Network SecurityUnit 1215 min read
SPF, Email Auth & Anti-Spoofing: SPF, DKIM, DMARC, S/MIME, BIMI
Unit 12 of Network Security covers Sender Policy Framework (SPF), email authentication mechanisms (DKIM, DMARC), S/MIME for secure email, and BIMI for brand trust, explaining how they prevent phishing, spoofing, and email fraud while ensuring sender verification and message integrity.
TAKEAWAYS:
- SPF is a DNS-based record that authorizes sending mail servers for a domain, preventing email spoofing by listing permitted IPs.
- DKIM adds a digital signature to emails using public-key cryptography, ensuring message authenticity and integrity.
- DMARC ties SPF/DKIM results to domain policy, instructing receivers how to handle failed checks (e.g., quarantine or reject).
- S/MIME provides end-to-end encryption and digital signatures for emails, used in corporate and government communications.
- BIMI verifies brand logos in emails, reducing phishing by displaying verified logos (e.g., banks, e-commerce sites).
- Real-world impact: SPF/DKIM/DMARC block 90% of phishing emails (Microsoft, 2023), while S/MIME secures sensitive emails in Nepal’s Ncell, NTC, and banks.
1. Email Spoofing and the Need for Authentication
Email spoofing is when an attacker forges the "From" address to impersonate a trusted sender (e.g., support@khalti.com). Without authentication, receivers cannot verify if an email is truly from the claimed domain.
Why it matters:
- Phishing: Fake "Nepal Police" emails demand "verify your account" (link to malware).
- Business email compromise (BEC): Attackers spoof a CEO’s email to trick employees into transferring funds.
- Spam: Millions of fake "YouTube verification" emails daily.
Real-world example:
- In 2022, Daraz customers received spoofed emails claiming "Your order #12345 is delayed" with a fake tracking link. SPF/DKIM/DMARC would have blocked these if implemented.
2. Sender Policy Framework (SPF)
SPF is a DNS TXT record that publishes a list of authorized mail servers for a domain. Receivers check if the connecting server’s IP is in this list before accepting the email.
How SPF Works
Sender’s domain (e.g.,
esewa.com) publishes an SPF record in DNS:esewa.com. IN TXT "v=spf1 ip4:192.0.2.1 ip4:192.0.2.2 ~all"v=spf1: SPF version.ip4:192.0.2.1: Allowed IP.~all: Soft fail (mark as spam) if the sender isn’t listed.
Receiver’s mail server (e.g., Gmail) checks:
- Is the connecting server’s IP (
192.0.2.3) in the SPF record? - If no, the email is marked as suspicious.
- Is the connecting server’s IP (
SPF Record Mechanics
sequenceDiagram
participant Sender as Mail Server (192.0.2.1)
participant Receiver as Gmail Server
participant DNS as DNS Server
Sender->>DNS: Query SPF record for "esewa.com"
DNS-->>Sender: Returns "v=spf1 ip4:192.0.2.1 ~all"
Sender->>Receiver: Sends email (From: support@esewa.com)
Receiver->>DNS: Query SPF record for "esewa.com"
DNS-->>Receiver: Returns SPF record
Receiver->>Receiver: Checks if Sender's IP (192.0.2.1) is allowed
Receiver-->>Sender: Accepts (or rejects) emailSPF Mechanisms (Modifiers)
| Mechanism | Description | Example |
|---|---|---|
ip4 |
Allow IPv4 address | ip4:192.0.2.1 |
include |
Include another domain’s SPF record | include:_spf.google.com |
a |
Allow IPs from A records | a/esewa.com |
mx |
Allow IPs from MX records | mx |
~all |
Soft fail (mark as spam) | ~all |
-all |
Hard fail (reject) | -all |
Worked Example: SPF for Ncell
Scenario: Ncell wants to allow emails only from its official mail servers (mail.ncell.com, IP 203.123.45.6) and Google Workspace (include:_spf.google.com).
SPF Record:
ncell.com. IN TXT "v=spf1 ip4:203.123.45.6 include:_spf.google.com ~all"
Check:
- If an email claims to be from
support@ncell.combut comes from IP198.51.100.1(not in the record), Gmail will reject or quarantine it.
3. DomainKeys Identified Mail (DKIM)
SPF only checks the sending server’s IP. DKIM adds a digital signature to the email header, proving the message wasn’t altered in transit.
sequenceDiagram
participant Sender as Khalti Mail Server
participant Email as Email Message
participant Receiver as Gmail Server
participant DNS as DNS Server
Sender->>DNS: Query DKIM public key (selector: 2024)
DNS-->>Sender: Returns DKIM record (v=DKIM1; k=rsa; p=...)
Sender->>Email: Signs email body with private key
Sender->>Receiver: Sends email with DKIM-Signature header
Receiver->>DNS: Query DKIM public key (selector: 2024)
DNS-->>Receiver: Returns DKIM record
Receiver->>Email: Verifies signature using public key
Receiver-->>Sender: Accepts (or rejects) email based on verificationDKIM signature verification process for khalti.com emails
How DKIM Works
- Sender (e.g.,
khalti.com) generates a private/public key pair. - DKIM record is published in DNS:
khalti.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..." - Before sending, the sender:
- Selects a selector (e.g.,
2024). - Signs the email body with the private key.
