USENIX Security2023Top-tier venue
You've Got Report: Measurement and Security Implications of DMARC Reporting
Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong Chung
Abstract
Email, since its invention, has become the most widely used communication system and SMTP is the standard for email transmission on the Internet. However, SMTP lacks built-in security features, such as sender authentication, making it vulnerable to attacks, including sender spoofing. To address the threat of spoofing, several security extensions, such as SPF or DKIM, have been proposed. Domain-based Message Authentication Reporting and Conformance (DMARC) was introduced in 2012 as a way for domain name owners to publish desired actions for email receivers to take through a DNS record if SPF or DKIM validation fails. The DMARC record can also request email receivers to send machine-generated reports back to the specified addresses to aid domain name owners in detecting and evaluating the risk of spoofed emails. However, DMARC's complexity creates opportunities for mismanagement that can be exploited by attackers. This paper presents a large-scale and comprehensive measurement study of DMARC reporting deployment and management. We collected data for all second-level domains under the .com, .net, .org, and .se TLDs over 13 months to analyze deployment and management from the domain name owner's perspective. Additionally, we investigated 7 popular email hosting services and 2 open-source DMARC reporting software to understand their reporting practices. Our study reveals pervasive mismanagement and missing security considerations in DMARC reporting. For example, we found that a single email from an attacker can make a victim SMTP server receive a large number of reports with a high amplification factor (e.g., 1,460×) by exploiting misconfigured SMTP servers. Based on our findings of several operational misconfigurations for DMARC reporting, we provide recommendations for improvement.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2d1849e7-4eee-46af-a9c6-8f75103a8715Cited by top-tier papers7
- PiMRef: Deducing Ever-evolving Spear-phishing Emails with Knowledge Base InvariantsRuofan Liu, Yun Lin, Yuxin Wang, Xiwen Teoh et al.CCS 2026 · 4 citations
- SPF Beyond the Standard: Management and Operational Challenges in Practice and Practical RecommendationsMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2024 · 3 citations
- Unfiltered: Measuring Cloud-based Email Filtering BypassesSumanth Rao, Enze Liu, Grant Ho, Geoffrey M. Voelker et al.WWW 2024 · 1 citation
- CoordMail: Exploiting SMTP Timeout and Command Interaction to Coordinate Email Middleware for Convergence Amplification AttackRuixuan Li, Chaoyi Lu, Baojun Liu, Yanzhong Lin et al.NDSS 2026 · 1 citation
- Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this VulnerabilityChuhan Wang, Chenkai Wang, Songyi Yang, Sophia Liu et al.USENIX Security 2025
Builds on10
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 94 citations
- You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS CertificatesRichard Roberts, Yaelle Goldschlag, Rachel Walter, Taejoong Chung et al.CCS 2019 · 52 citations
- Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing AttacksKaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng et al.USENIX Security 2021 · 49 citations
Related papers
- A Large-scale and Longitudinal Measurement Study of DKIM DeploymentChuhan Wang, Kaiwen Shen, Minglei Guo, Yuxuan Zhao et al.USENIX Security 2022
- FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email SystemsJinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo et al.USENIX Security 2024 · 7 citations
- Composition Kills: A Case Study of Email Sender AuthenticationJianjun Chen, Vern Paxson, Jian JiangUSENIX Security 2020
- A Longitudinal and Comprehensive Study of the DANE Ecosystem in EmailHyeonmin Lee, Aniketh Gireesh, Roland van Rijswijk-Deij, Taekyoung Kwon et al.USENIX Security 2020
- BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the InternetChuhan Wang, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang et al.NDSS 2024
