Domain message authentication reporting is used by a mail server to verify a received email is authorised to be sent from the domain and IP. It consists of sender policy framework (spf) and domain keys identified mail (skim) records. When a mail is received, the sender domain and ip is checked against the record and if not matched will be reported to the user. This could be used to detect phishing mail. This requires user to actively maintain the spf and dkim record for it to works. Also IP can be impersonated and so passing the check does not guarantee the mail is legitimate.
No comments:
Post a Comment