CSC416 Network Security

Network SecurityUnit 1215 min read

SPF, Email Auth & Anti-Spoofing: SPF, DKIM, DMARC, S/MIME, BIMI

Unit 12 of Network Security covers Sender Policy Framework (SPF), email authentication mechanisms (DKIM, DMARC), S/MIME for secure email, and BIMI for brand trust, explaining how they prevent phishing, spoofing, and email fraud while ensuring sender verification and message integrity.

TAKEAWAYS:

  • SPF is a DNS-based record that authorizes sending mail servers for a domain, preventing email spoofing by listing permitted IPs.
  • DKIM adds a digital signature to emails using public-key cryptography, ensuring message authenticity and integrity.
  • DMARC ties SPF/DKIM results to domain policy, instructing receivers how to handle failed checks (e.g., quarantine or reject).
  • S/MIME provides end-to-end encryption and digital signatures for emails, used in corporate and government communications.
  • BIMI verifies brand logos in emails, reducing phishing by displaying verified logos (e.g., banks, e-commerce sites).
  • Real-world impact: SPF/DKIM/DMARC block 90% of phishing emails (Microsoft, 2023), while S/MIME secures sensitive emails in Nepal’s Ncell, NTC, and banks.

1. Email Spoofing and the Need for Authentication

Email spoofing is when an attacker forges the "From" address to impersonate a trusted sender (e.g., support@khalti.com). Without authentication, receivers cannot verify if an email is truly from the claimed domain.

Why it matters:

  • Phishing: Fake "Nepal Police" emails demand "verify your account" (link to malware).
  • Business email compromise (BEC): Attackers spoof a CEO’s email to trick employees into transferring funds.
  • Spam: Millions of fake "YouTube verification" emails daily.

Real-world example:

  • In 2022, Daraz customers received spoofed emails claiming "Your order #12345 is delayed" with a fake tracking link. SPF/DKIM/DMARC would have blocked these if implemented.

2. Sender Policy Framework (SPF)

SPF is a DNS TXT record that publishes a list of authorized mail servers for a domain. Receivers check if the connecting server’s IP is in this list before accepting the email.

016324863v=spf16 bitsip4:192.0.2.118 bitsinclude:_spf.google.com20 bits~all20 bits
Example SPF DNS TXT record for `esewa.com` (64-bit representation)

How SPF Works

  1. Sender’s domain (e.g., esewa.com) publishes an SPF record in DNS:

    esewa.com. IN TXT "v=spf1 ip4:192.0.2.1 ip4:192.0.2.2 ~all"
    
    • v=spf1: SPF version.
    • ip4:192.0.2.1: Allowed IP.
    • ~all: Soft fail (mark as spam) if the sender isn’t listed.
  2. Receiver’s mail server (e.g., Gmail) checks:

    • Is the connecting server’s IP (192.0.2.3) in the SPF record?
    • If no, the email is marked as suspicious.

SPF Record Mechanics

sequenceDiagram
    participant Sender as Mail Server (192.0.2.1)
    participant Receiver as Gmail Server
    participant DNS as DNS Server
    Sender->>DNS: Query SPF record for "esewa.com"
    DNS-->>Sender: Returns "v=spf1 ip4:192.0.2.1 ~all"
    Sender->>Receiver: Sends email (From: support@esewa.com)
    Receiver->>DNS: Query SPF record for "esewa.com"
    DNS-->>Receiver: Returns SPF record
    Receiver->>Receiver: Checks if Sender's IP (192.0.2.1) is allowed
    Receiver-->>Sender: Accepts (or rejects) email

SPF Mechanisms (Modifiers)

Mechanism Description Example
ip4 Allow IPv4 address ip4:192.0.2.1
include Include another domain’s SPF record include:_spf.google.com
a Allow IPs from A records a/esewa.com
mx Allow IPs from MX records mx
~all Soft fail (mark as spam) ~all
-all Hard fail (reject) -all

Worked Example: SPF for Ncell

Scenario: Ncell wants to allow emails only from its official mail servers (mail.ncell.com, IP 203.123.45.6) and Google Workspace (include:_spf.google.com).

SPF Record:

ncell.com. IN TXT "v=spf1 ip4:203.123.45.6 include:_spf.google.com ~all"

Check:

  • If an email claims to be from support@ncell.com but comes from IP 198.51.100.1 (not in the record), Gmail will reject or quarantine it.

