Skip to main content

IPv6 Email Authentication
draft-otis-ipv6-email-authent-01

Document Type Expired Internet-Draft (individual)
Expired & archived
Authors Douglas Otis , David Rand
Last updated 2013-11-10 (Latest revision 2013-05-09)
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

IPv6 facilitates network routing over an incredibly vast address space, but abuse mitigation resolving to underlying structures of routes or blocks of prefixes would be highly disruptive due to collateral effects. Use of domains minimizes unintended coincidental blocking while offering the consolidation necessary to facilitate connection management. Currently, email lacks conventions ensuring SMTP clients can be identified by an authenticated domain. DKIM is independent of intended recipients and domains accountable for having sent email. SPF normally requires several text based responses imposing high overhead to query various locations. These locations can be constructed by email-address local-part macros which can flood caches or leverage DNS name compression to further increase network DDoS amplifications when receivers' attempt to verify message sources which may then only offer authorization, not authentication of accountable domains. Most email abuse, including what might be imposed by SPF, is prevented with comprehensive mapping of the address space, but such mapping is impractical with IPv6. An effective authenticated domain name alternative is needed to provide a basis for assessing and reacting to abusive behavior. For most high scale protocols, this involves cryptography.

Authors

Douglas Otis
David Rand

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)