Sunday, 23 August 2026
Nigeria Communications Week
E-Business

Banks, Internet Firms Fight Spam

Comms Week6 Feb 20120 Comments
Kindly share this post

Some of the world's biggest Internet companies and financial services firms have developed a new approach to fighting e-mail spam that they hope will reduce online scams. Facebook, Google and…

Some of the world's biggest Internet companies and financial services firms have developed a new approach to fighting e-mail spam that they hope will reduce online scams.
Facebook, Google and Microsoft have joined with financial firms Bank of America, Fidelity Investments and eBay's PayPal to create a set of industry standards for preventing criminals from sending out spam e-mails that appear to come from corporate e-mail addresses.
Fraudsters often pose as banks and other trusted firms in attempts to persuade e-mail recipients to provide payment card numbers, bank account information and other personal data, or click on links that infect computers with malicious software.
The new approach calls for e-mail providers and businesses to attack spammers by coordinating on a massive scale the use of two existing technologies for e-mail authentication known by the acronyms SPF and DKIM, which have yet to be widely adopted.
PayPal is one company that currently uses Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) technology standards to fight e-mail spoofing, but only through partnerships with Yahoo and Google, said Brett McDowell, a security manager at PayPal who serves as chairman of the group that developed the new standard.
The group goes by the name DMARC.org, which stands for Domain-based Message Authentication, Reporting and Conformance.
If Yahoo or Google get an e-mail claiming to come from PayPal that is not properly authenticated with SPF or DKIM, the e-mail is not delivered, he said. But if fraudsters send spoofed PayPal e-mail to other e-mail providers, it might get through.
"What we need is an Internet standard that allows this level of protection to work at scale – without any discussion, without any partner agreements, that is what DMARC does, McDowell said.
Other companies involved in the group include American Greetings, LinkedIn and Yahoo, as well as privately held Agari, Cloudmark, eCert, Return Path and the Trusted Domain Project.
Michael Versace, IDC security analyst, said the approach recommended by the group appeared to be effective and inexpensive to implement.
Yet he said the industry should keep developing new technologies to fight spammers because he expects cyber criminals will eventually figure out how to circumvent the DMARC protections.

C
Published by

Comms Week

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in E-Business