IP Library Granted Patent US 10,257,231
Granted Patent B2
US 10,257,231 · App. 15/663,771 · Granted Apr 9, 2019

Centralized validation of email senders via EHLO name and IP address targeting

Inventor: Peter Martin Goldstein (San Francisco, CA)
Assignee: VALIMAIL INC.
H04L63/20G06F21/56G06F21/6218H04L51/04H04L51/12H04L61/1511H04L61/304H04L63/08H04L63/126H04L63/14H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,257,231
App. No.
15/663,771
Granted
Apr 9, 2019
Kind
B2
Abstract

A DNS server receives from a receiving email system, a DNS query for an email domain stored at the DNS server, the DNS query including identifying information of a sender of an email. The DNS server extracts the identifying information of the email sender from the DNS query and identifies one of a plurality of delivering organizations from the information. The DNS server determines whether the identified delivering organization is authorized to deliver email on behalf of the email domain. In response to determining that the identified delivering organization is authorized to deliver email on behalf of the email domain, the DNS server generates a target validation record based on the identity of the authorized delivering organization and the email domain, the target validation record including one or more rules indicating to the receiving email system whether the delivering organization is an authorized sender of email for the email domain.

Claims (46)

1. A non-transitory computer readable storage medium configured to store instructions, the instructions when executed by a processor cause the processor to:

generate an email domain validation record to include in a Domain Name System (DNS) record of an email domain, the email domain validation record to be queried by a receiving email system when receiving an email from the email domain, and indicating to the receiving email system whether the sender of an email is an authorized sender for the email domain, the generation of the email domain validation record including instructions that when executed by the processor further cause the processor to:

generate the email domain validation record to include a target domain, the target domain being a domain distinct from the email domain, causing the receiving email system, when querying the email domain validation record, to submit a second request for a validation record to the target domain; and

generate the email domain validation record to include one or more Sender Policy Framework (SPF) macro statements specifying identifying information, the macro statements causing the receiving email system, when querying the email domain validation record, to include as identifying information at least one of an extended HELO (EHLO) name and Internet Protocol (IP) address of the sender of the email in the second request;

publish the created email domain validation record as a DNS TXT record of the email domain;

receive a query from any server for the DNS TXT record; and

transmit, in response to the receipt of the query, a DNS record to the server for authenticating an email at the receiving email system.

2. The computer readable storage medium of claim 1 , wherein the email domain validation record is a Sender Policy Framework (SPF) record.

3. The computer readable storage medium of claim 1 , wherein the macro statements and the target domain in the email domain validation record are separated by separating characters that are not allowed in the formation of a hostname.

4. The computer readable storage medium of claim 1 , wherein the DNS record is further hidden behind one or more DNS Canonical Name record (CNAME) entries.

5. A computer-implemented process, comprising:

generating an email domain validation record to include in a Domain Name System (DNS) record of an email domain, the email domain validation record to be queried by a receiving email system when receiving an email from the target domain, and indicating to the receiving email system whether the sender of an email is an authorized sender for the email domain, the generation of the email domain validation record further comprising:

generating the email domain validation record to include a target domain, the target domain being a domain distinct from the email domain, causing the receiving email system, when querying the email domain validation record, to submit a second request for a validation record to the target domain; and

generating the email domain validation record to include one or more macro statements specifying identifying information, the macro statements causing the receiving email system, when querying the email domain validation record, to include identifying information of the sender of the email in the second request;

publishing the created email domain validation record as a DNS TXT record of the email domain;

receiving a query from any server for the DNS TXT record; and

transmitting, in response to the receipt of the query, a DNS record to the server for authenticating an email at the receiving email system.

6. The process of claim 5 , wherein the email domain validation record is a Sender Policy Framework (SPF) record.

7. The process of claim 5 , wherein the macro statements are Sender Policy Framework (SPF) macros, and the macro statements instruct the receiving email system to include as the identifying information at least one of an extended HELO (EHLO) name and an Internet Protocol (IP) address of the sender of the email.

8. The process of claim 7 , wherein the macro statements and the target domain in the email domain validation record are separated by separating characters that are not allowed in the formation of a hostname.

