Authenticating the World’s Email
Ed Amoroso summarizes a recent technical conversation with the principals of ValiMail about advanced email authentication solutions.

Authenticating the World’s Email

Readers of this column have come to recognize my incessant on-and-on about the need for improvements in global email security infrastructure. I’ve argued repeatedly that the full adoption of DMARC, in particular, would represent a major advance in this regard. I was therefore pleased to see the US Federal Government finally mandate DMARC (and HTTPS) for civilian agencies in 2018, following the UK’s similar directive in 2016. Good job, Feds.

Now, for your little test: I want you to take a moment and be honest: Do you really understand what DMARC is all about? Would you be able to get up to a white board and explain the security standard and its implications for your colleagues? My suspicion is that most of you probably could not. In fact, I’ll bet that more than half the people reading this article would not be able to expand the acronym. (Go ahead and jump over to Wikipedia to look it up. I’ll wait.)

And so, I had the great pleasure to spend some quality time this past month on two separate occasions digging into the fine technical work being done at ValiMail. Founded in 2015, the company is focused on not just the modest (ahem) goal of automating DMARC deployment and monitoring for email security, but also eventually targeting the more awesome task of authenticating the world’s communications. But first things first . . .

I asked company founder and CEO Alex García-Tobar to share his strategy for driving his DMARC-based solutions for business customers, and he was enthusiastic in his response. “First, we believe the timing is finally right,” he explained. “It took a long time for the standard to take-off, but now that the United States Government has mandated this security approach for agencies, there is no question in our minds that businesses will decide to follow.”

The ValiMail team spent time re-introducing me with the technical details of DMARC and its underlying SPF and DKIM components. They recounted for me the benefits of how email recipients can use the standard to determine whether an inbound message aligns with specific information about the actual sender. This is how, for example, a recipient can determine if that email from backstreets.com really came from the Boss’s official email provider.

I asked Dylan Tweney, who heads up Communications, how they intended to support customers. “Since roughly 70% of all current DMARC deployments have not been fully realized,” he said, “we believe the market is now ready for email authentication as a service.” He went on to explain how such an end-to-end managed DMARC solution addresses the more frustrating and confusing aspects of dealing with SFP lookup limits, rotating DKIM keys, and so on.

We spent some time discussing the threats addressed by email authentication, and the list was impressive. “Fraudulent use of email, including phishing attacks, is really the most intense exploit addressed in our solution,” García-Tobar explained. “The ValiMail solution literally shuts down phishing attacks using spoofed domains as a means for targeting an enterprise or government organization.”

The value proposition emphasized by the ValiMail team with respect to email authentication is automation. The team provided great evidence that without full automation of DMARC, SPF, and DKIM, the ability to move customers to full enforcement – with the requisite quarantine or rejection of suspect email – is severely limited. This theme certainly met with my own experience of trying to push the DMARC standard across different industry sectors.

As you might guess, the ValiMail was pleased with the Department of Homeland Security’s recent directive that all government agencies implement DMARC in early 2018, with the goal of enforcing policy by early 2019. To support this mandate, the company is now offering ValiGov, which fully automates the required activities for federal agencies, which will increase the chances that all requirements will be met by the target dates.

Now, everyone knows that determined fraudsters can certainly still navigate around email authentication by using cousin domains and similar exploits – so DMARC is far from a perfect control. But every security expert agrees that email authentication is a great step forward, one that should be mandated not only for government, but for all businesses of every size in every sector.

Give the ValiMail team a call to learn more about their fine solution offering. And as usual, please let me know what you learned. 

Genevieve Nicholas

Owner/Facilitator - Saddle Up Life Skills (Life Skills Development)

6 年

Edward, I’d love to write about this. If I do, could I reference your work?

Dylan Tweney

I help companies, execs, and founders communicate better.

6 年

Thanks for the kind writeup, Ed! ValiMail is here on LinkedIn, if anyone wants more info. ValiMail

Buddy Youngblood

Vice President & Executive Director AT&T Govt Solutions (Retired) Military Veteran

6 年

check out SPARKPOST .... good article on WHAT IS DMARK

要查看或添加评论,请登录

Edward Amoroso的更多文章

  • Why TAG is Now Rating Cybersecurity Vendors

    Why TAG is Now Rating Cybersecurity Vendors

    by Edward Amoroso The first time I ever paid attention to an analyst quadrant – fully two decades ago, I found myself…

    8 条评论
  • Predicting the Impact of Trump’s Election on Cyber

    Predicting the Impact of Trump’s Election on Cyber

    Below are seven predictions from our team at TAG for how the recent Trump election of 2024 will impact U.S.

    78 条评论
  • Five Tips for Working CISOs

    Five Tips for Working CISOs

    Our team at TAG has been coaching CISOs for years – and this includes private discussions just about every day of every…

    12 条评论
  • The SEC is Weakening the Cybersecurity Posture of the United States. Here is Why.

    The SEC is Weakening the Cybersecurity Posture of the United States. Here is Why.

    Preface During May and June of 2024, draft versions of this article were shared with Chief Information Security…

    123 条评论
  • Sad Loss Today

    Sad Loss Today

    Several years ago, before the Pandemic, I received a friendly call from a law firm I’d done some business with – and…

    9 条评论
  • Remembering Steve Katz

    Remembering Steve Katz

    Back in the mid-1990’s, Frank Ianna, then President of AT&T, called me into his office to ask whether it would be…

    39 条评论
  • Here is the Letter the SEC Should Send to Investors on Cyber

    Here is the Letter the SEC Should Send to Investors on Cyber

    Below is a draft letter that I believe the Securities and Exchange Commission (SEC) should send to investors: The…

    57 条评论
  • Telling Your Startup Story: From Napkin to PowerPoint

    Telling Your Startup Story: From Napkin to PowerPoint

    Motivation. In our research and advisory work at TAG, we regularly witness startup founders telling their story in a…

    5 条评论
  • The Death of Cybersecurity Questionnaires in Three Acts

    The Death of Cybersecurity Questionnaires in Three Acts

    Below, we offer a little cybersecurity fable that starts in Act 1 with the use of an evil human-to-human questionnaire…

    15 条评论
  • Three Briefing Tips for Small Startups

    Three Briefing Tips for Small Startups

    Occasionally, in our day-to-day research and advisory work at TAG, we see business mistakes being made by smaller…

    18 条评论

社区洞察

其他会员也浏览了