; and by falsifying names and email addresses in the email sender field.

ASRG members sounded an optimistic note about the new unification subcommittee and the prospect of solving the spam problem with protocols, rather than legal curbs or economic disincentives that would force people to pay to send email on a per-message basis.

"We can solve spam with a technical solution, rather than by going through the Congress or by implementing micropayments," said Meng Wong, founder and chief technology officer of Philadephia-based email service provider Pobox.com, a backer of SPF and a member of the ASRG subcommittee. "We're all trying to come together on this. Because I think SPF offers a superset of functionality, we're probably going to wind up with something very similar to it by the end of the process."

Earlier this year, Pobox.com estimated that more than 70 percent of the email it processed was spam.

Wong said sender-verification systems would have to work in conjunction with some type of reputation system that would help recipients recognise known spammers' domains.

"Once you have reputation systems that work on the basis of domains, which spammers cannot forge, then no matter how many machines you hack into, you still have to use the spammer's domain," Wong said. "And that's how we'll get you."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
64 out of 149 people found this useful


Full Talkback thread

1 comment

  1. Since I have put controls on my inbox I have recie... John B Ridyard

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Systems Administrator (CCTV)

The key skills, knowledge, and experience selection criteria for the successful Systems Administrator (CCTV) candidate include: - TCP/IP configuring ...

Netapp - NAS Engineer - Sheffield - 38000

The estates you will be working on consist of multi-protocol storage environments presenting NetApp storage to a range of host operating systems ...

Network Engineer - Aberdeen - Up to 50,000

G.729, G.723, G.711 Expert use of protocol analyzers, network sniffers and management tools, and other tools of the trade' Experience with Cisco Call ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment