Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Google Joins Yahoo, AOL in Adopting Stricter Email Authentication

    Written by

    Jaikumar Vijayan
    Published October 21, 2015
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Google is tightening its policy for handling emails that fail the authentication checks of the Domain-based Message Authentication, Reporting & Conformance (DMARC) standard.

      Starting June 2016, Google’s policy will be to reject outright all emails that fail the DMARC checks to protect against domain spoofing attacks, a company executive said Tuesday.

      “Google is committed to email authentication,” John Rae-Grant, lead project manager for Gmail, said in a statement issued by DMARC.org Tuesday. “In June of 2016, we will be taking a big step by moving gmail.com to DMARC policy p=reject,” Rae-Grant said, referring to the stricter policy standard the company will begin using.

      Google is joining Yahoo and AOL in implementing stricter DMARC, which is a widely used standard designed to let email receivers and senders verify if a message is really from a purported sender or not. It provides policies that organizations can use to decide what to do with an email message that fails the authentication tests implemented under the standard.

      Yahoo and AOL have claimed huge success in combating email fraud by using DMARC to reject emails containing their domain names but originating from external email servers. Yahoo’s initial success with DMARC recently prompted the company to announce plans to extend use of the standard to its Ymail and Rocketmail services as well.

      With Google’s proposed policy change next year, the company too will instruct all email servers and services to reject messages from gmail.com that either do not originate from its servers or fail other DMARC authentication checks.

      DMARC was developed as a way to combat fraud resulting from email address spoofing. This is a type of fraud where attackers forge real email addresses and use them to send spam and phishing emails to victims who often fall for the hoax because the emails appear to originate from sources they trust.

      DMARC offers a mechanism for authenticating the origin of an email and allows receivers to either quarantine, report or reject messages that fail the checks. Domain owners and email services can use DMARC to instruct other email servers on how to handle messages that appear to be coming from their domain but fail the authentication checks.

      As part of the transition, Google will adopt a recently developed protocol dubbed Authenticated Received Chain (ARC) to enable mailing list operators and other legitimate email forwarding services to deal with the stricter DMARC policy.

      Currently, many legitimate emails sent by forwarding services and mailing lists are rejected because they fail DMARC checks. The ARC protocol is designed as a way around the issue by giving such services a way to authenticate forwarded emails in a manner that is compliant with DMARC’s checks.

      “What happens with ARC is the mailing list is able to say ‘hey I got this message, it checked out okay, but I’m making changes to it so [DMARC authentication] won’t work,'” said Steven Jones, executive director of DMARC.org. The ARC protocol allows such services to securely declare their involvement in the forwarding of an email, so that email servers don’t reject the emails, Jones said in a conversation with eWEEK.

      Jones described Google’s decision to start rejecting emails that fail DMARC checks as a significant step forward in combating email fraud. The more the domains that adopt the stricter DMARC policy, the harder it becomes for people to impersonate domains. “It raises the bar a bit on the amount of effort it takes to spoof an email,” Jones said.

      Jaikumar Vijayan
      Jaikumar Vijayan
      Vijayan is an award-winning independent journalist and tech content creation specialist covering data security and privacy, business intelligence, big data and data analytics.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×