This site uses cookies. By continuing to browse this site you are agreeing to our use of cookies. Find out more.X

Experts publish DKIM flaw best practice

Share this article:

Messaging security experts have published best practice guidance on how to avoid flawed implementation of the DKIM anti-phishing standard.

Google was among companies caught out in October using DomainKeys Identified Mail (DKIM) keys that were too short, allowing a researcher to spoof emails to Sergey Brin and Larry Page, purportedly from each other.

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG), which counts Google as one of its sponsors, published guidance on Tuesday calling on business enterprises to replace previously secure 512- and 768-bit verification keys with 1024-bit and higher encryption.

"Technology is advancing, and to keep pace with hackers, the industry needs to revisit its practices in light of their expanding capabilities," M3AAWG co-chairman Chris Roosenraad said in a statement.

The group recommended that keys be rotated quarterly, and that signatures should have an expiration period greater than the current key rotation period. Email services using DKIM should avoid sending messages in testing mode apart from during a testing period, and should monitor receiver performance using Domain-based Message Authentication, Reporting and Conformance (DMARC).

Share this article:

SC webcasts on demand

This is how to secure data in the cloud


Exclusive video webcast & Q&A sponsored by Vormetric


As enterprises look to take advantage of the cloud, they need to understand the importance of safeguarding their confidential and sensitive data in cloud environments. With the appropriate security safeguards, such as fine-grained access policies, a move to the cloud is as, or more, secure than an on-premise data storage.


View the webcast here to find out more

More in News

Brit Lauri Love faces more US hacking charges

Brit Lauri Love faces more US hacking charges

Lauri Love, a 29-year-old British man from Stradishall in Suffolk, has been charged by a US court with hacking into multiple US government computers and stealing more than 100,000 employee ...

StubHub ticketing agency taken for a million pounds

StubHub ticketing agency taken for a million pounds

Police around the world have arrested seven people - thought to have been tied into an international fraud ring - that allegedly defrauded the eBay-owned StubHub online ticketing service of ...

DDoS attacks grow as first DIY kits emerge

DDoS attacks grow as first DIY kits emerge

The latest report from Akamai Technologies has revealed another increase in DDoS attacks and the resurgence of botnets to carry out server-based attacks.