Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Assessing Email Authentication: A Study of Domain-based Security measures
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2024 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This work evaluates the security protocols in a chosen set of domains by scanning their email security measures. To do so we assessed whether the examined domains are configured with the email authentication protocols: Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC). These protocols are used for encountering phishing attacks and confronting the exploitation tactics used by attackers.

The results showed that all domains are configured with SPF. However, a lack of DKIM and DMARC utilization was found. We performed the analysis using three different tools to detect potential variations in the results. The study encompassed a total of 25 different domains and the results showed that all domains are configured with a valid SPF, a DKIM key was found in 21 domains, DMARC records were identified in 18 domains, each of these 18 domains adopted one of the three response policies: None, Quarantine, or Reject.

The response policy types varied among the domains, with 11 out of 18 domains setting their policy to None, which is used for monitoring, 4 domains are configured with the Quarantine policy, which sends flagged emails to the spam folder for review, while 3 domains adopt a Reject policy which discards unauthenticated emails.

The study emphasizes the necessity for reliable email authentication measures that aligns with the organization’s requirements and priorities.

Place, publisher, year, edition, pages
2024. , p. 11
Keywords [en]
DMARC, SPF, DKIM, Email Authentication, Cyber Security
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-22124Local ID: EXN300OAI: oai:DiVA.org:hv-22124DiVA, id: diva2:1886457
Subject / course
Computer engineering
Educational program
Nätverksteknik med IT-säkerhet
Supervisors
Examiners
Available from: 2024-08-23 Created: 2024-08-01 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Engineering Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 149 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf