Gmail gets phishing protection

Google's popular free Web-based e-mail service is testing phishing protection designed to alert users to potential e-mail fraud attacks.

When a Gmail user opens a suspected phishing message, the software displays a large red dialog box stating: "Warning: This message may not be from whom it claims to be. Beware of following any links in it or of providing the sender with any personal information." The service also provides a hyperlink to information on Gmail's help pages about e-mail fraud.

Gmail will also remove all live hyperlinks from suspect HTML-based e-mails to protect users from potentially fraudulent Web sites. The addresses of the sites can still be accessed by examining the original code of the e-mail, a feature that Gmail provides.

Gmail has also provided a prominent 'Report Spam' button to its users. Any messages reported as spam get sent to a separate folder and Google's anti-spam software is notified. The company's help pages boast that "the more spam you mark, the better our system will get at weeding out those annoying messages".

In 2004, Google added a similar but less obvious button to its service, inviting users to 'Report Phishing'.

Google competitors Yahoo and Microsoft could not be reached for comment on whether their Web-based e-mail services offered users phishing protection.

Google has made several moves to cut down dubious e-mail. In October last year the company implemented DomainKeys on its e-mail servers. DomainKeys is a technology invented by Yahoo that tries to cross-check e-mail messages to verify their origin. Yahoo itself only implemented the service on its own mail servers in November 2004.

The idea behind DomainKeys is to thwart e-mail spoofing; or in other words, spam messages that appear to be from legitimate addresses but actually originate somewhere else.

DomainKeys attaches encrypted digital tags to each e-mail. Each e-mail is then compared to a publicly-available database of legitimate addresses. If the tag and database entry do not match when the e-mail arrives, the e-mail does not make it into a the receiver's inbox.

Alternatives to DomainKeys do exist; Webmail competitors America Online and Microsoft (which owns Hotmail) are pushing their own e-mail authentication technologies: Sender Policy Framework and Sender ID respectively. Yahoo and Microsoft have filed with the Internet Engineering Task Force (IETF) for their technologies to become Internet standards. The IETF is the body that defines standard Internet protocols such as TCP/IP.

Advertisement

Talkback 3 comments

    This has been there for a few ...Anonymous -- 05/04/05

    This has been there for a few months already.

    Bluebottle an Australian based ...Anonymous -- 15/04/05

    Bluebottle an Australian based free email service is rumoured to be beta testing a much smarter solution to phishing than Google. It solves phishing, s****ing and spam in an elegant fashion. Due for release to its users in near future.

    Actually it is Trusted Deliver ...Anonymous -- 17/04/05

    Actually it is Trusted Delivery that owns Bluebottle and I have tred the Beta version and it is fantastic. Bring it on soon for everyine.

Add your opinion

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured