SlideShare une entreprise Scribd logo
1  sur  34
Connect the world’s professionals
to make them more productive
and successful
Our mission
277MMembers
The World Wide Web
6
The World Wide Web
is not the only service on the
Internet
What about SMTP?
SMTP:
Simple Mail Transfer Protocol
SMTP metrics and challenges:
3.3+ Billion Mailboxes in the world
247+ Billion emails per day
70%+ is SPAM
91% of targeted attacks involve spear-phishing emails.
http://www.email-marketing-reports.com/metrics/email-statistics.htm
http://www.email-marketing-reports.com/iland/2009/08/8-email-statistics-to-use-at-parties.html
http://www.zdnet.com/worldwide-spam-rate-falls-2-5-percent-but-new-tactics-emerge-7000025517/
Trend Micro Report: “Spear-Phishing Email: Most Favored APT Attack Bait”, 2012
Why SMTP over IPv6 now?
No Rush!
Not hard to get one IPv4 for a mail server
Email servers need to have IPv4 to send
emails between each others
If SPAM is not handled people mailbox will
be unusable
No Rush!
Not hard to get one IPv4 for a mail server
Email servers need to have IPv4 to send
emails between each others
Not hard to get one IPv4 for a mail server
Email servers need to have IPv4 to send
emails between each others
If SPAM is not handled people mailbox will
be unusable
Mandate requirements
before anything goes
If you start to send email over IPv6 and the emails are not delivered
then the problem is on the sending side
If you start to receive emails over IPv6 and the emails are not delivered
then the problem is on the receiving side
VS
Receive over IPv6 before
others send so you can set
the rules!
Fight SPAM with low cost
solution:
DNSBL
DNS based Blacklist
DNSBL
DNS based Blacklist
IP: spamhaus, spamcop, sorbs…
Blocks about 66% of spam at connection time
Domain: spamhaus, surbl, uribl…
Used mainly for links in emails, but should not be
http://www.dnsbl.com/2007/03/how-well-do-various-blacklists-work.html
RBLDNSD
Support IPv6 at /64 since
June 2013
http://www.corpit.ru/pipermail/rbldnsd/2013q2/001169.html
Fewer domains than IPv6
/64 networks
Domain allocation is more
granular and portable than
IP space allocation
/64 block likely to do
collateral damage
IP reputation
Domain reputation
http://googleonlinesecurity.blogspot.com/2013/12/internet-wide-efforts-to-fight-email.html
Google:
8.6% of non-spam emails do not use SPF or DKIM
http://googleonlinesecurity.blogspot.com/2013/12/internet-wide-efforts-to-fight-email.html
Google:
91.4% of legit emails use SPF or DKIM
SPF: Is this IP allowed to
send email for this domain?
DKIM: Is this email linked to
this domain?
What if we could mandate
SPF or DKIM over IPv6?
Additional guidelines for IPv6
The sending IP must have a PTR record (i.e., a reverse DNS of the
sending IP) and it should match the IP obtained via the forward DNS
resolution of the hostname specified in the PTR record. Otherwise, mail
will be marked as spam or possibly rejected.
The sending domain should pass either SPF check or DKIM check.
Otherwise, mail might be marked as spam.
https://support.google.com/mail/answer/81126
Google bulk sender
guidelines
What if we could mandate
SPF or DKIM over IPv6?
Can we get IPv6 emails to
fallback to IPv4 instead of
marking them as SPAM by
default?
Can we get IPv6 emails to
fallback to IPv4 instead of
marking them as SPAM by
default?
Can we get IPv6 emails to
fallback to IPv4?
RFC5321: pick MX in order of preference
RFC6724: Pick AAAA before A
Problems:
- Cannot see the A on a dual stack host
- Complains if host is IPv6 only
- IPv6 and IPv4 are different stacks, which one is really better for me?
Need better guidance…
First: host selection
SMTP target host selection in Mixed IPv4/IPv6 environments
http://datatracker.ietf.org/doc/draft-martin-smtp-target-host-selection-ipv4-IPv6/
Second: Fallback
- Does not necessarily mark the email as spam
- Does not deliver it in the junk folder by default
If SPF or DKIM pass, then we have a domain. We don’t need
to base our decisions on the IP address.
If SPF and DKIM do not pass, then we go back to the usual
IPv4 based blocking or reputation measures.
Why Fallback?
A DMARC policy allows a sender to indicate that their
emails are protected by SPF and/or DKIM, and tells a
receiver what to do if neither of those authentication
methods passes - such as junk or reject the message.
DMARC removes guesswork from the receiver's handling of
these failed messages, limiting or eliminating the user's
exposure to potentially fraudulent & harmful messages.
DMARC also provides a way for the email receiver to report
back to the sender about messages that pass and/or fail
DMARC evaluation.
Get Feedback with DMARC!
SMTP target host selection in Mixed IPv4/IPv6 environments
http://datatracker.ietf.org/doc/draft-martin-smtp-target-host-selection-ipv4-
IPv6/
SMTP IPv6 to IPv4 Fallback: An Applicability Statement
http://datatracker.ietf.org/doc/draft-martin-smtp-ipv6-to-ipv4-fallback/
Domain-based Message Authentication, Reporting and
Conformance (DMARC)
https://datatracker.ietf.org/doc/draft-kucherawy-dmarc-base/
References:

