Google, Microsoft and others putting kibosh on phishing emails

A year after Google, Microsoft and other email heavyweights launched the DMARC program to filter out spoofed email that attackers use for phishing, they say an estimated 60% of the world's email boxes are now safe.

"This empowers mailbox providers to take definitive actions on fraudulent mail," says Trent Adams, senior adviser of ecosystem security at PayPal information risk management, part of DMARC supporter eBay. "This has shut down entire avenues that lead to widespread email fraud. It's a lot like an inoculation."

[ BACKGROUND: Google, Microsoft, Facebook, Bank of America team to wipe out phishing ]

Of the 325 million spoofed messages blocked during the last two months of 2012 via the DMARC process, 49 million were targeted for "highly phished domains, like PayPal and Facebook," Adams says. Blocking those phishing messages before they hit email recipients "from a PayPal perspective, that protection is golden," he says.

DMARC stands for "Domain-based Message Authentication, Reporting and Conformance," and basically it's a filtering process based on policies in which email managers implement the DMARC.org specification to check that email originated from where it was supposed to. DMARC supports standards that include Sender Policy Framework and DomainKeys Identified Mail, two basic approaches for authenticating mail.

The spoofed mail caught through DMARC can be blocked, quarantined and deleted. According to DMARC.org, the top 10 email senders which today publish a DMARC record to support this anti-spoofing process, are:

  • facebookmail.com
  • google.com
  • amazon.com
  • livingsocial.com
  • taggedmail.com
  • zyngamail.com
  • youtube.com
  • facebookappmail.com
  • new.itunes.com
  • ebay.com

Support for DMARC has been growing, with Mail.ru, the largest mailbox provider in Russia, for example, getting on board with it, points out Krish Vitaldevara, DMARC.org chair and Microsoft principal group program manager.

He says the experience with DMARC technology has been positive enough that Microsoft is thinking about implementing this functionality in some products, such as Exchange.

Although an estimated 60% of email boxes today may be supported by DMARC, that leaves plenty that aren't. (DRMARC.org points out that as of last April, the Radicati Group estimated there are 3.3 billion email accounts, expected to rise to over 4.3 billion by the end of 2016.)

Mike Adkins, messaging engineer at Facebook, says the DMARC.org group is hoping to win support for the technology from large telecom providers and ISPs. Comcast just indicated it would come on board, he says.

Have the bad guys started catching on to DMARC, though?

"We know that fraudsters are looking at DMARC," says Adams, adding there have been some variations in attack patterns indicating they're trying to get around it. But have they broken it? So far, it doesn't appear so.

Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security. Twitter: @MessmerE. Email: emessmer@nww.com.

Read more about wide area network in Network World's Wide Area Network section.

Tags: DMARC, Google, Bank of America, security, Microsoft, ebay, paypal, phishing, Facebook

BlackBerry Hints at Complete End Point Security

READ THIS ARTICLE
DO NOT SHOW THIS BOX AGAIN [ x ]
Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Email Security and Data Protection

Encrypt your sensitive email

Latest Jobs
Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.