Sign In
Terry Zink's Cyber Security Blog
Discussing Internet security in (mostly) plain English
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Common Tasks
Blog Home
Email Blog Author
About
OK
RSS for comments
RSS for posts
Atom
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
Authentication
Backscatter
Botnets
Economics
Education
Entertainment
Facebook
Foreign language
Hacking
Legal
Malware
Miscellaneous
Net Neutrality
Outbound
Pages
Privacy
Reputation
Security
Social Networking
Spam
Stories
Monthly Archives
Archives
February 2012
(7)
January 2012
(21)
December 2011
(6)
November 2011
(12)
October 2011
(13)
September 2011
(12)
August 2011
(15)
July 2011
(14)
June 2011
(11)
May 2011
(11)
April 2011
(11)
March 2011
(11)
February 2011
(9)
January 2011
(1)
December 2010
(19)
November 2010
(16)
October 2010
(18)
September 2010
(16)
August 2010
(16)
July 2010
(16)
June 2010
(16)
May 2010
(16)
April 2010
(21)
March 2010
(25)
February 2010
(17)
January 2010
(13)
December 2009
(13)
November 2009
(17)
October 2009
(18)
September 2009
(13)
August 2009
(12)
July 2009
(15)
June 2009
(12)
May 2009
(13)
April 2009
(10)
March 2009
(9)
February 2009
(9)
January 2009
(16)
December 2008
(15)
November 2008
(16)
October 2008
(13)
September 2008
(19)
August 2008
(16)
July 2008
(16)
June 2008
(15)
May 2008
(14)
April 2008
(15)
March 2008
(17)
February 2008
(15)
January 2008
(14)
December 2007
(16)
November 2007
(12)
October 2007
(16)
September 2007
(16)
August 2007
(8)
July 2007
(15)
June 2007
(16)
May 2007
(15)
April 2007
(11)
March 2007
(10)
February 2007
(9)
January 2007
(20)
December 2006
(14)
November 2006
(8)
October 2006
(14)
September 2006
(13)
August 2006
(22)
July 2006
(12)
July, 2007
MSDN Blogs
>
Terry Zink's Cyber Security Blog
>
July, 2007
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Terry Zink's Cyber Security Blog
Sender authentication part 18: More hazards
Posted
over 5 years ago
by
tzink
5
Comments
The other hazard I'd like to look at with regards to SPF and SenderID is the issue of newsletters, or more specifically, bulk emailers. Bulk emailers have a long and checkered history of using questionable email practises. They put in lots of advertising...
Terry Zink's Cyber Security Blog
Sender authentication part 17: Hazards of SenderID and SPF
Posted
over 5 years ago
by
tzink
3
Comments
Both SenderID and SPF have their critics. I'd like to touch on two potential problems with them: the first is the issue of email forwarding. There's no official standard on how email is to be forwarded (in terms of rewriting the headers). Suppose that...
Terry Zink's Cyber Security Blog
Sender authentication part 16: SenderID vs SPF
Posted
over 5 years ago
by
tzink
1
Comments
SPF and SenderID are similar to each other in the way they act, but the differences between them are in what they are designed to target (at least how I see it). Both OpenSPF and Wikipedia say that SenderID and SPF are designed to address different problems...
Terry Zink's Cyber Security Blog
Some notes on PDF spam
Posted
over 5 years ago
by
tzink
2
Comments
I started tracking some statistics on pdf spam this weekend. The following numbers will seem a little inflated (since spam performance metrics always appears better on weekends) but they are still interesting. Of all the messages with PDF attachments...
Terry Zink's Cyber Security Blog
Sender authentication part 15: How SenderID interprets SPF records
Posted
over 5 years ago
by
tzink
2
Comments
In my last post, we were introduced to the new SPF record syntax that is specifically designed for SenderID. The question now is how does SenderID treat SPF records that were originally designed to be used with SPF? SenderID allows the spam filter to...
Terry Zink's Cyber Security Blog
Sender authentication part 14: Introduction to SenderID
Posted
over 5 years ago
by
tzink
2
Comments
Now that we've moved our way through the workings of SPF, let's take a look at Microsoft's own branded technology, SenderID (I don't mean that Microsoft invented it since it derives from an earlier standard, only that Microsoft advocates the use of it...
Terry Zink's Cyber Security Blog
July 12 - My third year anniversary!
Posted
over 5 years ago
by
tzink
9
Comments
Today is a special day at Microsoft, it is the three-year anniversary of the day I joined Frontbridge (now Microsoft Exchange Hosted Services) as a spam analyst. Ah, what a memorable three years it has been. On our first day on the job, me and three...
Terry Zink's Cyber Security Blog
Sender authentication part 13: Some SPF odds and ends
Posted
over 5 years ago
by
tzink
0
Comments
Let’s tie up a couple of loose ends (but by no means all the loose ends) when it comes to SPF. I would like to interpret the below SPF record: v=spf1 a/24 mx/24 ptr ?all Now that we are experts in SPF syntax, reading this is a snap. The version of SPF...
Terry Zink's Cyber Security Blog
Sender authentication part 12: Some examples of SPF
Posted
over 5 years ago
by
tzink
5
Comments
Now that we've plowed our way through SPF, including the syntax (I can't believe I took the time to do it, but if I ever go into a university and have to teach it I guess I should know it), let's take a look at some real life examples of domains that...
Terry Zink's Cyber Security Blog
Sender authentication part 11: More on SPF Syntax (Continued)
Posted
over 5 years ago
by
tzink
1
Comments
The mx mechanism mx mx/<prefix-length> mx:<domain> mx:<domain>/<prefix-length> All the A records for all the MX records for domain are tested in order of MX priority. If the client IP is found among them, this mechanism matches...
Terry Zink's Cyber Security Blog
Sender authentication part 10: More on SPF Syntax
Posted
over 5 years ago
by
tzink
3
Comments
Moving onwards to mechanisms, let's take a look at them in a bit more detail. Again, this information comes straight from the OpenSPF page, with extra commentary by me. The all mechanism all This mechanism always matches. It usually goes at the end of...
Terry Zink's Cyber Security Blog
Sender authentication part 9: SPF Syntax
Posted
over 5 years ago
by
tzink
2
Comments
This is essentially going to be a summary of the information that appears on the OpenSPF documentation web page. Really, what else can I say that isn't said there? But, if you're like me and rarely bother clicking on links inside of blog posts and would...
Terry Zink's Cyber Security Blog
Sender authentication part 8: Best-Guess SPF
Posted
over 5 years ago
by
tzink
5
Comments
I've had a document sitting on my shelf (ie, the window-sill 10 feet away from my desk) for about 6 months now just waiting to be read. It's entitled Sender Repuration in a Large Webmail Service. It's by Bradley Taylor, at Google, and is available to...
Terry Zink's Cyber Security Blog
Spamhaus spam
Posted
over 5 years ago
by
tzink
2
Comments
This morning I had the distinct "pleasure" of getting spam in my inbox that was pumping the services of Spamhaus. Here's an excerpt: WORKING TO PROTECT INTERNET NETWORKS WORLDWIDE Spamhaus tracks the Internet's Spammers, Spam Gangs and Spam...
Terry Zink's Cyber Security Blog
More on spam levels
Posted
over 5 years ago
by
tzink
1
Comments
I continue my brief hiatus from sender authentication to comment on the amount of spam we're seeing. We continue to see high levels of spam not seen on our networks in previous times. They haven't really dropped off at all since they started hitting...
Page 1 of 1 (15 items)