iEntry 10th Anniversary Forum Rules Search
WebProWorld
Register FAQ Calendar Mark Forums Read
Webmaster Resources Discussion Forum Sitemaps and robots and logfiles -- Oh My! If you have any questions, comments, concerns and/or ideas about the tools currently available to webmasters to make their lives... 'easier'. Here's where you need to be. Know of a good tool? Post it here. Got something funny in your logfiles? Maybe we can help.

Share Thread: & Tags

Share Thread:

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-19-2008, 09:26 PM
spiderbait's Avatar
WebProWorld Pro
 
Join Date: Oct 2003
Location: Gibsons, BC, Canada
Posts: 271
spiderbait RepRank 5spiderbait RepRank 5spiderbait RepRank 5spiderbait RepRank 5spiderbait RepRank 5spiderbait RepRank 5
Default Protect Your Domain's Email Reputation

I figure that there's a lot of confusion around the various sender authentication protocols and frameworks that are out there, so it's worth posting this as a specific thread to help people research and understand them.

Definition:
Quote:
Originally Posted by Wikipedia
E-mail authentication greatly simplifies and automates the process of identifying senders. After identifying and verifying a claimed domain name, it is possible to treat suspected forgeries with suspicion, reject known forgeries, and block e-mail from known spamming domains.
Taken from Wikipedia
In plain English for domain owners, this can help you in at least 2 ways. First, it allows you to prevent forged or spoofed email sent by others from damaging your domain's email reputation (and keeps you from dealing with many of the bounces those forged emails cause). Secondly, by adopting and using these standards, you can reduce the amount of spam mail that you personally receive and also contribute to reducing the amount of spam mail in general faced by all of us. In other words, it's good for all of us.

In short, if your business depends on email you owe it to yourself to investigate these methods and make an informed choice about whether to implement them or not. Personally, I can't see any reason not to embrace them all, since it's important to me to do everything I can to ensure that email I send is actually received.

So, the links below will take you to various resources regarding the different methods. I'll provide just the briefest overview of them since there's no point in remaking the wheel.

SPF (Sender Policy Framework) utilizes a small text entry in your domain's Zone file to identify servers which are permitted to send email on behalf of your domain. It's important to note that your server doesn't have to use SPF records for filtering incoming mail for you to implement your own SPF record for your domain. Receiving servers that do utilize SPF to screen incoming mail will compare mail claiming to come from your domain against the list of permitted senders. (Adopted by many large email providers, such as Gmail and AOL)


SIDF (Sender ID Framework) is very much the same as the SPF record and is promoted by Microsoft. The link will take you to a MS page where you can create an SPF record and where you can also submit your domain to be added to the SIDF cache. This is a very useful process if you tend to email a lot of Microsoft addresses (hotmail, live)


AOL Postmaster Tools - AOL has adopted SPF and provides resources here for webmasters and postmasters to register their servers, create feedback loops and request whitelist status. This is very useful if you send a lot of email to AOL addresses.


DomainKeys Is distinctly different from SPF/SID methods because it doesn't use domain names as the method of authentication. Instead, DomainKeys uses a signature which is attached to outgoing email. Receiving servers that used DomainKeys can then compares that signature against the public key held on the server of the actual domain. DomainKeys was originally developed by Yahoo, but has been adopted by Gmail and is also now widely supported on many web hosting servers.


There are other resources, but these seem the most valuable to me. Of course there will be new developments and there will be critics. But from my perspective, it's up to us as website owners and managers to stay on top of these new methods and to implement them when we can.

To my knowledge, there are no major ISPs or email providers that are REQUIRING email authentication from incoming mail, yet!

However, many (AOL, Gmail, Hotmail and others) have indicated that is exactly where they're headed.

A final tip: Because Gmail uses both SPF and DomainKeys I like to use it for testing my configuration when setting up email authentication. Send an email to a Gmail address and then view the headers - you'll get a very useful description of Gmail's analysis of the message's authenticity. This is also useful for seeing how Gmail is handling mail from non-authenticated sources.

Anyway, I hope this is helpful to some people.
__________________
Jade Burnside, Ahead of the Web
What good is your web site if no one can find it?
SEO & Optimized Web Site Design
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Webmaster Resources Discussion Forum

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
How Do I Determine a Domain's Value? beakerbum Domains Buy/Sell 5 01-15-2009 11:49 AM
Reputation Management Advice Rebecca Kelley Search Engine Optimization Forum 21 05-23-2007 12:18 PM
Get Involved with the New WPW Reputation System Clicken WebProWorld: Guidelines/Announcements/Suggestions 0 05-18-2007 12:25 PM
Domain's Ranking on Alexa craven Domain Discussion Forum 2 05-19-2004 03:20 PM


All times are GMT -4. The time now is 06:08 PM.



Search Engine Optimization by vBSEO 3.3.0