Google & Yahoo tighten the noose on spam emails – The two giant companies use the DMARC system to block spoofed emails
The two giant companies, Google and Yahoo, are expanding the use of successful system for detecting spam emails.
The move is part of a long-standing effort by the two companies to implement a series of checks designed to determine whether an email has actually been sent from the domain it appears to be from. Email spoofing has always been a problem, as it is easy to forge the “from” address, tricking the recipient into believing that the message is from a legitimate source.
Starting November 2, Yahoo plans to use DMARC (Domain-based Message Authentication, Reporting & Conformance) for its services . Next year, Google also plans to move Gmail to a strict DMARC policy, according to an announcement from the company itself.
DMARC allows email senders to opt in to its services if they use other technologies (such as those listed below) to eliminate spam emails.
Many email senders use DKIM, or DomainKeys Identified Mail, which essentially 'wraps' an encrypted signature around an email and verifies the domain name from which the message was sent. The second technology, SPF, or Sender Policy Framework, allows email senders to indicate which hosts are authorized to send their email.
DMARC allows email senders some flexibility, letting them choose what action they want to take with messages that are not authenticated. Recipients can also let senders know what they have done with messages that fail verification.
The aim is to dramatically reduce phishing emails, which seek to trick users into clicking on malicious links or revealing personal information.
DMARC has broad support across the security industry and is also used by Facebook and Microsoft.