9. The process of claim 5 , wherein the DNS record is further hidden behind one or more DNS Canonical Name record (CNAME) entries.

10. A computing device, comprising:

a processor;

a non-transitory computer readable storage medium, configured to store instructions, that when executed by the processor, cause the processor to:

generate an email domain validation record to include in a Domain Name System (DNS) record of an email domain, the email domain validation record to be queried by a receiving email system when receiving an email from the email domain, and indicating to the receiving email system whether the sender of an email is an authorized sender for the email domain, the generation of the email domain validation record including instructions that when executed by the processor further cause the processor to:

generate the email domain validation record to include a target domain, the target domain being a domain distinct from the email domain, causing the receiving email system, when querying the email domain validation record, to submit a second request for a validation record to the target domain; and

generate the email domain validation record to include one or more macro statements specifying identifying information, the macro statements causing the receiving email system, when querying the email domain validation record, to include identifying information of the sender of the email in the second request;

publish the created email domain validation record as a DNS TXT record of the email domain;

receive a query from any server for the DNS TXT record; and

transmit, in response to the receipt of the query, a DNS record to the server for authenticating an email at the receiving email system.

11. The computing device of claim 10 , wherein the email domain validation record is a Sender Policy Framework (SPF) record.

12. The computing device of claim 10 , wherein the macro statements are Sender Policy Framework (SPF) macros, and the macro statements instruct the receiving email system to include as identifying information at least one of an extended HELO (EHLO) name and an Internet Protocol (IP) address of the sender of the email.

13. The computing device of claim 12 , wherein the macro statements and the target domain in the email domain validation record are separated by separating characters that are not allowed in the formation of a hostname.

14. The computing device of claim 10 , wherein the DNS record is further hidden behind one or more DNS Canonical Name record (CNAME) entries.

15. A non-transitory computer readable storage medium configured to store instructions, the instructions when executed by a processor cause the processor to:

generate an email domain validation record to include in a Domain Name System (DNS) record of an email domain, the email domain validation record to be queried by a receiving email system when receiving an email from the email domain, and indicating to the receiving email system whether the sender of an email is an authorized sender for the email domain, the generation of the email domain validation record including instructions that when executed by the processor further cause the processor to:

generate the email domain validation record to include a target domain, the target domain being a domain distinct from the email domain, causing the receiving email system, when querying the email domain validation record, to submit a second request for a validation record to the target domain; and

generate the email domain validation record to include one or more macro statements specifying identifying information, the macro statements causing the receiving email system, when querying the email domain validation record, to include identifying information of the sender of the email in the second request;

publish the created email domain validation record as a DNS TXT record of the email domain;

receive a query from any server for the DNS TXT record; and

transmit, in response to the receipt of the query, a DNS record to the server for authenticating an email at the receiving email system.

16. The computer readable storage medium of claim 15 , wherein the email domain validation record is a Sender Policy Framework (SPF) record.

17. The computer readable storage medium of claim 15 , wherein the macro statements are Sender Policy Framework (SPF) macros, and the macro statements instruct the receiving email system to include as the identifying information at least one of an extended HELO (EHLO) name and an Internet Protocol (IP) address of the sender of the email.

18. The computer readable storage medium of claim 17 , wherein the macro statements and the target domain in the email domain validation record are separated by separating characters that are not allowed in the formation of a hostname.

19. The computer readable storage medium of claim 18 , wherein the target domain parses the received second request using the separating characters as non-ambiguous delimiters.

20. The computer readable storage medium of claim 15 , wherein the DNS record is further hidden behind one or more DNS Canonical Name record (CNAME) entries.

Assignments (3)
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 9, 2026
From: VALIMAIL INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 074281/0239 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2025
From: VALIMAIL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 073910/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2017
From: GOLDSTEIN, PETER MARTIN
To: VALIMAIL INC.
Reel/Frame 043536/0473 →
Continuity (4)
Continuation 15175031 · Jun 6, 2016
Continuation PCTUS2016015796 · Jan 29, 2016
Provisional Application 62116409 · Feb 14, 2015
Related Publication 20170339193A1 · Nov 23, 2017
Cited By (2)
US 12,294,662 US 12,407,638