Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity

    Goodmail, One Year Later

    Written by

    Larry Seltzer
    Published February 1, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      It was a big deal, just about a year ago. AOL announced that it would be implementing Goodmail CertifiedEmail, an accreditation service. The service has been operating, according to Goodmail, since May of 2006.

      The way it works is that Goodmail sets technical and business criteria for e-mail senders. Those who qualify can pay a per-message fee to send specially signed messages that will be escorted around the standard AOL spam filtering procedures. The messages appear in the AOL client with a special display saying that they are certified as being from the purported sender.

      A grass-roots stink was made, engineered by the Electronic Frontier Foundation. Go to DearAOL.com, the home page for the anti-Goodmail revolution, to get their side of it in their own words, but my summary is that the EFF argued that a financial interest in accreditation, and particularly one that had a per-message fee, gave AOL perverse incentives that would result in a degradation of quality in spam filtering.

      There are almost 46,000 signers to their petition (although a large number of these signers have names like “buy vicodin online” and “parts corolla” and link to spam sites).

      Once it made money on each certified message, AOL would have no incentive to maintain its whitelisting service. As a result, small senders of bulk mail, such as small nonprofits, would find their messages blocked and themselves pressured to pony up money to Goodmail and AOL.

      I always thought it was a specious argument. AOL insisted that the revenue cut from Goodmail was bound to be puny and that it was supporting Goodmail not for the direct monies but to decrease its false positives with big commercial senders. This made, and continues to make, sense to me.

      /zimages/4/28571.gifMatt Hines chats with VeriSign Director of Product Marketing Tim Callan about the companys new Extended Validation digital certificates and how they aim to help businesses and end users fight phishing and online fraud. Click here to listen to the podcast.

      So whats happened over the last year? If its really nine months since AOLs been sending out CertifiedEmail, then we should have seen something by now. I decided to ask the major players for their impressions and was surprised that nobody was all that anxious to talk.

      AOL and Goodmail, it seems, dont want an annual round of controversy. All AOL would say is that its on target, whatever that means, and that the process by which senders get themselves on the whitelist has gotten simpler, not more difficult.

      The requirements are interesting, in that they force the sender to think about both policy and technical considerations, but it all looks doable for all but very small senders (“An organizations mail servers must send a minimum of 100 e-mails per month to maintain whitelist status”). Theres actually a large overlap between AOLs rules and the rules set by Goodmail in its Acceptable Use and Security Policy (here in PDF form).

      I asked Goodmail, and it didnt have much to say either, besides its claim that it has “just over 300 sending brands using CertifiedEmail—this in just about half a year of availability.” Incidentally, it also claims to have gone live on Yahoo Mail in December. This is where things got a little confusing.

      First, Goodmail says that it “went live … in December at Yahoo,” but Yahoo tells me that “we recently started testing a CertifiedEmail system which includes transactional e-mails from trusted institutions.” A small exaggeration perhaps, beefing up a test into a deployment.

      Next page: How much Goodmail is going on?

      How much Goodmail is


      going on?”>

      I also checked in with the American Red Cross, which was famously used by both sides as an example in last years Goodmail Flame Wars. Goodmail set up preferential treatment for nonprofits (it turned out to be cheap as opposed to free) and told me recently, as part of the earlier statement about over 300 sending brands using CertifiedEmail, that “[w]e also have a number of nonprofits, such as American Red Cross, Americans for the Arts, Lukemia and Lymphoma Society, and National Center for Missing and Exploited Children, and approximately 80 governmental agencies, ranging from municipal organizations up to federal agencies.”

      When I spoke to the American Red Cross they said that they had been working on setting up Goodmail (not a simple process) and were almost ready to start, but hadnt in fact done so.

      My final test was my sister, a heavy AOL user, who tells me that she hasnt seen anything that sounds like “CertifiedEmail.” It could just be that she doesnt use the right brands, or perhaps she just hasnt noticed the CertifiedEmail stuff. But shes smart and observant and I would think shed remember it, especially in as much as its designed to be noticed. More likely, there isnt a whole lot of CertifiedEmail out there yet.

