latest update

Change in Implementation of Identities in webmail

Dear Clients,

As part of our efforts to cut down unsolicited email from our system and the problems created due to it, we're introducing certain measures to mitigate such activities. The idea behind these measures is to ensure that our email system is not viewed suspiciously by other service providers, which would lead to email originating from our servers to be deferred or rejected.

A lot of spam email that gets caught in our anti-spam filters, and is reported to us by the feedback loop with other email service providers, shows a high correlation with spoofed envelope from addresses. For example, when a user a@domain.com authenticates with smtp.domain.com in order to send a mail from our outbound servers, he can currently set whatever he wants as his "from" address, including email addresses that don't actually exist. This is a widely used method for email spoofing. In order to avoid such instances, users will now be asked to register a set of identities from their webmail interface for email addresses that need be used to send email. Every identity must have a valid email address, which must be authorized before it can be used to send email. The process to do so is fairly straightforward -

1. The user must log on to Webmail as a@domain.com, and add the necessary identities, say sales@domain.com and x@gmail.com.

2. The system will send verification emails to sales@domain.com and x@gmail.com, asking them: "a@domain.com is trying to use x@gmail.com to send email, do you want to allow this?"

3. Upon confirmation, the user will be able to send email as x@gmail.com or sales@domain.com from their account.

4. A list of user accounts are allowed to use sales@domain.com as their from address will be stored by the system (since there may be more than one user who may want to use the same from address).

To know more about setting identities, you may refer to this article: http://support.mailhostbox.com/email-users-guide/sender-identities

We are monitoring email logs to identify accounts that are sending email in this fashion. We shall pro-actively add identities for these accounts, and send out alerts to clients using a different 'from' address than the authenticated one. However, we might not be able to determine all users who need this feature. Thus, we recommend you to be informed about this policy change, and add sender identities if required. The identities must be created and verified before Tuesday 12th April, after which any unauthorized 'from' address will not be allowed to send email.

If you have any questions about this process, please contact our support team, we'd be happy to clarify doubts and provide any other information you need.


Posted on: Friday, 8th April 2011 3:07 AM