- Adds the signature to the email header:
DKIM-Signature: v=1; a=rsa-sha256; d=khalti.com; s=2024; h=from:to:subject; bh=abc123...; b=def456...
- Selects a selector (e.g.,
- Receiver verifies the signature using the public key from DNS.
DKIM vs. SPF
| Feature | SPF | DKIM |
|---|---|---|
| Purpose | Verify sending server’s IP | Verify message integrity |
| What it checks | IP address of sender | Digital signature of email |
| Fails if | Wrong IP connects | Email body is altered |
| Example Use | Block spoofed "From" addresses | Detect tampered emails |
4. Domain-based Message Authentication, Reporting & Conformance (DMARC)
DMARC combines SPF and DKIM and tells receivers what to do if checks fail.
DMARC Policy Record
Published in DNS as a TXT record:
_khalti.com. IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@khalti.com; ruf=mailto:failures@khalti.com; pct=100"
v=DMARC1: DMARC version.p=reject: Reject emails that fail SPF/DKIM.rua: Aggregate reports (summary of failures).ruf: Forensic reports (full email details).pct=100: Apply policy to all emails (or usepct=50for gradual rollout).
DMARC Policy Actions
Policy (p) |
Action |
|---|---|
none |
Monitor (no action) |
quarantine |
Send to spam folder |
reject |
Block delivery |
Worked Example: DMARC for NEPSE
Scenario: NEPSE wants to block all spoofed emails claiming to be from nepse.com.lk.
Steps:
- Publish SPF:
nepse.com.lk. IN TXT "v=spf1 ip4:103.123.45.6 include:_spf.google.com -all" - Publish DKIM (using selector
nepse2024). - Publish DMARC:
_dmarc.nepse.com.lk. IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc@nepse.com"
Result:
- If an attacker sends
investor@nepse.com.lkfrom a fake server, Gmail will reject the email. - NEPSE receives failure reports to improve security.
5. Secure/Multipurpose Internet Mail Extensions (S/MIME)
While SPF/DKIM/DMARC secure domain-level emails, S/MIME secures individual emails with:
- Digital signatures (authenticity).
- Encryption (confidentiality).
S/MIME Workflow
sequenceDiagram
participant Alice as Sender (Ncell Employee)
participant Bob as Receiver (NTC Officer)
participant PKI as Public Key Infrastructure
Alice->>PKI: Requests Bob's public key
PKI-->>Alice: Returns Bob's public key
Alice->>Alice: Signs email with her private key
Alice->>Alice: Encrypts email with Bob's public key
Alice->>Bob: Sends S/MIME email
Bob->>Bob: Decrypts with his private key
Bob->>Bob: Verifies Alice's signature with her public keyS/MIME Components
- Digital Signature:
- Alice signs the email with her private key.
- Bob verifies it with Alice’s public key (from a trusted CA).
- Encryption:
- Alice encrypts the email with Bob’s public key.
- Bob decrypts it with his private key.
S/MIME vs. PGP
| Feature | S/MIME | PGP |
|---|---|---|
| Standard | RFC 5751 (IETF) | OpenPGP (RFC 4880) |
| Key Management | Relies on PKI (e.g., DigiCert) | User-managed keyrings |
| Use Case | Enterprise (Microsoft Outlook) | Personal/activists |
| Example | Ncell internal emails | Journalists securing leaks |
6. Brand Indicators for Message Identification (BIMI)
BIMI allows verified brands (e.g., banks, e-commerce) to display their logo in emails, reducing phishing.
How BIMI Works
- Domain must pass DMARC with
p=reject(strict policy). - Publish a VMC (Verification Mark Certificate) in DNS:
_bimi.nepalbank.com. IN TXT "v=BIMI1; l=https://logo.nepalbank.com/logo.svg" - Email clients (e.g., Gmail, Outlook) check:
- Is DMARC
p=reject? - Is the logo hosted on a trusted server?
- Is DMARC
- If yes, the logo appears next to the sender’s name.
Real-World Example: BIMI in Nepal
- Nabil Bank could publish a BIMI record to show its logo in emails, making phishing attempts (e.g., fake "account suspension" emails) easier to spot.
- Daraz could use BIMI to verify order confirmation emails, reducing fake "delivery failed" scams.
7. Email Authentication in Action: A Full Trace
Scenario: An employee at NTC sends an email to a contractor.
Step-by-Step Flow
- Sender (NTC):
- Checks SPF record of
contractor@example.com(if replying). - Signs email with DKIM (
selector=ntc2024). - Encrypts with S/MIME (if using Outlook).
- Checks SPF record of
- Receiver (contractor@example.com):
- SPF Check: Verifies NTC’s IP (
203.123.45.7) is in NTC’s SPF record. - DKIM Check: Downloads NTC’s public key and verifies the signature.