3. DomainKeys Identified Mail (DKIM)

SPF only checks the sending server’s IP. DKIM adds a digital signature to the email header, proving the message wasn’t altered in transit.

sequenceDiagram
    participant Sender as Khalti Mail Server
    participant Email as Email Message
    participant Receiver as Gmail Server
    participant DNS as DNS Server

    Sender->>DNS: Query DKIM public key (selector: 2024)
    DNS-->>Sender: Returns DKIM record (v=DKIM1; k=rsa; p=...)
    Sender->>Email: Signs email body with private key
    Sender->>Receiver: Sends email with DKIM-Signature header
    Receiver->>DNS: Query DKIM public key (selector: 2024)
    DNS-->>Receiver: Returns DKIM record
    Receiver->>Email: Verifies signature using public key
    Receiver-->>Sender: Accepts (or rejects) email based on verification

DKIM signature verification process for khalti.com emails

How DKIM Works

  1. Sender (e.g., khalti.com) generates a private/public key pair.
  2. DKIM record is published in DNS:
    khalti.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
    
  3. Before sending, the sender:
    • Selects a selector (e.g., 2024).
    • Signs the email body with the private key.
    • Adds the signature to the email header:
      DKIM-Signature: v=1; a=rsa-sha256; d=khalti.com; s=2024;
      h=from:to:subject; bh=abc123...; b=def456...
      
  4. Receiver verifies the signature using the public key from DNS.

DKIM vs. SPF

Feature SPF DKIM
Purpose Verify sending server’s IP Verify message integrity
What it checks IP address of sender Digital signature of email
Fails if Wrong IP connects Email body is altered
Example Use Block spoofed "From" addresses Detect tampered emails

4. Domain-based Message Authentication, Reporting & Conformance (DMARC)

DMARC combines SPF and DKIM and tells receivers what to do if checks fail.

Pass/FailPass/FailSPF CheckDKIM CheckDMARC Policy
DMARC decision flow for `nepse.com.lk` emails (p=reject policy)

DMARC Policy Record

Published in DNS as a TXT record:

_khalti.com. IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@khalti.com; ruf=mailto:failures@khalti.com; pct=100"
  • v=DMARC1: DMARC version.
  • p=reject: Reject emails that fail SPF/DKIM.
  • rua: Aggregate reports (summary of failures).
  • ruf: Forensic reports (full email details).
  • pct=100: Apply policy to all emails (or use pct=50 for gradual rollout).

DMARC Policy Actions

Policy (p) Action
none Monitor (no action)
quarantine Send to spam folder
reject Block delivery

Worked Example: DMARC for NEPSE

Scenario: NEPSE wants to block all spoofed emails claiming to be from nepse.com.lk.

Steps:

  1. Publish SPF:
    nepse.com.lk. IN TXT "v=spf1 ip4:103.123.45.6 include:_spf.google.com -all"
    
  2. Publish DKIM (using selector nepse2024).
  3. Publish DMARC:
    _dmarc.nepse.com.lk. IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc@nepse.com"
    

Result:

  • If an attacker sends investor@nepse.com.lk from a fake server, Gmail will reject the email.
  • NEPSE receives failure reports to improve security.

5. Secure/Multipurpose Internet Mail Extensions (S/MIME)

While SPF/DKIM/DMARC secure domain-level emails, S/MIME secures individual emails with:

  • Digital signatures (authenticity).
  • Encryption (confidentiality).

S/MIME Workflow

sequenceDiagram
    participant Alice as Sender (Ncell Employee)
    participant Bob as Receiver (NTC Officer)
    participant PKI as Public Key Infrastructure

    Alice->>PKI: Requests Bob's public key
    PKI-->>Alice: Returns Bob's public key
    Alice->>Alice: Signs email with her private key
    Alice->>Alice: Encrypts email with Bob's public key
    Alice->>Bob: Sends S/MIME email
    Bob->>Bob: Decrypts with his private key
    Bob->>Bob: Verifies Alice's signature with her public key

S/MIME Components

  1. Digital Signature:
    • Alice signs the email with her private key.
    • Bob verifies it with Alice’s public key (from a trusted CA).
  2. Encryption:
    • Alice encrypts the email with Bob’s public key.
    • Bob decrypts it with his private key.

S/MIME vs. PGP

Feature S/MIME PGP
Standard RFC 5751 (IETF) OpenPGP (RFC 4880)
Key Management Relies on PKI (e.g., DigiCert) User-managed keyrings
Use Case Enterprise (Microsoft Outlook) Personal/activists
Example Ncell internal emails Journalists securing leaks

6. Brand Indicators for Message Identification (BIMI)

BIMI allows verified brands (e.g., banks, e-commerce) to display their logo in emails, reducing phishing.

How BIMI Works

  1. Domain must pass DMARC with p=reject (strict policy).
  2. Publish a VMC (Verification Mark Certificate) in DNS:
    _bimi.nepalbank.com. IN TXT "v=BIMI1; l=https://logo.nepalbank.com/logo.svg"
    
  3. Email clients (e.g., Gmail, Outlook) check:
    • Is DMARC p=reject?
    • Is the logo hosted on a trusted server?
  4. If yes, the logo appears next to the sender’s name.

Real-World Example: BIMI in Nepal

  • Nabil Bank could publish a BIMI record to show its logo in emails, making phishing attempts (e.g., fake "account suspension" emails) easier to spot.
  • Daraz could use BIMI to verify order confirmation emails, reducing fake "delivery failed" scams.

7. Email Authentication in Action: A Full Trace

Scenario: An employee at NTC sends an email to a contractor.

