AOL testing new anti-spam technology
By
Paul Roberts
,
IDG News Service
, 01/22/2004
- Share/Email
- Tweet This
- Print
Deluged by unsolicited commercial, or spam, e-mail messages, ISP AOL is trying a new technology for cracking down on one common
spammer tool: forged sender addresses, which spammers and virus writers use to bypass blacklists and trick unsuspecting recipients.
AOL is conducting a trial of a new e-mail protocol called Sender Permitted From, or SPF, across its entire user base of 33
million subscribers. The company hopes that SPF will eliminate e-mail forgeries by enabling organizations to specify which
servers are allowed to send mail on behalf of their Internet domain, according to AOL spokesman Nicholas Graham.
SPF stops e-mail address spoofing by modifying the Domain Name System (DNS) to declare which servers can send mail from a
particular Internet domain. AOL is using SPF to publish the IP addresses of the servers it uses to send outgoing e-mail. DNS
is the system that translates numeric IP addresses into readable Internet domain names.
Once widely deployed, SPF records can be referenced by Mail Transfer Agents (MTA) stationed throughout the Internet when routing
e-mail messages from a particular domain to determine whether an e-mail message's source is legitimate or "spoofed," according
to Graham.
AOL briefly tested the protocol two weeks ago, before shutting it off to make technical changes based on feedback from other
ISPs, according to Graham, who declined to describe the changes.
The program is still experimental and for the time being AOL will not use SPF to filter mail from other Internet domains,
Graham said. "(SPF) is just getting off the ground. AOL is interested in putting the proposal out there and getting feedback
from stakeholders," he said. Those stakeholders include other major ISPs such as Microsoft's MSN, Yahoo and Earthlink, as
well as other major domain owners processing bulk e-mail, Graham said.
The trial is a major test of SPF, which is one of a number of new technologies designed to thwart spammers, according to John
Levine, co-chairman of the Anti-Spam Research Group.
SPF patches a hole in Simple Mail Transfer Protocol, which is currently used to route e-mail messages from one e-mail inbox
to another. Developed in the early 1980s, SMTP was designed to provide a reliable and efficient way to relay messages between
host systems using different computer hardware and operating systems.
In recent years, spammers and viruses such as Sobig-F and the recent Beagle/Bagel worm have exploited SMTP's flexibility,
easily transposing the actual source of messages with legitimate e-mail addresses from lists that are traded online or harvested
from infected computers' hard drives.
The long-term benefit of SPF is that, when the technology is widely deployed, e-mail providers will be able to associate reputations
with Internet domains rather than with IP addresses, which are harder to track, according to Eric Raymond, president of the
Open Source Initiative, who gave a presentation on SPF during January's Spam Conference 2004 at the Massachusetts Institute
of Technology in Cambridge.
The IDG News Service is a Network World affiliate.
Partner Content
Simplify Your Branch Infrastructure
Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.
Download the Free Info Kit
Next-Gen Load Balancing
Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.
Download the Free Guide
Accelerate Your Web Apps by up to 5x
Free Guide: "The Secret to Getting Maximum Speed from your Web Applications."' Learn how you can deliver Web apps up to 5x faster.
Download the Free Guide
Comment