Contenu connexe

Tendances

EmailCoE_10715_DesignSystem
EmailCoE_10715_DesignSystemEmailCoE_10715_DesignSystem
EmailCoE_10715_DesignSystem
Eric Appelbaum
 

Tendances (20)

E-mail Metrics That Matter by Joe Scharf [Metrics Marketing Bootcamp]
E-mail Metrics That Matter by Joe Scharf [Metrics Marketing Bootcamp]E-mail Metrics That Matter by Joe Scharf [Metrics Marketing Bootcamp]
E-mail Metrics That Matter by Joe Scharf [Metrics Marketing Bootcamp]
 
20 rules for successful cold emailing
20 rules for successful cold emailing20 rules for successful cold emailing
20 rules for successful cold emailing
 
Email Validation for Improved Deliverability and Marketing Results
Email Validation for Improved Deliverability and Marketing ResultsEmail Validation for Improved Deliverability and Marketing Results
Email Validation for Improved Deliverability and Marketing Results
 
How to Manage Your Email Reputation - Rob Van Slyke 4-2010
How to Manage Your Email Reputation - Rob Van Slyke 4-2010How to Manage Your Email Reputation - Rob Van Slyke 4-2010
How to Manage Your Email Reputation - Rob Van Slyke 4-2010
 
Stay Out of Spam Folder
Stay Out of Spam FolderStay Out of Spam Folder
Stay Out of Spam Folder
 
The 4 dos and 8 donts of getting your emails delivered
The 4 dos and 8 donts of getting your emails deliveredThe 4 dos and 8 donts of getting your emails delivered
The 4 dos and 8 donts of getting your emails delivered
 
The deliverability top 5
 The deliverability top 5 The deliverability top 5
The deliverability top 5
 
The Agoge Sequence - Sam Nelson
The Agoge Sequence - Sam NelsonThe Agoge Sequence - Sam Nelson
The Agoge Sequence - Sam Nelson
 
NewZapp-Factsheet-NewZapp-vs-MailChimp
NewZapp-Factsheet-NewZapp-vs-MailChimpNewZapp-Factsheet-NewZapp-vs-MailChimp
NewZapp-Factsheet-NewZapp-vs-MailChimp
 
Evaluate your content and messaging
Evaluate your content and messagingEvaluate your content and messaging
Evaluate your content and messaging
 
NewZapp-Factsheet-What-is-NewZapp
NewZapp-Factsheet-What-is-NewZappNewZapp-Factsheet-What-is-NewZapp
NewZapp-Factsheet-What-is-NewZapp
 
Email marketing for your business.
Email marketing for your business.Email marketing for your business.
Email marketing for your business.
 
Transactional Email Best Practices
Transactional Email Best PracticesTransactional Email Best Practices
Transactional Email Best Practices
 
Best Practices in Email Deliverability
Best Practices in Email DeliverabilityBest Practices in Email Deliverability
Best Practices in Email Deliverability
 
Using Return Path Data to Protect Your Brand: Security Breakout Session - LA
Using Return Path Data to Protect Your Brand: Security Breakout Session - LAUsing Return Path Data to Protect Your Brand: Security Breakout Session - LA
Using Return Path Data to Protect Your Brand: Security Breakout Session - LA
 
Email Optimization Suite Product Overview
Email Optimization Suite Product OverviewEmail Optimization Suite Product Overview
Email Optimization Suite Product Overview
 
Email Continuity
Email ContinuityEmail Continuity
Email Continuity
 
Email Marketing with Blackbaud NetCommunity- Boot Camp Series
Email Marketing with Blackbaud NetCommunity-  Boot Camp SeriesEmail Marketing with Blackbaud NetCommunity-  Boot Camp Series
Email Marketing with Blackbaud NetCommunity- Boot Camp Series
 
EmailCoE_10715_DesignSystem
EmailCoE_10715_DesignSystemEmailCoE_10715_DesignSystem
EmailCoE_10715_DesignSystem
 
Email Marketing
Email MarketingEmail Marketing
Email Marketing
 

Similaire à SMTP over IPv6 at LinkedIn

B2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the InboxB2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the Inbox
B2BCamp
 