      Goodmail does claim that by the end of this quarter (March 31, I assume) at least 90 percent of AOLs 22 million users should have seen a CertifiedEmail.

      Im skeptical, especially since the only bank I see in its list of brands is KeyBank—banks were supposed to be the perfect CertifiedEmail customers. I suspect the problems are similar to the Red Cross: Setting up Goodmail on a large e-mail list is not a trivial task—nor should it be—and the real volume is probably not far away.

      So it may be too early to judge Goodmail completely, but I still argue that the absence of any evidence of the catastrophe predicted by the DearAOL crowd shows that it was just bad science fiction to begin with.

      The clearest response I got was from Danny OBrien, activism coordinator at the EFF, who agrees its too early to draw conclusions. He points out, as I had realized on my own, that AOLs business model underwent a revenue transplant over the last year. He argues that as subscription revenues decline, AOL will be more and more tempted to get what it can out of other sources like Goodmail, especially if Goodmail is successful. Its still speculative, but its a better argument than they had last year.

      OBrien worries generally about the point “where Goodmail [or other for-pay certification systems that share with the ISP] starts picking up smaller, commodity ISPs and it becomes collectively harder for senders [to] object to the idea of switching to a pay service.”

      /zimages/4/28571.gifAccording to RSAs annual Consumer Online Fraud Survey, consumers are more afraid than ever before that e-commerce and online banking is putting their data at risk. Click here to read more.

      OBrien shouldnt worry so much. A major part of the Goodmail value proposition is that CertifiedEmail messages appear markedly different from uncertified messages in the client. AOL and Yahoo can do this, as can others with a proprietary mail client, such as GMail. But the typical ISP account that uses SMTP and POP3 and where the user is probably using one of a dozen versions of Outlook or Outlook Express, or perhaps a Mac or Eudora or any of numerous other potential e-mail clients, has no easy mechanism for delivering the software changes to make this possible.

      Those users are no better-served by Goodmail than by more conventional accreditation services like Habeas. This difference also helps to explain why it makes sense for Goodmail to share revenue with its clients.

      Im still bullish on accreditation and Goodmail, although changes to e-mail do seem to take frustratingly long times. There are plenty of open- and standards-based efforts in this area and related ones, such as the Domain Assurance Council, which is attempting to standardize access to reputation services.

      And in the very long term I think that e-mail is the wrong venue for opt-in communications anyway. The sooner all that moves to RSS, which is a pull system from which users can unsubscribe when they wish, the better.

      Security Center Editor Larry Seltzer has worked in and written about the computer industry since 1983.

      /zimages/4/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      More from Larry Seltzer

      Larry Seltzer
      Larry Seltzer
      Larry Seltzer has been writing software for and English about computers ever since—,much to his own amazement— He was one of the authors of NPL and NPL-R, fourth-generation languages for microcomputers by the now-defunct DeskTop Software Corporation. (Larry is sad to find absolutely no hits on any of these +products on Google.) His work at Desktop Software included programming the UCSD p-System, a virtual machine-based operating system with portable binaries that pre-dated Java by more than 10 years.For several years, he wrote corporate software for Mathematica Policy Research (they're still in business!) and Chase Econometrics (not so lucky) before being forcibly thrown into the consulting market. He bummed around the Philadelphia consulting and contract-programming scenes for a year or two before taking a job at NSTL (National Software Testing Labs) developing product tests and managing contract testing for the computer industry, governments and publication.In 1991 Larry moved to Massachusetts to become Technical Director of PC Week Labs (now eWeek Labs). He moved within Ziff Davis to New York in 1994 to run testing at Windows Sources. In 1995, he became Technical Director for Internet product testing at PC Magazine and stayed there till 1998.Since then, he has been writing for numerous other publications, including Fortune Small Business, Windows 2000 Magazine (now Windows and .NET Magazine), ZDNet and Sam Whitmore's Media Survey.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×