Automatic authentication of email servers and personal computers independent of the active participation of server administrators or personal computer users

Michael G. Kaplan · 2011

Universal email authentication is impossible with existing authentication schemes, namely DomainKeys Identified Mail (DKIM) and Sender Policy Framework (SPF), primarily because at a minimum this would require the ongoing participation of every domain administrator in the world. Consequently a vast quantity of current email is unauthenticated, thus empowering spammers. This paper describes two unique methods employing digital signatures to automatically authenticate every computer involved in sending an email. The first method will authenticate the mail transfer agent (MTA) used to forward an email, while the second method will authenticate the personal computer that originated the email. Universal authentication occurring redundantly at both the MTA and the personal computer is achievable because these two methods do not require the participation of email users or administrations.

Read the paper · More papers on PaperTik