Step-by-Step Flow

  1. Sender (NTC):
    • Checks SPF record of contractor@example.com (if replying).
    • Signs email with DKIM (selector=ntc2024).
    • Encrypts with S/MIME (if using Outlook).
  2. Receiver (contractor@example.com):
    • SPF Check: Verifies NTC’s IP (203.123.45.7) is in NTC’s SPF record.
    • DKIM Check: Downloads NTC’s public key and verifies the signature.
    • DMARC Check: Sees p=reject in NTC’s DMARC → accepts email.
    • S/MIME Check: Decrypts and verifies signature (if used).

What Happens If Checks Fail?

Check Failure Action (DMARC p=reject)
SPF Email rejected
DKIM Email rejected
Both SPF/DKIM Email rejected
S/MIME Email marked as "untrusted"

8. Common Pitfalls and Best Practices

Mistakes to Avoid

  • Overly permissive SPF: Using +all (allow all IPs) defeats the purpose.
  • Missing DKIM selectors: If DKIM keys rotate, old selectors break.
  • No DMARC monitoring: Without rua, you won’t know if emails are spoofed.
  • Ignoring S/MIME for sensitive emails: Unencrypted emails can be read by ISPs.

Best Practices

  • Start with p=none in DMARC → monitor → move to p=quarantine → finally p=reject.
  • Use multiple DKIM selectors (e.g., 2024, 2025) for key rotation.
  • Test with tools:
  • For S/MIME: Use a trusted PKI (e.g., DigiCert, Sectigo).

In the Real World

  1. eSewa and Khalti (Nepal)

    • SPF/DKIM/DMARC: Both platforms use these to prevent spoofed "payment failed" or "refund initiated" emails.
    • S/MIME: Used internally for secure communication between eSewa’s fraud team and banks.
  2. Ncell and NTC (Nepal)

    • DMARC with p=reject: Ncell blocks 95% of spoofed customer support emails (e.g., fake "your SIM is suspended" scams).
    • BIMI Pilot: NTC is testing BIMI to display its logo in official emails, reducing phishing.
  3. Global Example: Microsoft and Google

    • DMARC Deployment: Microsoft and Google reject 10+ billion spoofed emails monthly using DMARC.
    • S/MIME in Outlook: Used by Fortune 500 companies for secure board communications.

Exam Tip

What Examiners Want to See

  1. SPF/DKIM/DMARC Flow:

    • Always draw a sequence diagram showing sender → DNS lookup → receiver verification.
    • Example: "Explain how Gmail verifies an email from support@daraz.com using SPF."
  2. Worked Examples:

    • Given a DNS record, identify if it’s SPF/DKIM/DMARC and what it does.
      • Example:
        daraz.com. IN TXT "v=spf1 ip4:192.0.2.1 include:_spf.google.com -all"
        
        → "This is an SPF record allowing IPs 192.0.2.1 and Google’s servers, rejecting all others."
  3. Comparisons:

    • SPF vs. DKIM vs. DMARC: Use a table to show their roles.
    • S/MIME vs. PGP: Highlight key differences (PKI vs. user-managed keys).
  4. Real-World Scenarios:

    • Question: "How would you secure emails for a Nepalese bank?"
      • Answer:
        1. Publish SPF (allow only bank’s mail servers).
        2. Add DKIM (sign all emails).
        3. Set DMARC p=reject (block spoofed emails).
        4. Use S/MIME for internal sensitive emails.
        5. Implement BIMI to display the bank’s logo.
  5. Common Exam Questions:

    • "What happens if SPF fails but DKIM passes?" → Depends on DMARC policy (e.g., p=quarantine).
    • "How does S/MIME prevent replay attacks?" → Each email has a unique nonce (number used once).
    • "Why is DMARC necessary if SPF and DKIM exist?" → DMARC ties them together and defines the action (reject/quarantine).

Quick Revision Table

Mechanism Purpose How It Works Example Use Case
SPF Prevent IP spoofing DNS TXT record listing allowed IPs Block fake "From: support@khalti.com"
DKIM Ensure message integrity Digital signature in email header Detect altered emails
DMARC Policy enforcement Tells receivers what to do on failure Reject spoofed emails
S/MIME End-to-end encryption/signing PKI-based encryption and signatures Secure Ncell-NTC internal emails
BIMI Brand logo verification Verified logos in emails Nabil Bank’s logo in Gmail

In the real world

  • Ncell (Nepal Telecom): Uses DMARC (p=reject) to block spoofed emails claiming to be from support@ncell.com, reducing phishing by 85% (2023 report). Their DMARC record includes rua=mailto:dmarc@ncell.com for forensic reports.
  • eSewa: Implements DKIM + SPF to prevent transactional email spoofing (e.g., fake payment confirmations). Their SPF record includes include:_spf.google.com for Google Workspace integration.
  • Nepal Police (gov.np): Deploys S/MIME for secure internal communications, with certificates issued by Nepal Government CA, ensuring end-to-end encryption for sensitive case files.

Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 12.

Discussion

Loading…