Modern Anti-Spam: Rejection - No Sorting
Modern Anti-Spam: Rejection - No SortingModern Anti-Spam: Rejection - No Sorting
Modern Anti-Spam: Rejection - No Sorting
Thomas Stensitzki
 
Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)
webhostingguy
 
Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)
webhostingguy
 
Protecting E-mail From SPAM and Malware
Protecting E-mail From SPAM and MalwareProtecting E-mail From SPAM and Malware
Protecting E-mail From SPAM and Malware
Scott McDermott
 
Spam and Anti-spam - Sudipta Bhattacharya
Spam and Anti-spam - Sudipta BhattacharyaSpam and Anti-spam - Sudipta Bhattacharya
Spam and Anti-spam - Sudipta Bhattacharya
sankhadeep
 

Similaire à SMTP over IPv6 at LinkedIn (20)

B2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the InboxB2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the Inbox
 
Modern Anti-Spam - Rejection, No Sorting (Version 2014)
Modern Anti-Spam - Rejection, No Sorting (Version 2014)Modern Anti-Spam - Rejection, No Sorting (Version 2014)
Modern Anti-Spam - Rejection, No Sorting (Version 2014)
 
Modern Anti-Spam Protection - Rejection, no sorting
Modern Anti-Spam Protection - Rejection, no sortingModern Anti-Spam Protection - Rejection, no sorting
Modern Anti-Spam Protection - Rejection, no sorting
 
Protect your domain with DMARC
Protect your domain with DMARCProtect your domain with DMARC
Protect your domain with DMARC
 
A plan for email over IPv6
A plan for email over IPv6A plan for email over IPv6
A plan for email over IPv6
 
Modern Anti-Spam: Rejection - No Sorting
Modern Anti-Spam: Rejection - No SortingModern Anti-Spam: Rejection - No Sorting
Modern Anti-Spam: Rejection - No Sorting
 
Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)
 
Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)
 
Tips to prevent your email ip being blacklisted
Tips to prevent your email ip being blacklistedTips to prevent your email ip being blacklisted
Tips to prevent your email ip being blacklisted
 
E mail image spam filtering techniques
E mail image spam filtering techniquesE mail image spam filtering techniques
E mail image spam filtering techniques
 
Commtouch outbound-anti spam-webinar-201312-final
Commtouch outbound-anti spam-webinar-201312-finalCommtouch outbound-anti spam-webinar-201312-final
Commtouch outbound-anti spam-webinar-201312-final
 
Protecting E-mail From SPAM and Malware
Protecting E-mail From SPAM and MalwareProtecting E-mail From SPAM and Malware
Protecting E-mail From SPAM and Malware
 
What You Need to Know About Email Authentication
What You Need to Know About Email AuthenticationWhat You Need to Know About Email Authentication
What You Need to Know About Email Authentication
 
Fighting XMPP abuse and spam with ejabberd - ejabberd Workshop #1
Fighting XMPP abuse and spam with ejabberd - ejabberd Workshop #1Fighting XMPP abuse and spam with ejabberd - ejabberd Workshop #1
Fighting XMPP abuse and spam with ejabberd - ejabberd Workshop #1
 
Massive emailing with Linux, Postfix and Ruby on Rails
Massive emailing with Linux, Postfix and Ruby on RailsMassive emailing with Linux, Postfix and Ruby on Rails
Massive emailing with Linux, Postfix and Ruby on Rails
 
UserGate Mail Server
UserGate Mail ServerUserGate Mail Server
UserGate Mail Server
 
Email management
Email managementEmail management
Email management
 
A multi layer architecture for spam-detection system
A multi layer architecture for spam-detection systemA multi layer architecture for spam-detection system
A multi layer architecture for spam-detection system
 
A multi layer architecture for spam-detection system
A multi layer architecture for spam-detection systemA multi layer architecture for spam-detection system
A multi layer architecture for spam-detection system
 
Spam and Anti-spam - Sudipta Bhattacharya
Spam and Anti-spam - Sudipta BhattacharyaSpam and Anti-spam - Sudipta Bhattacharya
Spam and Anti-spam - Sudipta Bhattacharya
 

Dernier

Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
soniya singh
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
sexy call girls service in goa
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
@Chandigarh #call #Girls 9053900678 @Call #Girls in @Punjab 9053900678
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
ellan12
 

Dernier (20)

VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls Dubai
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
 
