AOL To ESPs: Comply with SPF, Or Else

  |  June 9, 2004   |  Comments

America Online plans to have SPF e-mail authentication in place by the end of summer and bulk mailers not in compliance will lose their whitelisting status.

America Online plans to have SPF email authentication in place by the end of summer and email service providers (ESPs) not in compliance will lose their whitelisting status.

SPF, or Sender Policy Framework, authenticates the identity of the sender of an email. Since most spam has faked addresses, SPF could be a powerful weapon in fighting spam, spoofing [define] and phishing [define].

ESPs are scrambling to comply with the AOL edict.

"Many ESPs have already complied," said Dave Lewis, co-chair of the E-Mail Service Provider Coalition (ESPC) vendor relations committee and VP of deliverability management for Digital Impact. Lewis said his firm is in the process of complying, as is another major ESP, Bigfoot Interactive, a spokesman confirmed. Other firms, such as EmailLabs and Socketware, are already in compliance.

Compliance is not a demanding process. The entity in question need only publish information such as its IP address or addresses in a specified format within the Domain Name System (DNS). [define]

"If individual companies, corporations, organizations and so forth want to remain on AOL's whitelist they will want to establish an SPF record for their domain since AOL will soon begin to query IP addresses that are on our whitelist from a domain SPF record," said Nicholas Graham, AOL spokesman.

Graham said the giant ISP will begin using SPF to maintain its whitelist in the short-term future, with August being within a potential timeframe. Carl Hutzler, director of anti-spam operations for AOL mail operations, put it more simply: "End of summer if I can get developers to do their magic."

SPF works by comparing the identifying information of an incoming email with the information on file with the DNS to see if they match. This authenticates the identity of the sender by checking information in the email "envelope."

However, because SPF doesn't authenticate any of the headers actually seen by the end user -- the "from" address, for example -- some are pushing for other protocols. Microsoft, for example, is in the process of integrating SPF with its own Caller ID for E-Mail authentication protocol to enable checking of the fields seen by the end user. Meanwhile, Yahoo has its own authentication proposal, DomainKeys, which uses encryption of digital signatures.

While SPF will not eliminate spam, it "will make a big difference in a positive way," according to John Mathew, VP of operations for Bigfoot Interactive.

Or, as Digital Impact's Lewis put it, "We're not able to score the touchdown on the first play. But these two forms of authentication [SPF and DomainKeys] will get us a goodly way up the field."

ClickZ Live New York What's New for 2015?
You spoke, we listened! ClickZ Live New York (Mar 30-Apr 1) is back with a brand new streamlined agenda. Don't miss the latest digital marketing tips, tricks and tools that will make you re-think your strategy and revolutionize your marketing campaigns. Super Saver Rates are available now. Register today!


Janis Mara

COMMENTSCommenting policy

comments powered by Disqus

ClickZ Today is our #1 newsletter.
Get a daily dose of digital marketing.




Featured White Papers

Google My Business Listings Demystified

Google My Business Listings Demystified
To help brands control how they appear online, Google has developed a new offering: Google My Business Locations. This whitepaper helps marketers understand how to use this powerful new tool.

5 Ways to Personalize Beyond the Subject Line

5 Ways to Personalize Beyond the Subject Line
82 percent of shoppers say they would buy more items from a brand if the emails they sent were more personalized. This white paper offer five tactics that will personalize your email beyond the subject line and drive real business growth.


    Information currently unavailable


    • Lead Generation Specialist
      Lead Generation Specialist (The Oxford Club) - BaltimoreThe Oxford Club is seeking a talented writer/marketer to join our growing email lead-generation...
    • Health Marketing Editor
      Health Marketing Editor (Agora Inc.) - BaltimoreCome flex your intellectual muscle as part of Agora, Inc’s ( legal team...
    • Technical Business Analyst
      Technical Business Analyst (OmniVista Health) - BaltimoreOmniVista Health is looking to add a Technical Business Analyst to our expanding team...