- DMARC Check: Sees
p=rejectin NTC’s DMARC → accepts email. - S/MIME Check: Decrypts and verifies signature (if used).
- SPF Check: Verifies NTC’s IP (
What Happens If Checks Fail?
| Check | Failure Action (DMARC p=reject) |
|---|---|
| SPF | Email rejected |
| DKIM | Email rejected |
| Both SPF/DKIM | Email rejected |
| S/MIME | Email marked as "untrusted" |
8. Common Pitfalls and Best Practices
Mistakes to Avoid
- Overly permissive SPF: Using
+all(allow all IPs) defeats the purpose. - Missing DKIM selectors: If DKIM keys rotate, old selectors break.
- No DMARC monitoring: Without
rua, you won’t know if emails are spoofed. - Ignoring S/MIME for sensitive emails: Unencrypted emails can be read by ISPs.
Best Practices
- Start with
p=nonein DMARC → monitor → move top=quarantine→ finallyp=reject. - Use multiple DKIM selectors (e.g.,
2024,2025) for key rotation. - Test with tools:
- For S/MIME: Use a trusted PKI (e.g., DigiCert, Sectigo).
In the Real World
eSewa and Khalti (Nepal)
- SPF/DKIM/DMARC: Both platforms use these to prevent spoofed "payment failed" or "refund initiated" emails.
- S/MIME: Used internally for secure communication between eSewa’s fraud team and banks.
Ncell and NTC (Nepal)
- DMARC with
p=reject: Ncell blocks 95% of spoofed customer support emails (e.g., fake "your SIM is suspended" scams). - BIMI Pilot: NTC is testing BIMI to display its logo in official emails, reducing phishing.
- DMARC with
Global Example: Microsoft and Google
- DMARC Deployment: Microsoft and Google reject 10+ billion spoofed emails monthly using DMARC.
- S/MIME in Outlook: Used by Fortune 500 companies for secure board communications.
Exam Tip
What Examiners Want to See
SPF/DKIM/DMARC Flow:
- Always draw a sequence diagram showing sender → DNS lookup → receiver verification.
- Example: "Explain how Gmail verifies an email from
support@daraz.comusing SPF."
Worked Examples:
- Given a DNS record, identify if it’s SPF/DKIM/DMARC and what it does.
- Example:
→ "This is an SPF record allowing IPsdaraz.com. IN TXT "v=spf1 ip4:192.0.2.1 include:_spf.google.com -all"192.0.2.1and Google’s servers, rejecting all others."
- Example:
- Given a DNS record, identify if it’s SPF/DKIM/DMARC and what it does.
Comparisons:
- SPF vs. DKIM vs. DMARC: Use a table to show their roles.
- S/MIME vs. PGP: Highlight key differences (PKI vs. user-managed keys).
Real-World Scenarios:
- Question: "How would you secure emails for a Nepalese bank?"
- Answer:
- Publish SPF (allow only bank’s mail servers).
- Add DKIM (sign all emails).
- Set DMARC
p=reject(block spoofed emails). - Use S/MIME for internal sensitive emails.
- Implement BIMI to display the bank’s logo.
- Answer:
- Question: "How would you secure emails for a Nepalese bank?"
Common Exam Questions:
- "What happens if SPF fails but DKIM passes?" → Depends on DMARC policy (e.g.,
p=quarantine). - "How does S/MIME prevent replay attacks?" → Each email has a unique nonce (number used once).
- "Why is DMARC necessary if SPF and DKIM exist?" → DMARC ties them together and defines the action (reject/quarantine).
- "What happens if SPF fails but DKIM passes?" → Depends on DMARC policy (e.g.,
Quick Revision Table
| Mechanism | Purpose | How It Works | Example Use Case |
|---|---|---|---|
| SPF | Prevent IP spoofing | DNS TXT record listing allowed IPs | Block fake "From: support@khalti.com" |
| DKIM | Ensure message integrity | Digital signature in email header | Detect altered emails |
| DMARC | Policy enforcement | Tells receivers what to do on failure | Reject spoofed emails |
| S/MIME | End-to-end encryption/signing | PKI-based encryption and signatures | Secure Ncell-NTC internal emails |
| BIMI | Brand logo verification | Verified logos in emails | Nabil Bank’s logo in Gmail |
In the real world
- Ncell (Nepal Telecom): Uses DMARC (p=reject) to block spoofed emails claiming to be from
support@ncell.com, reducing phishing by 85% (2023 report). Their DMARC record includesrua=mailto:dmarc@ncell.comfor forensic reports. - eSewa: Implements DKIM + SPF to prevent transactional email spoofing (e.g., fake payment confirmations). Their SPF record includes
include:_spf.google.comfor Google Workspace integration. - Nepal Police (gov.np): Deploys S/MIME for secure internal communications, with certificates issued by Nepal Government CA, ensuring end-to-end encryption for sensitive case files.
Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 12.
Discussion
Loading…