Skip to main content
QUICK REVIEW

[Paper Review] Towards the Adoption of Anti-spoofing Protocols

Hang Hu, Peng Peng|arXiv (Cornell University)|Nov 17, 2017
Spam and Phishing Detection25 references3 citations
TL;DR

This paper investigates why anti-spoofing email protocols (SPF, DKIM, DMARC) remain under-adopted despite years of development. Through a qualitative user study with 9 email administrators, it identifies key barriers—protocol limitations, weak incentives, and deployment complexity—and proposes solutions like improved UI security indicators, cloud-friendly configurations, and external enforcement mechanisms to boost adoption and reduce spoofing threats.

ABSTRACT

Email spoofing is a critical step of phishing, where the attacker impersonates someone the victim knows or trusts. In this paper, we conduct a qualitative study to explore why email spoofing is still possible after years of efforts to develop and deploy anti-spoofing protocols (e.g., SPF, DKIM, DMARC). First, we measure the protocol adoption by scanning 1 million Internet domains. We find the adoption rates are still low, especially for the new DMARC (3.1%). Second, to understand the reasons behind the low-adoption rate, we collect 4293 discussion threads (25.7K messages) from the Internet Engineering Task Force (IETF), a working group formed to develop and promote Internet standards. Our analysis shows key security and usability limitations in the protocol design, which makes it difficult to generate a positive "net effect" for a wide adoption. We validate our results by interviewing email administrators and discuss key implications for future anti-spoofing solutions.

Motivation & Objective

  • To understand the persistent challenges in adopting anti-spoofing email protocols (SPF, DKIM, DMARC) despite their standardization.
  • To investigate the technical, organizational, and incentive-related barriers preventing widespread deployment from the perspective of email administrators.
  • To explore practical solutions that can improve protocol adoption and reduce the success rate of email spoofing attacks.
  • To examine the role of email providers and users in mitigating spoofing threats when server-side authentication is incomplete or unreliable.

Proposed method

  • Conducted a qualitative user study with 9 email administrators from diverse institutions (universities, payment services, online communities) via online and in-person interviews.
  • Collected insights on perceived protocol weaknesses, deployment challenges, and motivations for or against adopting SPF, DKIM, and DMARC.
  • Analyzed administrator concerns regarding protocol defects, lack of critical mass, and operational risks such as false positives or email rejection.
  • Proposed practical improvements including cloud-friendly protocol configurations, testing modes (e.g., DMARC's 'pct' or 'monitoring' mode), and enhanced email user interface indicators.
  • Explored incentive mechanisms inspired by HTTPS adoption, such as visual trust indicators in email clients for authenticated domains.
  • Discussed policy-level enforcement for high-sensitivity domains (e.g., banks, government) to mandate authentication record publication.

Experimental results

Research questions

  • RQ1Why do email administrators perceive anti-spoofing protocols as insufficient despite their standardization?
  • RQ2What technical, organizational, and incentive-related factors hinder the widespread deployment of SPF, DKIM, and DMARC?
  • RQ3How do cloud-based email services and complex organizational email infrastructures affect protocol deployment?
  • RQ4What role can improved email user interfaces play in helping users detect spoofed emails when server-side authentication is incomplete?
  • RQ5What external incentives or enforcement mechanisms could accelerate critical mass adoption of anti-spoofing protocols?

Key findings

  • Email administrators acknowledge that SPF, DKIM, and DMARC are helpful but insufficient to fully prevent spoofing due to protocol limitations and misconfigurations.
  • The primary barrier to adoption is the lack of critical mass—authentication only works effectively when a large number of domains publish valid records.
  • Many organizations, especially those using cloud email services (e.g., G-Suite, Office 365), face significant deployment challenges due to limited control and configuration complexity.
  • Email administrators express strong concern about false positives, where legitimate emails are rejected due to misconfigured authentication policies.
  • There is a clear need for better deployment tools, including testing modes and simplified configuration interfaces, to reduce operational risk.
  • Improving email user interfaces to display authentication results (e.g., trust indicators) is seen as a viable complementary strategy to enhance user awareness and reduce spoofing success.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.