Roger Howorth headshot

SPF strengthens anti-spam defences

Used in tandem with filtering, the Sender Policy Framework protocol could slash corporate spam

Written by Roger Howorth

I had a watershed moment last week – I received spam that contained only a single PDF file. I have never had this stuff before, but I have a feeling more is on the way.

Fortunately, the developers of the spam filter I use – the Anti Spam SMTP Proxy (ASSP) – appear to be on the case and eager to help solve the problem. The trouble is, solving this one issue will only create new problems.

For example, when a greylisting feature was added to ASSP about 18 months ago, it proved effective, cutting my personal spam from about 85 percent to about 60 percent. But greylisting has become such a common feature in most spam filters that some spammers have already updated their software to deal with it.

In short, the more popular an anti-spam solution becomes, the more likely it is that spammers will try to defeat it.

The interesting thing about the Sender Policy Framework (SPF – the protocol used to eliminate email forgeries) is that this “less is more” rule doesn’t hold true. The only thing spammers can do to bypass SPF filtering is to register more legitimate domains from which to send their mail. People could then block those domains, either by manual methods or, more likely, by having their spam filter automatically update itself from a spam blacklist.

This would mean the newly registered domains would only be effective until they were spotted and added to the blacklists, something that would probably take less than a few hours. Registering domains wouldn’t be popular with spammers because they cost money and are traceable.

Some argue there is no point using technologies such as SPF if there are too few email service providers signed up to it. While this is partly true, there are already some notable exceptions, including AOL and Google’s Gmail. And while spam filters probably can’t use an SPF “fail” result to positively identify spam, they can use an SPF “pass” result as an indicator that the mail is not spam.

Previously, SPF has also been criticised for not handling mail-forwarding very well. Messages that were forwarded from domains using SPF to mail servers also using SPF would be rejected. However, the complementary Sender Rewriting Scheme (SRS) deals with this problem.

Admittedly, implementing SPF and SRS is a little more complicated than installing a basic spam filter. A company would need to update its DNS servers with appropriate records, for example. But this is not too onerous, and most organisations would probably agree it is a price worth paying to reduce the volume of spam in their users’ mailboxes.

Tags:

reader comments

related articles

Spam to hijack video messaging

Unwanted email levels set to fall but techniques will become more sophisticated 18 Jul 2007

 

Innovators offer hope of curing spam

Strato and Tumbleweed’s clever solutions may stop systems from drowning in image-based junk email 13 Apr 2007

Trend Micro steps up messaging security

Updates InterScan and ScanMail product ranges 01 Mar 2007

NEC blocks spam over telephony

NEC will unveil its VoIP Seal tool at 3GSM next month 29 Jan 2007

Spammers becoming more business savvy

Cyber-crooks capatilising on news in a more commercial way 30 Jan 2008

Picasa and Flash become latest spam tools

Image site helps spammers elude filters 05 Sep 2008

Nokia updates messaging and maps on Ovi

New services and features unveiled in Barcelona 02 Dec 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation