Google, Microsoft And Others Announce Anti-Phishing Initiative

Google, Facebook, Microsoft, PayPal and 11 other companies have announced a proposed standard for email sending and receiving in an attempt to stamp out phishing.

DMARC, or Domain-based Message Authentication, Reporting and Conformance, is a system that will aid communication between companies and consumers by creating a standardised way of authenticating emails.

Fighting the phishers

The other companies working in the DMARC group are AOL, Yahoo, Bank of America, Fidelity, LinkedIn, American Greetings and email security providers Agari, Cloudmark, eCert, ReturnPath and Trusted Domain Project.

The group came together roughly 18 months ago and last November it emerged that Google, Yahoo, AOL, Microsoft and Agari were authenticating for Facebook, YouSendIt and other e-commerce organisations and social networks. Today’s move sees DMARC expand its list of participants in the hope that the system will be more widely recognised.

Backed by the Online Trust Alliance (OTA), BITS, and the Messaging Anti-Abuse Working Group (MAAWG), the eventual goal of the DMARC collaborators is to “develop an operational specification to be introduced to the IETF (Internet Engineering Task Force) for standardisation” and eventually become an official internet standard.

“One of the worst experiences for a user is being phished,” said Adam Dawes, DMARC representative and Google product manager, told Wired. “The best way to protect them is to make sure the email never reaches the spam folder at all.”

The DMARC system ensures that email senders are protected by SPF (Sender Policy Framework) and/or DKIM (DomainKeys Indentified Mail) and receivers are informed and advised should messages fail to meet the authentication methods.

Phishing persists as a major problem, with data from the OTA suggesting that hundreds of thousands of accounts are hijacked daily. The hope is that as more companies adopt DMARC’s standard, the scamming practice will be rendered useless.

Jiten Karia

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago