What Email Servers Can Tell to Johnny: An Empirical Study of Provider-to-Provider Email Security

被引:7
作者
Kambourakis, Georgios [1 ]
Gil, Gerard Draper [1 ]
Sanchez, Ignacio [1 ]
机构
[1] European Commiss, Joint Res Ctr JRC, I-21027 Ispra, Italy
来源
IEEE ACCESS | 2020年 / 8卷 / 08期
关键词
Electronic mail; Security; Servers; Protocols; Standards; Internet; Postal services; Email security; Internet measurement; network security; SMTP;
D O I
10.1109/ACCESS.2020.3009122
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With hundred billions of emails sent daily, the adoption of contemporary email security standards and best practices by the respective providers are of utmost importance to everyone of us. Leaving out the user-dependent measures, say, S/MIME and PGP, this work concentrates on the current security standards adopted in practice by providers to safeguard the communications among their SMTP servers. To this end, we developed a non-intrusive tool coined MECSA, which is publicly available as a web application service to anyone who wishes to instantly assess the security status of their email provider regarding both the inbound and outbound communication channels. By capitalising on the data collected by MECSA over a period of 15 months, that is, approximate to 7,650 assessments, analysing a total of 3,236 unique email providers, we detail on the adoption rate of state-of-the-art email security extensions, including STARTTLS, SPF, DKIM, DMARC, and MTA-STS. Our results indicate a clear increase in encrypted connections and in the use of SPF, but also considerable retardation in the penetration rate of the rest of the standards. This tardiness is further aggravated by the still low prevalence of DNSSEC, which is also appraised for the email security space in the context of this work.
引用
收藏
页码:130066 / 130081
页数:16
相关论文
共 59 条
  • [1] Alexa Internet, 2020, TOP SIT WEB
  • [2] DNS amplification attack revisited
    Anagnostopoulos, Marios
    Kambourakis, Georgios
    Kopanos, Panagiotis
    Louloudakis, Georgios
    Gritzalis, Stefanos
    [J]. COMPUTERS & SECURITY, 2013, 39 : 475 - 485
  • [3] Andrews M., 1998, NEGATIVE CACHING DNS
  • [4] [Anonymous], 2020, MAJESTIC MILLION
  • [5] [Anonymous], 2014, CURRENT STATE SMTP S
  • [6] [Anonymous], 4033 RFC INT ENG TAS
  • [7] [Anonymous], 1999, P 8 C US SEC S US
  • [8] Arkin B., 2013, ADOBE IMPORTANT CUST
  • [9] Barker E., 2019, 800131A SP NAT I STA
  • [10] Understanding the Role of Registrars in DNSSEC Deployment
    Chung, Taejoong
    van Rijswijk-Deij, Roland
    Choffnes, David
    Levin, Dave
    Maggs, Bruce M.
    Mislove, Alan
    Wilson, Christo
    [J]. PROCEEDINGS OF THE 2017 INTERNET MEASUREMENT CONFERENCE (IMC'17), 2017, : 369 - 383