Tuesday, 12 September 2006

Domain Assurance Council

The Domain Assurance Council (or DAC) is a new trade body representing organizations that certify or accreditate email sending organizations and customers of those organizations. (Examples of such organizations include Habeas and Goodmail; their customers are typically ISPs and spam control technology vendors.)

With sender "authentication" (authorization) standards such as SPF and DKIM becoming more popular, there's a need for a standard way for a trusted authority to vouch for a domain name. DAC plans to help the industry create a standard way for organizations to "vouch" for a sending domain. They will do that by publishing reputation or accreditation data about a domain name in a standard form. The standard will be known as Vouch By Reference (VBR).

For example, a receiving mail system may be able to use SPF or DKIM to verify that an incoming message was sent by example.com, but it currently has no standard way of deciding if it wants to receive email from that company. Using VBR, a receiving system would be able to look up the domain and decide if it wishes to receive the message.

VBR could also allow smaller, more specialist organizations to vouch for organizations in their own vertical industry or niche (e.g. the pharmacalogical industry). The theory is that specialist authorities will know their industry better; if a sender goes bad, a specialist authority might discover this more quickly than a generalist.

VBR means that there should be no need for proprietary methods, such as Goodmail's. VBR will create a market for organization who vouch for domains; allowing its members to compete with minimum "friction." VBR should also allow customers to switch providers -- i.e. there will be no lock-in to a proprietary provider such as Goodmail.

Current members of DAC are Goodmail, Habeas, Return Path, Trend Micro, and IronPort. DAC is run by John Levine and Paul Hoffman. Paul has plenty of experience running this sort of group, having previously run the Internet Mail Consortium amongst others.

Friday, 1 September 2006

New Spammer Tactic: Blipverts

For a while now, stock kiting spammers have been encoding their spam in images and trying new ways to make each image slightly different. That makes it harder for hash-based content filters to spot the images.

Here's an interesting new twist. An animated GIF that flashes subliminal images. Presumably each of these is slightly different from message-to-message. On the right, you can see one of these "blipverts" separated out from the GIF (and resized).

(With apologies to Max Headroom)

Friday, 25 August 2006

New Unsubscribe Button in Windows Live (née Hotmail)

ClickZ' Rebecca Lieb reports on the Windows Live Unsubscribe button:

Ironic as it may sound, commercial e-mailers are jubilant about a new feature Microsoft's rolling out: an "unsubscribe" button.

The button is part of Windows Live, the beta service that will replace Hotmail in a few months. If it's as successful as many anticipate, expect similar changes at the other major ISPs.

Here's how it works: Windows Live account holders have begun to see the "unsubscribe" button replace the dreaded "report spam" button on messages that contain a valid unsubscribe link. When a person clicks the "unsubscribe" button, Microsoft forwards the request to the sender.
Not sure what I think about this. Microsoft claims to be protecting against listwashing, as only "legitimate" senders get the unsubscribe button. Then again, do we trust Microsoft's view of who's legitimate?

Note that if MS thinks the sender is legit., you don't get to see a Report Spam button.

Monday, 21 August 2006

Email Cryptography Helps Avoid Bad Debts

If a credit card company were to send statements by email, it might be able to identify which of its customers are getting into financial difficulties. That's the interesting claim made by email encryption company Identum.

The argument goes like this: when card issuers send paper statements to people, they're usually opened quickly. However, when people are getting into financial trouble, they often go into denial. This causes them to ignore card statements, putting them in a pile somewhere, unopened.

What if the card issuer had some way of knowing that statements were going unread? That would be an early warning that there's a problem. This of course relies on card issuers having two important capabilities:

  • A secure way of emailing sending statements to customers
  • A reliable way of getting read receipts back
But what about online banking? Wouldn't people prefer to just read their statements online? Some would, but others seem to prefer to have statements "pushed" to them in email.

Thursday, 10 August 2006

Ziff Davis are SPAMMERS

I've had enough. I'm outing Ziff Davis as a spamhaus.

The company sends me several unwanted messages per week. I have diligently unsubscribed several times. It also appears to repurpose lists to an alarming degree.

Its ISPs also appear to ignore abuse complaints.

I'm mad as hell and I'm not holding my tongue any more.