Home  › Email › Email Marketing

SPF: It’s Not Just a Good Idea

  |  August 2, 2004   |  Comments

Microsoft will soon check for SPF records on inbound e-mail. What does that mean for e-mail marketers?

Last week, Microsoft announced it will check for SPF records in all email coming into its Hotmail service, beginning October 1, 2004.

That’s all well and good, you may say, but what’s "SPF"?

Sender Policy Framework is one of several email authentication schemes that have been vying for attention and adoption during the past few months. Others include Yahoo’s Domain Keys and ePrivacy Group’s Trusted Email Open Standard (TEOS).

According to the SPF Web site, SPF:

Fights email address forgery and makes it easier to identify spams, worms, and viruses. Domain owners identify sending mail servers in DNS. SMTP receivers verify the envelope sender address against this information, and can distinguish legitimate mail from spam before any message data is transmitted.

What does this mean? On the most basic level, SPF allows mail server administrators to assert "the mail server at this IP address sends email from x.com, y.com, and z.com." Thus, when an email arrives at the border of the receiving system, that system looks up, via DNS, to see whether an SPF record is associated with that IP address.

As the SPF site explains it:

SPF makes it easy for a domain, whether it’s an ISP, a business, a school or a vanity domain, to say, "I only send mail from these machines. If any other machine claims that I’m sending mail from there, they’re lying...."

And that’s it! SPF aims to prevent spammers from ruining other people’s reputations. If they want to send spam, they should at least do it under their own name.

SPF isn’t a great way to identify and stop spam in and of itself. But it is a fabulous way to authenticate the identity of email senders.

Authentication is important because it helps prevent transmission of email containing forged sender information, as with phishing and, indeed, most spam. Phishing is the act of sending email with an intentionally forged sender address, usually a well-known company. The phisher tries to get the target to follow a link and reveal sensitive information, such as a password or credit card information.

Microsoft’s announcement means that beginning in October, the company will check inbound email’s source IP address for an SPF record. In other words, Microsoft will check whether the person responsible for that outbound mail server has published an SFP record. E-mail that passes the SPF test will be passed through for delivery. E-mail that doesn’t pass this simple test must go through additional hoops before it can be delivered to the inbox.

Bottom line: If you haven’t already done so, publish an SPF record. It’s fairly easy. The good folks at SPF even offer a setup wizard. Give it a whirl!

Join us for Search Engine Strategies 2004 in San Jose, CA, August 2-5.

Vote for your favorite product or campaign from July 20 through close of business August 2.

ClickZ Live San Francisco This Year's Premier Digital Marketing Event is #CZLSF
ClickZ Live San Francisco (Aug 11-14) brings together the industry's leading practitioners and marketing strategists to deliver 4 days of educational sessions and training workshops. From Data-Driven Marketing to Social, Mobile, Display, Search and Email, this year's comprehensive agenda will help you maximize your marketing efforts and ROI. Register today!

ABOUT THE AUTHOR

Anne Mitchell

Anne P. Mitchell is a professor of law at Lincoln Law School of San Jose, and president and CEO of the Institute for Spam and Internet Public Policy. In addition to her duties at the Institute, and teaching" Spam and the Law" at Lincoln, Anne is a driving force behind such cross-industry e-mail deliverability initiatives as the Email Deliverability Summits, the Email Processing Industry Alliance, and the ISIPP Sender Accreditation Database. Prior to running the Institute, she was an original founder of Habeas, Inc., and before that, the director of legal and public affairs for Mail Abuse Prevention System (MAPS), creator of the RBL(Realtime Blackhole List).

COMMENTSCommenting policy

comments powered by Disqus

Get ClickZ Email newsletters delivered right to your inbox. Subscribe today!

COMMENTS

UPCOMING EVENTS

Featured White Papers

BigDoor: The Marketers Guide to Customer Loyalty

The Marketer's Guide to Customer Loyalty
Customer loyalty is imperative to success, but fostering and maintaining loyalty takes a lot of work. This guide is here to help marketers build, execute, and maintain a successful loyalty initiative.

Marin Software: The Multiplier Effect of Integrating Search & Social Advertising

The Multiplier Effect of Integrating Search & Social Advertising
Latest research reveals 68% higher revenue per conversion for marketers who integrate their search & social advertising. In addition to the research results, this whitepaper also outlines 5 strategies and 15 tactics you can use to better integrate your search and social campaigns.

WEBINARS

    Information currently unavailable

Jobs

    • Interactive Product Manager
      Interactive Product Manager (Western Governors University) - Salt Lake CityWestern Governors University, one of the 20 largest universities...
    • SEO Senior Analyst
      SEO Senior Analyst (University of Phoenix (Apollo Education Group)) - San FranciscoSEO Senior Analyst   Position Summary...
    • SEM & Biddable Media Manager
      SEM & Biddable Media Manager (Kepler Group LLC) - New YorkAs an Optimization & Innovation Manager at Kepler Group, you will be on the bleeding...