Antispam proposals advance

Filed under
Security

The Internet Engineering Steering Group (IESG), a division of the Internet Engineering Task Force (IETF), said it would publish two competing and overlapping sets of documents that define ways of confirming that e-mail senders are who they say they are.

The experimental Requests for Comment (RFCs)--Sender Policy Framework (SPF) for Authorizing Use of Domains in E-Mail and Sender ID: Authenticating E-Mail--have been the subject of intense jockeying by Microsoft, America Online and others.

Critics have accused Microsoft of trying to strong-arm the industry into accepting Sender ID. Concerns over Microsoft's Sender ID-related patents have alarmed some involved in setting standards, and last year the IETF let a Sender ID working group expire.

"While many proposals for domain-based authorization have been under consideration, no consensus has yet been reached concerning a single technical approach," the IESG said in a statement. "The IESG does not endorse either of the two mechanisms documented in the experimental RFCs--their publication is intended to encourage further discussion and experimentation in order to gain experience that can be used to write future standards in this space."

Microsoft said that despite the expiration of the Sender ID working group in September, the approval of the experimental RFCs showed that its technology is alive and well in the standards-setting process.

"We think this is great," said Samantha McManus, business strategy manager for Microsoft's technology care and safety group. "We're glad to see Sender ID's experimental status, and we think e-mail authentication is very important for addressing spam and phishing. That said, we definitely have more to do."

Full Story.