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
 

SMTP over IPv6 at LinkedIn

  • 1.
  • 2. Connect the world’s professionals to make them more productive and successful Our mission
  • 4.
  • 6.
  • 7. 6
  • 8. The World Wide Web is not the only service on the Internet
  • 11. SMTP metrics and challenges: 3.3+ Billion Mailboxes in the world 247+ Billion emails per day 70%+ is SPAM 91% of targeted attacks involve spear-phishing emails. http://www.email-marketing-reports.com/metrics/email-statistics.htm http://www.email-marketing-reports.com/iland/2009/08/8-email-statistics-to-use-at-parties.html http://www.zdnet.com/worldwide-spam-rate-falls-2-5-percent-but-new-tactics-emerge-7000025517/ Trend Micro Report: “Spear-Phishing Email: Most Favored APT Attack Bait”, 2012
  • 12. Why SMTP over IPv6 now?
  • 13. No Rush! Not hard to get one IPv4 for a mail server Email servers need to have IPv4 to send emails between each others If SPAM is not handled people mailbox will be unusable
  • 14. No Rush! Not hard to get one IPv4 for a mail server Email servers need to have IPv4 to send emails between each others Not hard to get one IPv4 for a mail server Email servers need to have IPv4 to send emails between each others If SPAM is not handled people mailbox will be unusable
  • 15. Mandate requirements before anything goes If you start to send email over IPv6 and the emails are not delivered then the problem is on the sending side If you start to receive emails over IPv6 and the emails are not delivered then the problem is on the receiving side VS
  • 16. Receive over IPv6 before others send so you can set the rules!
  • 17. Fight SPAM with low cost solution: DNSBL DNS based Blacklist
  • 18. DNSBL DNS based Blacklist IP: spamhaus, spamcop, sorbs… Blocks about 66% of spam at connection time Domain: spamhaus, surbl, uribl… Used mainly for links in emails, but should not be http://www.dnsbl.com/2007/03/how-well-do-various-blacklists-work.html
  • 19. RBLDNSD Support IPv6 at /64 since June 2013 http://www.corpit.ru/pipermail/rbldnsd/2013q2/001169.html
  • 20. Fewer domains than IPv6 /64 networks Domain allocation is more granular and portable than IP space allocation /64 block likely to do collateral damage
  • 24. SPF: Is this IP allowed to send email for this domain? DKIM: Is this email linked to this domain?
  • 25. What if we could mandate SPF or DKIM over IPv6?
  • 26. Additional guidelines for IPv6 The sending IP must have a PTR record (i.e., a reverse DNS of the sending IP) and it should match the IP obtained via the forward DNS resolution of the hostname specified in the PTR record. Otherwise, mail will be marked as spam or possibly rejected. The sending domain should pass either SPF check or DKIM check. Otherwise, mail might be marked as spam. https://support.google.com/mail/answer/81126 Google bulk sender guidelines
  • 27. What if we could mandate SPF or DKIM over IPv6?
  • 28. Can we get IPv6 emails to fallback to IPv4 instead of marking them as SPAM by default?
  • 29. Can we get IPv6 emails to fallback to IPv4 instead of marking them as SPAM by default? Can we get IPv6 emails to fallback to IPv4?
  • 30. RFC5321: pick MX in order of preference RFC6724: Pick AAAA before A Problems: - Cannot see the A on a dual stack host - Complains if host is IPv6 only - IPv6 and IPv4 are different stacks, which one is really better for me? Need better guidance… First: host selection SMTP target host selection in Mixed IPv4/IPv6 environments http://datatracker.ietf.org/doc/draft-martin-smtp-target-host-selection-ipv4-IPv6/
  • 32. - Does not necessarily mark the email as spam - Does not deliver it in the junk folder by default If SPF or DKIM pass, then we have a domain. We don’t need to base our decisions on the IP address. If SPF and DKIM do not pass, then we go back to the usual IPv4 based blocking or reputation measures. Why Fallback?
  • 33. A DMARC policy allows a sender to indicate that their emails are protected by SPF and/or DKIM, and tells a receiver what to do if neither of those authentication methods passes - such as junk or reject the message. DMARC removes guesswork from the receiver's handling of these failed messages, limiting or eliminating the user's exposure to potentially fraudulent & harmful messages. DMARC also provides a way for the email receiver to report back to the sender about messages that pass and/or fail DMARC evaluation. Get Feedback with DMARC!
  • 34. SMTP target host selection in Mixed IPv4/IPv6 environments http://datatracker.ietf.org/doc/draft-martin-smtp-target-host-selection-ipv4- IPv6/ SMTP IPv6 to IPv4 Fallback: An Applicability Statement http://datatracker.ietf.org/doc/draft-martin-smtp-ipv6-to-ipv4-fallback/ Domain-based Message Authentication, Reporting and Conformance (DMARC) https://datatracker.ietf.org/doc/draft-kucherawy-dmarc-base/ References: