Amir Herzberg
Title: DNS-based Email Sender Authentication Mechanisms: a Critical
Review
Abstract
We describe and compare three predominant email sender
authentication mechanisms based on DNS: SPF, DKIM and Sender-ID
Framework (SIDF). These mechanisms are designed mainly to assist in
filtering of undesirable email messages, in particular spam and
phishing emails.We clarify the limitations of these mechanisms,
identify risks, and make recommendations. In particular, we discuss
potential abuse of these mechanisms to facilitate DNS poisoning, and
suggest countermeasures.
--
Amir Herzberg
Associate Professor, Dept. of Computer Science
Bar Ilan University
http://AmirHerzberg.com
_______________________________________________
Asrg mailing list
Asrg at irtf.org
http://www.irtf.org/mailman/listinfo/asrg