Microsoft proposes ID solution for spam

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Microsoft on Thursday is holding a summit with members of the Email Service Provider Coalition to address the use of Sender ID technology as a standard to fight spam and phishing.

The software giant said it would gather more than 80 members of the ESPC coalition at its headquarters to discuss using Sender ID as a way to ensure that email originates from the Internet domain it claims to come from. Fighting the annoyance of spam and the dangers of fraud activity such as "phishing" is among the top concerns of Internet users and the companies that serve them.

Sender ID validates the server Internet Protocol address of the sender to assure an email recipient that a message claiming to be from a credit card company actually is. The technology relies on Microsoft's Caller ID for Email technology and the Sender Policy Framework, authored by Meng Weng Wong, chief technology officer at Pobox.com.

The Internet Engineering Task Force is currently evaluating Sender ID as an industry standard for email authentication. Thursday's meeting will look at what Sender ID can do to control unwanted email and at the challenges the technology will bring to legitimate users of email.

Several companies have already announced plans to roll out products and services that support Sender ID, including Cloudmark, DoubleClick, IronPort Systems, Sendmail, Symantec, Tumbleweed and VeriSign, Microsoft said in a statement.

DoubleClick, which delivers Web advertising, will use Sender ID in the email system it uses to communicate with its customers. Ken Takahashi, DoubleClick's senior director of email operations and ISP relations, said a framework like Sender ID is only part of the solution to controlling unwanted and fraudulent email.

"Since the spam epidemic exploded in the past few years, we have always maintained that a solution could only come from a combination of legislation, technology, industry self-regulation and consumer education."

Companies and individuals are increasingly deluged with spam and phishing scams, in which con artists send email purportedly from a recipient's bank, credit card company or Internet provider requesting sensitive information such as "lost" credit card numbers or passwords "needing confirmation."

Spammers often "spoof" their return addresses -- forging them to make them look legitimate to the recipient's spam filters. This can trick recipients into opening the unwanted mail, because it appears to be from a known contact. The technique also assists in the dissemination of email viruses.

Other efforts
The email problems have sparked efforts by other email giants such as America Online and Yahoo to research their own authentication systems. AOL and Yahoo have technologies in the works, and plan to implement them into their email systems by year's end.

AOL has been testing a system called Sender Permitted From, or SPF, that uses the domain name server (DNS). A company spokesman said SPF tests for outbound mail are currently compatible with SenderID. The company plans to test inbound SPF with SenderID beginning in September. AOL also will test technology supported by Yahoo by the end of the year.

"This isn't an online medal race to see who gets the gold when it comes to spam-fighting," AOL spokesman Nicholas Graham wrote in an email. "We're all on the same team."

As for Yahoo, the Web portal is testing its so-called DomainKeys system for Yahoo Mail. The technology creates an encrypted email address signature and then uses DNS to prove a message verify it came from Yahoo. Recipient email servers must add software to use domain keys.

A Yahoo spokeswoman said the company is also looking into SenderID technology.

"We are evaluating IP-based solutions like SenderID," said company spokeswoman Terrell Karlston. "We are eager to see the results of some rounds of testing by other industry leaders."

CNET News.com's Jim Hu contributed to this report.

Talkback

You want to enable your Windows based SMTP Server to do SPF, SPF2, SenderID and CallerID checks? Download our Aloaha from www.aloaha.com. The above mentioned features are freeware and dont require any license.
Thanks
Frank

via Facebook 31 August, 2004 22:25
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jonathan Hassell

You can find more information on BS 8878 by Jonathan Hassell its lead-author at http://www.hassellinclusion.com/bs8878/ The page includes a...

9 hours ago by Jonathan Hassell on BSI publishes first British web accessibility standard
servermanagement

Thanks for this list. Now I know, what to include on my system to make it more functional.

9 hours ago by servermanagement on Ten flawed products that derail productivity
1000092626

What if it's a 4 car household? The point is, more bandwidth = more things you can do simultaneously, like streaming HD video in one room of the...

10 hours ago by 1000092626 on Virgin Media beats 100Mbps schedule, hikes prices
Gary Burton

No point whatsoever increasing broadband download speed. unless ever server on the net has access to massively up rated throughput. The worlds...

10 hours ago by Gary Burton via Facebook on Virgin Media beats 100Mbps schedule, hikes prices
Random_Error

They're also increasing their TV package prices, whether to help fund this or not.

12 hours ago by Random_Error on Virgin Media beats 100Mbps schedule, hikes prices
Techs UK

How can you set it up wrong to intermittently connect? Should I be asking for more pay? Outlook/Exchange is a breeze.

15 hours ago by Techs UK on Ten flawed products that derail productivity
JamesCheese

And how much did Microsoft pay you for that article?

16 hours ago by JamesCheese on Time for an evil umpire: Google, Microsoft & privacy
JamesCheese

"But how many times have you seen someone make a video call from a tablet?" I do myself a lot. "How often have you seen someone hook up a tablet...

16 hours ago by JamesCheese on Apple and Amazon's tablet rivals don't get it
k0tcs3

I have to disagree with this article. Maybe there is a cultural difference between the US and UK, or maybe your network of friends is less...

16 hours ago by k0tcs3 on Apple and Amazon's tablet rivals don't get it
filthylooker

My thoughts are that there's some space for change in the business world for tablets as destop replacements. I'd contend that the tablet has a...

19 hours ago by filthylooker on Apple and Amazon's tablet rivals don't get it
emrahatilkan

Adobe did not dropped AIR development. It was Flex.

20 hours ago by emrahatilkan on Flash 11 and AIR 3 get a release date
dd2

Company called Synergix ( www.synergix.com ) has a fix for the offline folders issue experienced by Win 7 users. And you can check out...

20 hours ago by dd2 on VPNs, offline files and the simple Windows 7 fix; sometimes
Neil Lawther

I think all your above points are increasingly more invalid. The android ecosystem is open and evolving and maturing day by day. developers are...

21 hours ago by Neil Lawther via Facebook on Apple and Amazon's tablet rivals don't get it
David Meyer

That really is what the European Commission is telling me. To give a precise quote: if a member state turns down the agreement, "ACTA will stay a...

24 hours ago by David Meyer on ACTA's EU future in doubt after Polish pause
MyProffs Proffs

Apple devices are back online in German, take the down, no put them back...

1 day ago by MyProffs Proffs via Facebook on German iPhone, iPad sales temporarily banned
Fat Matt

AAAAAAAAWWWWW MAAAAAAANNN, I spent nearly a grand on my pc now it's gonna be completely outdated.

1 day ago by Fat Matt on Clever on-off switch for graphene. Transistors next?
Vanessa Deagan

I completely disagree with this article. I believe the reason why Google are not successful in the tablet space is because of two reasons: 1....

1 day ago by Vanessa Deagan via Facebook on Apple and Amazon's tablet rivals don't get it
servermanagement

Bravo Infiniserv! Virtual Private Server looks promising and very useful for companies who can't really afford a expensive cloud computing software.

1 day ago by servermanagement on Infiniserv launches Linux-based UK cloud
oneoffreader

Agree with Thinklog, Voice and video talk has been a key feature between all my friends who also use tablets.

1 day ago by oneoffreader on Apple and Amazon's tablet rivals don't get it
Thinklog

Thank you for your article. However, Sir, I must disagree. I regularly use my iPad to make video calls via Skype, and I see no reason to claim that...

2 days ago by Thinklog on Apple and Amazon's tablet rivals don't get it