Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

June 29th, 2011, 12:54 GMT · By

Gmail Makes Spotting Fake Emails Easier

SHARE:

Adjust text size:


Gmail displays more information about senders
Enlarge picture
Google made some changes to the way Gmail displays the origin of emails in order to help users determine if they are dealing with fake messages.

Up until now, when opening an email message, Gmail used to show the name of the sender followed by their email address, if they weren't already in the user's contacts list.

However, this origin information is not enough considering that the vast majority of phishers and spammers are capable of spoofing email addresses.

Google has now changed the Gmail interface to also display the domain name though which the message was sent when it doesn't correspond to the email address.

This is very useful because scammers don't usually have access to actual email servers of the spoofed addresses.

For example, if someone sends an email purporting to come from @paypal.com address, the message won't actually be delivered through PayPal's legit email server, unless the scammer managed to hack it which would be an extraordinary occurrance.

However, it's worth pointing out that not all emails sent via third-party domains are part of phishing or spam attacks.

For example, some websites allow users to share content with their friends via email. These notifications are usually sent in the name of the user, but through the website's own email server. There have been cases where this functionality has been abused.

Google also uses a system to check the authenticity of emails based on special headers added by technologies like DKIM or SPF. Messages that lack these headers but claim to originate from sources known to use these technologies are automatically flagged as suspicious.

In such cases will now see a warning at the top of the email that reads "This message might not be sent by <email address>" and will get an option to report the phishing attempt.

TELL US WHAT YOU THINK:

1,537 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Google Apps Customers Get Email Authentication for Free

Google Gives Gmail Users Security Advice Through Checklist

New Gmail Account Phishing Campaign in Circulation

Government Officials and Political Activists Targeted in Gmail Spear Phishing Attack

READER COMMENTS:


Comment #1 by: Tom on 29 Jun 2011, 14:36 UTC reply to this comment

It would be nice if WWW technology would sense these spoofs and kill them at the send point and never deliver to any email server or email address, now that type of technology would just about end the attempts at spoofing or give them a whole new trial effort at making spam.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM