New Audit and Registry Service to Combat Phishing and Spoofing of Email

Phishing messages continue to be highly effective trickery. One technology that fights phishing is DomainKeys Identified Mail (DKIM), which allows an organization to sign an email so that the message recipient can validate the sender. The DKIM protocol, however, has not been quite as widely adopted as some hoped. Nor have other available email authentication technologies.

Return Path, a provider of email deliverability and reputation management services, announced this week the launch of its Domain Assurance, an audit and registry service aimed at battling phishing and spoofing by enabling the widespread use of email authentication protocols. According to Return Path, the service leverages its relationships with the top global ISPs and its reach with 2,500 brand-name clients.

In his blog, Matt Blumberg, CEO and chairman of Return Path notes that companies have struggled to implement authentication protocols. “Because of inconsistent adoption, ISPs and other mailbox providers have been unable to unilaterally block unauthenticated email for fear that consumers would not receive wanted email,” he says. “Domain Assurance solves both of these problems by first auditing a company’s email streams to be sure authentication has been properly implemented. Then, the company’s domains are added to a registry. Participating ISPs can check the registry and block any unauthenticated emails coming from the domains found there. Return Path provides on-going checks for authentication accuracy and alerts participating companies any time their brand is phished or spoofed.”

The service, which is currently in beta with a commercial launch planned for Q3 2010, sounds like it will get off to a decent start. Return Path has extended its current relationships with Yahoo!, Comcast and Tucows to include the use of Domain Assurance, bringing the product’s coverage at launch to almost 400 million mailboxes worldwide. In addition, Cloudmark, which provides carrier-grade messaging infrastructure and security solutions, will make the service available to its customers who service over 1 billion users worldwide. This is in addition to Return Path’s current partnerships with more than 130 ISPs and mailbox providers covering more than 1.8 billion inboxes around the world through its Certification service.

“We are huge proponents of DKIM and its application as an extra security barrier to protect our nearly 300 million Yahoo! Mail users worldwide,” says Mark Risher, head of product management and Spam Czar for Yahoo! Mail. “We look forward to working with companies like Return Path to further help spread the adoption of domain keys technology across the industry and further reduce the number of spammers and phishing threats.”