Banks, Internet companies team up to fight spam

Image
Reuters Boston
Last Updated : Feb 02 2013 | 11:04 AM IST

Some of the world's biggest Internet companies and financial services firms have developed a new approach to fighting email spam that they hope will reduce online scams.

Facebook, Google and Microsoft have joined with financial firms Bank of America, Fidelity Investments and eBay's PayPal to create a set of industry standards for preventing criminals from sending out spam emails that appear to come from corporate email addresses.

Fraudsters often pose as banks and other trusted firms in attempts to persuade email recipients to provide payment card numbers, bank account information and other personal data or click on links that infect computers with malicious software.

The new approach calls for email providers and businesses to attack spammers by coordinating on a massive scale the use of two existing technologies for email authentication known by the acronyms SPF and DKIM, which have yet to be widely adopted.

PayPal is one company that currently uses SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) technology standards to fight email spoofing, but only through partnerships with Yahoo and Google, said Brett McDowell, a security manager at PayPal who serves as chairman of the group that developed the new standard.

The group goes by the name DMARC.org, which stands for Domain-based Message Authentication, Reporting and Conformance.

If Yahoo or Google get an email claiming to come from PayPal that is not properly authenticated with SPF or DKIM, the email is not delivered, he said. But if fraudsters send spoofed PayPal email to other email providers, it might get through.

"What we need is an Internet standard that allows this level of protection to work at scale - without any discussion, without any partner agreements," McDowell said. "That is what DMARC does."

Other companies involved in the group include American Greetings, LinkedIn and Yahoo as well as privately held Agari, Cloudmark, eCert, Return Path and the Trusted Domain Project.

IDC security analyst Michael Versace said that the approach recommended by the group appeared to be effective and inexpensive to implement.

Yet he said that the industry should keep developing new technologies to fight spammers because he expects that cyber criminals will eventually figure out how to circumvent the DMARC protections.

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Jan 30 2012 | 12:00 AM IST

Next Story