EP3764623A1

Centralized validation of email senders via ehlo name and ip address targeting

Abstract

A DNS server receives from a receiving email system, a DNS query for an email domain stored at the DNS server, the DNS query including identifying information of a sender of an email. The DNS server extracts the identifying information of the email sender from the DNS query and identifies one of a plurality of delivering organizations from the information. The DNS server determines whether the identified delivering organization is authorized to deliver email on behalf of the email domain. In response to determining that the identified delivering organization is authorized to deliver email on behalf of the email domain, the DNS server generates a target validation record based on the identity of the authorized delivering organization and the email domain, the target validation record including one or more rules indicating to the receiving email system whether the delivering organization is an au-thorized sender of email for the email domain.

EP3764623A1, drawing sheet 1
Sheet 1 of 5

Term

9.3 yearsto projected expiry

Projected expiry 29 January 2036, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 6 independent, 9 dependent

  1. 1
    A non-transitory computer readable storage medium configured to store instructions, the instructions when executed by a processor cause the processor to:generate an email domain validation record to include in a Domain Name System (DNS) record of an email domain, the email domain validation record to be parsed by a receiving email system when receiving an email from the target domain, and indicating to the receiving email system whether the sender of an email is an authorized sender for the email domain, the generation of the email domain validation record including instructions that when executed by the processor cause the processor to: generate the email domain validation record to include a target domain, the target domain being a domain distinct from the email domain, causing the receiving email system, when parsing the email domain validation record, to submit a second request for a validation record to the target domain;and generate the email domain validation record to include one or more macro statements specifying identifying information, the macro statements causing the receiving email system, when parsing the email domain validation record, to include identifying information of the sender of the email in the second request;and publish the created email domain validation record as a DNS record of the email domain.
  2. 4
    The computer readable storage medium of any one of claims 1 to 3, wherein the processor is a first processor, and the instructions when executed by a second processor cause the second processor to:receive, at a Domain Name System (DNS) server, from the receiving email system, a DNS query for an email domain stored at the DNS server, the DNS query including the identifying information of the sender of the email, and the email identified as being from the email domain, wherein the target domain comprises the DNS server;extract the identifying information of the email sender from the DNS query for identification of one of a plurality of delivering organizations;determine whether the identified delivering organization is authorized to deliver email on behalf of the email domain;generate, in response to determining that the identified delivering organization is authorized to deliver email on behalf of the email domain, a target validation record based on the identity of the authorized delivering organization and the email domain, the target validation record including one or more rules indicating to the receiving email system that the delivering organization is an authorized sender of email for the email domain;and transmit the target validation record to the receiving email system in response to the DNS query.
  3. 5
    A computer-implemented process, comprising:generating an email domain validation record to include in a Domain Name System (DNS) record of an email domain, the email domain validation record to be parsed by a receiving email system when receiving an email from the target domain, and indicating to the receiving email system whether the sender of an email is an authorized sender for the email domain, the creation of the email domain validation record comprising: generating the email domain validation record to include a target domain, the target domain being a domain distinct from the email domain, causing the receiving email system, when parsing the email domain validation record, to submit a second request for a validation record to the target domain;and generating the email domain validation record to include one or more macro statements specifying identifying information, the macro statements causing the receiving email system, when parsing the email domain validation record, to include identifying information of the sender of the email in the second request;and publishing the created email domain validation record as a DNS record of the email domain.
  4. 8
    The process of any one of claims 5 to 7, further comprising:receiving, at a Domain Name System (DNS) server, from the receiving email system, a DNS query for an email domain stored at the DNS server, the DNS query including the identifying information of the sender of the email, and the email identified as being from the email domain, wherein the target domain comprises the DNS server;extracting the identifying information of the email sender from the DNS query for identification of one of a plurality of delivering organizations;determining whether the identified delivering organization is authorized to deliver email on behalf of the email domain;generating, in response to determining that the identified delivering organization is authorized to deliver email on behalf of the email domain, a target validation record based on the identity of the authorized delivering organization and the email domain, the target validation record including one or more rules indicating to the receiving email system that the delivering organization is an authorized sender of email for the email domain;and transmitting the target validation record to the receiving email system in response to the DNS query.
  5. 9
    A computing device, comprising:a processor;a non-transitory computer readable storage medium, configured to store instructions, that when executed by the processor, cause the processor to: generate an email domain validation record to include in a Domain Name System (DNS) record of an email domain, the email domain validation record to be queried by a receiving email system when receiving an email from the email domain, and indicating to the receiving email system whether the sender of an email is an authorized sender for the email domain, the generation of the email domain validation record including instructions that when executed by the processor further cause the processor to: generate the email domain validation record to include a target domain, the target domain being a domain distinct from the email domain, causing the receiving email system, when querying the email domain validation record, to submit a second request for a validation record to the target domain;and generate the email domain validation record to include one or more macro statements specifying identifying information, the macro statements causing the receiving email system, when querying the email domain validation record, to include identifying information of the sender of the email in the second request;and publish the created email domain validation record as a DNS record of the email domain.
  6. 11
    A system comprising:the computing device according to claims 9 or 10;a second computing device comprising a second processor and a second non-transitory computer readable storage medium, configured to store instructions, that when executed by the second processor, cause the second processor to: receive, at a Domain Name System (DNS) server, from the receiving email system, a DNS query for an email domain stored at the DNS server, the DNS query including the identifying information of the sender of the email, and the email identified as being from the email domain, wherein the target domain comprises the DNS server;extract the identifying information of the email sender from the DNS query for identification of one of a plurality of delivering organizations;determine whether the identified delivering organization is authorized to deliver email on behalf of the email domain;generate, in response to determining that the identified delivering organization is authorized to deliver email on behalf of the email domain, a target validation record based on the identity of the authorized delivering organization and the email domain, the target validation record including one or more rules indicating to the receiving email system that the delivering organization is an authorized sender of email for the email domain;and transmit the target validation record to the receiving email system in response to the DNS query.