Tag: ietf

  • New email header attempts to prevent damage of reissued email addresses

    Transactional emails not delivered if the account’s owner has changed in the meantime. When in June, Yahoo announced it would free up inactive user IDs, it received fierce criticism from the security community. The concern was that many of these user IDs are tied to email addresses that, though dormant, may still be registered as…

  • IETF discusses deprecation of IPv6 fragmentation

    Little-used feature could have unintended security consequences. As the Internet is (very) slowly migrating towards IPv6, researchers are reconsidering a little-used feature that allows for IPv6 packets to be fragmented by the sender and reassembled by the recipient. Last year, we published an article on the security implications of the transition from IPv4 to IPv6.…

  • IETF expedites publication of RFC describing feedback loop recommendations

    Document fast-tracked to be published shortly before the sad passing of its author J.D. Falk. The Internet Engineering Task Force (IETF) has published an RFC detailing current practices of running email feedback loops. Feedback loops are essential for entities that send emails, such as ISPs and ESPs. Not only do they help them to detect…

  • New RFC grants DKIM improved status

    Email signing method now ‘Draft Standard’. The Internet Engineering Task Force (IETF) has published a new RFC describing the DKIM protocol which sees its status advance from ‘Proposed Standard’ to ‘Draft Standard’. DKIM (‘DomainKeys Identified Email’) allows mail transfer agents (MTAs) to sign email messages that pass through them and also to verify a signature…

  • ARF published as IETF standard

    Abuse report format helps auto-handling of email complaints ARF (Abuse Reporting Format) has been approved by the IETF as an Internet standard. ARF is a format used to send complaints about email – for instance the report generated when a user clicks a ‘this is spam’ button in their email agent. A draft version of…

  • IETF accepts DKIM specification as proposed standard

    Email authentication system moves to approval stage. The Internet Engineering Task Force (IETF), the body overseeing the technical running of the Internet, has accepted a new system for identifying and validating legitimate email into the final stages of approval as an Internet RFC standards document. DomainKeys Identified Mail (DKIM) is a proposed system to apply…