Home / Blogs

Searching for Truth in DKIM: Part 3 of 5

J.D. Falk

Last year, MAAWG published a white paper titled Trust in Email Begins with Authentication [PDF], which explains that authentication (DKIM) is "[a] safe means of identifying a participant-such as an author or an operator of an email service" while reputation is a "means of assessing their trustworthiness."

Reputation systems based on IP addresses, including Return Path's Sender Score, are used by many ISPs and anti-spam vendors to determine which mail to accept, which to reject, and which to subject to additional filtering before making a delivery decision. There, the identifier is the IP address.

The reason this sort of reputation works for delivery decisions is that it's an attempt to predict whether the sender of a message can be trusted to send mail that the recipients want — or, more accurately, whether the IP address of a message can be trusted to send mail that the recipients won't complain about. We also mix in the concept of safety, largely in the form of how likely it is that the IP address is sending phishing scams or similar bad stuff.

In part 1 of this series, we described how the DKIM "d=" identifier brings us closer to knowing who sent a message, because it can be tied to the company or person who registered that domain name.

Reputation or certification based on the DKIM d= identifier will have the same goal — and will be more effective, because it will be tied to the signing entity rather than a single IP address. When ADSP is applied, that signing entity could be the author domain (see part 2). If not, it's still a useful method for determining whether to trust the message. Any d= domain who regularly signs trusted messages becomes trustworthy, and vice versa.

Plus, d= reputation is portable — the owner of the d= domain can use that same identifier on multiple IP addresses, even bringing it to a different ESP (as we described in part 2), without having to start over from scratch or to "warm up" IPs.

While not absolutely perfect, reputation and certification based on d= will be far more accurate, effective, and convenient than when it's based solely on the IP address. But, does a trustworthy d= domain indicate a truthful message? Stay tuned for part 4.

(This article was originally published by Return Path)

By J.D. Falk, Internet Standards and Governance. Visit the blog maintained by J.D. Falk here.

Related topics: Domain Names, Email, Security, Spam

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

.IN.NET - New Internet Address for India, Launching June 17th

Radix Registry Passes 4 New gTLD Initial Evaluations

DomainsBot to Help Professionals Find .PRO Internet Addresses More Easily

INTA 2013: Gearing Up for Dallas

Hope is Not a Strategy: Neustar Releases 2012 Annual DDoS Attack and Impact Survey

.PW Crosses 50,000 Domain Registrations in 3 Weeks

The Ratings Are In: Measuring .ORG's Trust and Success in Numbers

How Neustar Technology Can Help Mitigate DDoS Attacks

dot Brand or dot What? Consumers Unaware of New TLDs, Including .Google, .Microsoft and .Nike

Zodiac Prepares for Chinese New gTLDs, Announces "Chinese Advisory Services" for New gTLD Applicants

.PW General Availability Opens With More Than 4000 Orders in 30 Minutes

CentralNic Powers First New Top-Level Domains Announced by ICANN

Invitation to a Seminar on "A New Beginning - Domain Name Market in China"

LogicBoxes Announces Vertical Integration Solutions for New gTLDs

.PW Registry Extends Landrush Till March 22, 2013

DCA Registry Services Participates in ICANN Africa Strategy Meeting, Addis Ababa

Network Solutions & Register.com, Web.com, become 100th and 101st Accredited Registrars for .PW

gTLD Update: No TLDH or Client Strings Affected

Public Interest Registry Releases Report Revealing Continued Growth of the .ORG Domain

Dyn to Host Email Analytics Webinar With Ongage

Sponsored Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
dotMobi

Mobile

Sponsored by
dotMobi
Neustar

DNS

Sponsored by
Neustar
Afilias

DNS Security

Sponsored by
Afilias