The DMARC system is used to block spoofed emails Credit: Thinkstock Google and Yahoo are expanding their use of a successful system for identifying spam.The move is part of years-long effort to implement a series of checks designed to figure out if an email really has been sent by the domain it purports to come from.Email spoofing has long been a problem since its easy to forge the “from” address, making it more likely the receiver will believe it came from a legitimate source.By Nov. 2, Yahoo plans to being using DMARC (Domain-based Message Authentication, Reporting & Conformance) for its ymail.com and rocketmail.com services. Next year, Google also plans to move Gmail to a strict DMARC policy, according to a news release. DMARC allows email senders to tell receiving services if they are using two other technologies to weed out spam.Many email senders use DKIM, or DomainKeys Identified Mail, which wraps a cryptographic signature around an email that verifies the domain name through which the message was sent. The second technology, SPF, or Sender Policy Framework, allows email senders to indicate which hosts are authorized to send their email, allowing receiving organizations to discard messages coming from spoofed “from” addresses.DMARC also allows for some flexibility for email senders, letting them to tell the recipient what to do if some messages aren’t authenticated. Recipients can also tell senders what they’ve done with the messages that didn’t pass muster.The idea is to dramatically cut down on phishing emails, which seek to get people to click on malicious links or reveal personal information.DMARC has wide industry support and is also used by Facebook and Microsoft. Related content news UK Cyber Security Council CEO reflects on a year of progress Professor Simon Hepburn sits down with broadcaster ITN to discuss Council’s work around cybersecurity professional standards, careers and learning, and outreach and diversity. By Michael Hill Sep 27, 2023 3 mins Government Government Government news FIDO Alliance certifies security of edge nodes, IoT devices Certification demonstrates that products are at low risk of cyberthreats and will interoperate securely. By Michael Hill Sep 27, 2023 3 mins Certifications Internet Security Security Hardware news analysis Web app, API attacks surge as cybercriminals target financial services The financial services sector has also experienced an increase in Layer 3 and Layer 4 DDoS attacks. By Michael Hill Sep 27, 2023 6 mins Financial Services Industry Cyberattacks Application Security news Immersive Labs adds custom 'workforce exercising' for each organizational role With the new workforce exercising capability, CISOs will be able to see each role’s cybersecurity readiness, risk areas, and exercise progress. By Shweta Sharma Sep 27, 2023 3 mins Security Software Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe